Trusted Interaction Window Overlay Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods fail to effectively protect users from graphical spoofing attacks during online transactions, particularly against chromeless window attacks where rogue applications overlay trusted windows, misleading users into entering sensitive information.
Innovation Solution
A trusted interaction window is continuously monitored to detect overlay conditions, ensuring it remains the topmost window and notifying users of potential interference, with visual or audible alerts, and disabling requested operations to prevent unauthorized data entry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the browser uses two different window colours to distinguish trusted browser windows from those containing server-provided content, then the user can recognize trusted windows, but this does not protect against a rogue application creating a graphical representation of a window with a border of the trusted colour
Solution Approach 1:
The patent uses dynamic color changes in window borders, where the border color changes at random intervals rather than remaining static. This temporal variation in color properties makes it impossible for spoofing applications to replicate the authentication mechanism, as they cannot predict when and what color the border will change to.
Solution Approach 2:
The patent transforms the static window border authentication into a dynamic system where the border color continuously changes at random intervals. This dynamic behavior creates an authentication mechanism that cannot be replicated by static spoofing applications, resolving the vulnerability to graphical spoofing attacks.
2Reliability
If the browser creates a trusted reference window and changes the border colour at random intervals, then the user can recognize trusted windows by synchronized border changes, but this technique does not defend against chromeless window attacks
Solution Approach 1:
The patent adds a new dimension to window authentication by monitoring the Z-order (stacking order) of windows. Instead of relying solely on visual border characteristics, the system tracks the positional dimension of windows in the stacking hierarchy, detecting when unauthorized windows are positioned above trusted windows, thereby defending against chromeless window attacks.
Solution Approach 2:
The patent implements continuous monitoring of window stacking orders and provides feedback when a chromeless window attempts to overlay a trusted window. This feedback mechanism detects the presence of unauthorized windows by monitoring changes in the Z-order, enabling the system to alert users and prevent authentication with spoofed interfaces.
3Ease of operation
If the operating system determines the order in which windows overlap (Z order), then window positioning can be managed, but the operating system does not always notify a window that it has become a background window or if an active window has been covered
Solution Approach 1:
The patent introduces an intermediary component that sits between the operating system's window management system and the application. This intermediary continuously monitors window stacking orders and translates the OS's Z-order information into meaningful notifications for the application, enabling the detection of chromeless window attacks that would otherwise go unnoticed.
Data Source
AI summary
A method and apparatus for protecting communication of information through a graphical user interface displays a graphical user interface that includes a trusted interaction window. In one example, the method includes continuously determining whether information has been overlayed on top of at least a portion of the displayed trusted interaction window and then disabling an operation being requested when an overlay condition has been determined. In one example, the trusted interaction window is maintained to be the top most window when it is called by an application, for example, during an online transaction, or any other suitable action. The trusted interaction window may be generated via a browser, or operating system, or any other suitable application. As such, the trusted interaction window detects when another window is overlayed on top of it, such as a chromeless window, thereby preventing an unscrupulous party from tricking the user or obtaining sensitive information.


