Traffic Inspector and Analyzer for Account Takeover Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to identify and protect users from account take over attacks, particularly when malware is involved, as they cannot determine the user's identity in infected sessions, allowing attackers to steal credentials and initiate fraudulent activities.

Innovation Solution

A method utilizing a traffic inspector and analyzer system that intercepts and analyzes web traffic, generates unique codes, and predicts user identities through characteristic data comparison, enabling the detection of account take over attacks and implementing protection mechanisms such as Strong Customer Authentication or Multi-Factor Authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus software is used to counter malware attacks, then protection against known malware is improved, but the system cannot detect or identify user identity in infected sessions, allowing account take over attacks to succeed

Engineering Contradiction:
Improveprotection against malwareVSAvoiddetection of user identity in infected sessions
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a traffic inspector and traffic analyzer as intermediary components between the user's browser and the online service. The traffic inspector intercepts HTTP requests and responses, while the traffic analyzer processes this traffic to detect malware and predict user identity. This intermediary system enables detection of account take over attacks without requiring modification of the existing antivirus software or browser components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical malware detection methods (antivirus software scanning) with a traffic analysis-based approach. Instead of relying on antivirus signatures and heuristics, the system uses characteristic data extraction from HTTP traffic and machine learning algorithms to predict user identity and detect compromised sessions. This substitution enables detection of previously undetectable account take over attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Object-generated harmful factors

If malware is installed on the user's computer to manipulate the web browser, then the attacker can steal credentials, but the web browser and web application are unable to locate the added malicious content

Engineering Contradiction:
Improvecredential theft capabilityVSAvoiddetection of malicious content injection
Core Design Contradiction:
Object-generated harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The traffic inspector acts as an intermediary that intercepts HTTP requests and responses between the browser and online service. By analyzing this traffic, the system can detect anomalies indicative of malware manipulation, such as unusual request patterns, unexpected redirects, or credentials being sent to unauthorized destinations. This intermediary monitoring enables detection of malicious content injection that the browser itself cannot detect.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback loops where the traffic analyzer continuously monitors traffic patterns and compares them against expected behavior. When anomalies are detected (such as credentials being transmitted to unauthorized servers), the system can trigger alerts or block further communication. This feedback mechanism enables real-time detection of credential theft attempts.

Inventive Principle:
Principle #23Feedback

3Productivity

If automatic systems perform bot attacks with high bandwidth consumption, then service abuse is enabled, but the system cannot distinguish between legitimate and malicious automated traffic

Engineering Contradiction:
Improveautomated service accessVSAvoiddetection of malicious automated traffic
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The traffic analyzer implements continuous feedback monitoring of automated traffic patterns. By analyzing request frequencies, timing patterns, and behavioral characteristics, the system can distinguish between legitimate automated access (such as scheduled tasks or accessibility tools) and malicious bot activity. The feedback mechanism allows the system to adapt to new attack patterns while maintaining legitimate automated access.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes the parameters used to evaluate automated traffic from simple volume-based metrics to multi-dimensional behavioral analysis. Instead of treating all automated traffic uniformly, the system analyzes multiple parameters including request timing, user agent patterns, session duration, and interaction sequences. This parameter transformation enables differentiation between legitimate and malicious automated traffic.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11973798B2Methods of monitoring and protecting access to online services
Publication Date: 2024.04.30 CLEAFY SPA
  • US11973798B2 patent drawing
  • US11973798B2 patent drawing
  • US11973798B2 patent drawing

AI summary

A method of monitoring and protecting access to an online service from an Account Take Over attack may include: providing a Traffic Inspector in signal communication with at least one client device for Internet browsing and with a web server having the online service residing therein; providing a Traffic Analyzer in signal communication with the Traffic Inspector; identifying, by the Traffic Inspector, each browsing session of the at least one client device on the online service; extracting and identifying, by the Traffic Analyzer, one or more usernames when a user performs authentication to the online service, analyzing traffic exchanged between the at least one client device and the web server; and collecting, by the Traffic Inspector, first characteristic data concerning unique and/or non-unique technical parameters and associating, by the Traffic Analyzer, the first characteristic data with respective identified one or more usernames.