User Action Characteristic Verification for Phishing Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users attempting to access sensitive applications or data on computing devices may pose as authorized users using stolen credentials, as existing technologies fail to effectively verify the authenticity of users, especially in cases of phishing attacks.
Innovation Solution
A method that measures and records user action characteristics, challenges the user with specific actions, and determines authenticity based on similarity conditions, using a system with a user action detector, characteristics measurement module, uniqueness assessor, challenge manager, and challenge actions to differentiate authorized from unauthorized users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional credential verification is used, then user access is simple and fast, but security against stolen credentials is insufficient
Solution Approach 1:
The system performs preliminary actions by collecting and analyzing user action characteristics during normal device usage before a security challenge is needed. This builds a baseline of legitimate user behavior patterns (typing rhythm, swipe characteristics, click patterns) that can be quickly compared against challenge responses without requiring complex real-time analysis infrastructure.
Solution Approach 2:
The verification system dynamically adapts between two modes: normal operation where user characteristics are passively collected, and challenge mode where specific actions are requested for verification. The system transitions between these states based on security risk assessment, maintaining simplicity during normal use while providing enhanced security when needed.
2Measurement precision
If user action characteristics are measured and analyzed, then authentication accuracy improves, but processing time and system complexity increase
Solution Approach 1:
User action characteristics such as typing speed, swipe duration, and click pressure are continuously measured and stored during normal device operation. This preliminary data collection creates a ready-to-use reference profile that enables rapid authentication decisions during challenge responses without requiring time-consuming real-time analysis.
Solution Approach 2:
The system changes parameters by selecting specific challenge actions from a pool of previously collected user actions. Rather than analyzing all possible characteristics continuously, the system transforms the verification process into comparing specific parameter sets (selected challenge actions) against the stored profile, reducing processing time while maintaining accuracy.
3Reliability
If multiple user actions are recorded for verification, then phishing attack detection improves, but data storage requirements and system complexity increase
Solution Approach 1:
The system extracts and stores only the essential characteristics of user actions (typing rhythm, swipe patterns, click characteristics) rather than storing complete action datasets. This extraction approach captures the unique biometric elements needed for phishing detection while minimizing data storage requirements and protecting user privacy.
Solution Approach 2:
Different types of user actions are recorded with different levels of detail based on their verification value. The system applies local quality by focusing measurement resources on capturing distinctive characteristics of high-value actions (such as password typing patterns) while using less detailed recording for routine actions, optimizing both detection capability and storage efficiency.
Data Source
AI summary
Challenging a current user of a computing device by measuring characteristics of user actions sensed by a computing device, determining that the measurements meet a uniqueness condition with respect to corresponding measurements in a comparison set of actions, recording the user actions and their measurements in a set of challenge actions associated with an authorized user, and responsive to a challenge requirement to determine whether a current user of the computing device is the authorized user, selecting challenge actions associated with an authorized user, prompting the current user to perform the selected challenge actions that are then sensed by the computing device, measuring characteristics of the prompted actions, and determining that the measurements of the characteristics of the prompted actions meet a similarity condition with respect to measurements of corresponding characteristics of the selected challenge actions.


