UI Interference Injection for Human-Bot Differentiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic device security systems are ineffective in distinguishing between human users and automated scripts or bots, particularly in preventing Application DDoS attacks and click-fraud, as they fail to accurately authenticate users and differentiate between legitimate and fraudulent activities.

Innovation Solution

The implementation of a system that introduces generic interferences or anomalies in the user interface, which human users can manually correct but automated scripts cannot, allowing for real-time differentiation and mitigation of fraudulent activities through user interaction analysis and machine learning-based authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional authentication methods are used, then user access is granted, but the system cannot differentiate between human users and automated scripts

Engineering Contradiction:
Improveuser authentication accuracyVSAvoidfraud detection capability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary actions by injecting interferences into the user interface before actual user operations occur. These interferences modify UI elements such as button positions, text content, or layout structures in advance, creating a baseline for comparing subsequent user interactions and detecting automated scripts that cannot adapt to these pre-injected changes

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring user interactions with the modified UI and comparing them against expected human behavior patterns. The system analyzes feedback from interaction timing, click patterns, and navigation sequences to dynamically update authentication decisions and differentiate between legitimate users and automated scripts

Inventive Principle:
Principle #23Feedback

2Reliability

If interferences are injected into the user interface, then fraudulent activities are detected, but user interaction complexity increases

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies parameter changes by modifying specific UI parameters such as element positions, text strings, or structural properties through injected interferences. These parameter modifications are designed to be subtle enough not to disrupt normal user experience while being sufficient to detect automated scripts that rely on fixed parameter values or predictable UI structures

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If traditional security measures are implemented, then basic protection is provided, but Application DDoS attacks and click-fraud cannot be prevented

Engineering Contradiction:
Improveattack resistanceVSAvoiduser differentiation accuracy
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The system applies preliminary anti-action by proactively injecting interferences that prevent automated scripts from successfully executing their fraudulent operations. These interferences are designed to disrupt the automated interaction patterns of DDoS bots and click-fraud scripts before they can complete their malicious actions, while remaining transparent to legitimate human users

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10079853B2Differentiating among users based on responses to injected interferences
Publication Date: 2018.09.18 BIOCATCH
  • US10079853B2 patent drawing
  • US10079853B2 patent drawing
  • US10079853B2 patent drawing

AI summary

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, detecting a cyber-attacker, and detecting click-fraud. An end-user device (a desktop computer, a laptop computer, a smartphone, a tablet, or the like) interacts and communicates with a server of a computerized server (a banking website, an electronic commerce website, or the like). The interactions are monitored, tracked and logged. User Interface (UI) interferences or irregularities are intentionally introduced to the communication session; and the server tracks the response or the reaction of the end-user to such communication interferences. The system determines whether the user is a legitimate human user, or a cyber-attacker or automated script posing as the legitimate human user. The system further detects click-fraud, and prevents or mitigates Application Distributed Denial-of-Service attacks.