Traffic Inspector and Analyzer for Account Takeover Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods fail to identify and protect users from account take over attacks, particularly when malware is involved, as they cannot determine the user's identity in infected sessions, allowing attackers to steal credentials and initiate fraudulent activities.
Innovation Solution
A method utilizing a traffic inspector and analyzer system that intercepts and analyzes web traffic, generates unique codes, and predicts user identities through characteristic data comparison, enabling the detection of account take over attacks and implementing protection mechanisms such as Strong Customer Authentication or Multi-Factor Authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If antivirus software is used to counter malware attacks, then protection against known malware is improved, but the system cannot detect or identify user identity in infected sessions, allowing account take over attacks to succeed
Solution Approach 1:
The patent introduces a traffic inspector and traffic analyzer as intermediary components between the user's browser and the online service. The traffic inspector intercepts HTTP requests and responses, while the traffic analyzer processes this traffic to detect malware and predict user identity. This intermediary system enables detection of account take over attacks without requiring modification of the existing antivirus software or browser components.
Solution Approach 2:
The patent replaces traditional mechanical malware detection methods (antivirus software scanning) with a traffic analysis-based approach. Instead of relying on antivirus signatures and heuristics, the system uses characteristic data extraction from HTTP traffic and machine learning algorithms to predict user identity and detect compromised sessions. This substitution enables detection of previously undetectable account take over attacks.
2Object-generated harmful factors
If malware is installed on the user's computer to manipulate the web browser, then the attacker can steal credentials, but the web browser and web application are unable to locate the added malicious content
Solution Approach 1:
The traffic inspector acts as an intermediary that intercepts HTTP requests and responses between the browser and online service. By analyzing this traffic, the system can detect anomalies indicative of malware manipulation, such as unusual request patterns, unexpected redirects, or credentials being sent to unauthorized destinations. This intermediary monitoring enables detection of malicious content injection that the browser itself cannot detect.
Solution Approach 2:
The system implements feedback loops where the traffic analyzer continuously monitors traffic patterns and compares them against expected behavior. When anomalies are detected (such as credentials being transmitted to unauthorized servers), the system can trigger alerts or block further communication. This feedback mechanism enables real-time detection of credential theft attempts.
3Productivity
If automatic systems perform bot attacks with high bandwidth consumption, then service abuse is enabled, but the system cannot distinguish between legitimate and malicious automated traffic
Solution Approach 1:
The traffic analyzer implements continuous feedback monitoring of automated traffic patterns. By analyzing request frequencies, timing patterns, and behavioral characteristics, the system can distinguish between legitimate automated access (such as scheduled tasks or accessibility tools) and malicious bot activity. The feedback mechanism allows the system to adapt to new attack patterns while maintaining legitimate automated access.
Solution Approach 2:
The system changes the parameters used to evaluate automated traffic from simple volume-based metrics to multi-dimensional behavioral analysis. Instead of treating all automated traffic uniformly, the system analyzes multiple parameters including request timing, user agent patterns, session duration, and interaction sequences. This parameter transformation enables differentiation between legitimate and malicious automated traffic.
Data Source
AI summary
A method of monitoring and protecting access to an online service from an Account Take Over attack may include: providing a Traffic Inspector in signal communication with at least one client device for Internet browsing and with a web server having the online service residing therein; providing a Traffic Analyzer in signal communication with the Traffic Inspector; identifying, by the Traffic Inspector, each browsing session of the at least one client device on the online service; extracting and identifying, by the Traffic Analyzer, one or more usernames when a user performs authentication to the online service, analyzing traffic exchanged between the at least one client device and the web server; and collecting, by the Traffic Inspector, first characteristic data concerning unique and/or non-unique technical parameters and associating, by the Traffic Analyzer, the first characteristic data with respective identified one or more usernames.


