Screen Capture Interception for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security techniques fail to effectively detect and deceive malicious entities that capture screenshots to access private data from computing devices, as they struggle to identify and counter unauthorized access and data usage.

Innovation Solution

A system that intercepts requests for screen captures, determines if they are from authorized sources, and embeds deception data, such as fake credentials, into the responses to mislead attackers, using a deception component and content modification to provide modified screenshots with misleading information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional deception techniques are used to detect malware, then detection capability is improved, but device complexity and customization requirements increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidcustomization requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal deception framework that works across different host systems without requiring scenario-specific customization. The system uses a standardized approach where fake credentials and deception data are injected into screen captures uniformly, eliminating the need for tailored changes per host scenario while maintaining effective malware detection

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates deceptive copies of legitimate screen capture content by embedding fake credentials and deception data into the visual output. Instead of modifying the host system or creating customized deception scenarios, the patent generates counterfeit screen content that mimics legitimate interfaces, allowing malware to interact with fake data while the real system remains protected

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If screen capture interception is implemented to deceive attackers, then data protection is improved, but processing overhead increases

Engineering Contradiction:
Improvedata protectionVSAvoidprocessing overhead
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The patent extracts the deception function from the core screen capture process by implementing it as a separate overlay layer. The system captures the legitimate screen content, then selectively injects deception data only in the portions where fake credentials need to appear, rather than processing and modifying the entire screen capture. This extraction approach minimizes processing overhead while maintaining effective data protection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The deception data is injected locally into specific regions of the screen capture where fake credentials are needed, rather than uniformly processing the entire screen content. The system applies deception only to the necessary portions of the visual output, reducing overall processing requirements while maintaining effective protection against data theft

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11102245B2Deception using screen capture
Publication Date: 2021.08.24 INTERWISE CO LTD
  • US11102245B2 patent drawing
  • US11102245B2 patent drawing
  • US11102245B2 patent drawing

AI summary

Multiple deception techniques utilized to mislead malicious entities that attempt to gather information associated with a computing device are implemented by changing a single result. In one aspect, requests for screen captures are intercepted and it is determined whether the requests are triggered due to user interaction (e.g., pressing a button and/or key) and/or received from an authorized application/device. If determined that the requests are not triggered due to user interaction and/or are received from an unauthorized application/device, a response comprising one of several pre-prepared or dynamically generated screen captures that are embedded (and/or appended) with misleading information (e.g., fake credentials, fake documents marked as important/hidden, etc.) is generated. Applications that attempt to utilize the misleading information can be flagged as malware.