User-Conditioned Interrupt Mechanism for Man-in-the-Screen Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current internet security measures are inadequate in preventing 'man-in-the-screen' attacks, which are difficult to detect and can intercept sensitive information by spoofing web pages or applications, compromising user security during financial transactions.

Innovation Solution

A system and method that utilizes a user-conditioned response to a stimulus, where a user-generated interrupt determines whether content is trusted, allowing secure information collection from certified and trusted sources while terminating actions on untrusted or malicious content, leveraging a whitelist and blacklist system and cryptographic authentications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security protocols and heuristics are used to detect attacks, then basic security measures are in place, but they cannot detect 'man-in-the-screen' attacks which spoof legitimate web pages and applications

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidundetectable malicious content
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary mechanism - a user-generated interrupt response system - that acts as a mediator between the user and the content. This interrupt mechanism serves as a new layer of security that is independent of traditional detection methods, allowing users to conditionally respond to stimuli from both legitimate and spoofed content, thereby enabling detection of man-in-the-screen attacks that traditional protocols miss

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security protocols are made more complex to detect sophisticated attacks, then detection capability improves, but ease of operation deteriorates

Engineering Contradiction:
Improveattack detection accuracyVSAvoiduser interaction complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically presenting stimuli to users and processing their interrupt responses without requiring users to understand security protocols. The security mechanism serves itself by leveraging natural user responses to familiar stimuli, eliminating the need for users to learn complex security procedures while maintaining high detection accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameter of user interaction from complex security verification steps to simple, natural responses to familiar stimuli. By transforming the interaction model to use conditionally-responsive user interrupts rather than traditional authentication sequences, the system maintains high security while dramatically improving ease of operation

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional proxy detection methods are used, then basic network security is maintained, but man-in-the-browser and man-in-the-screen attacks cannot be distinguished from legitimate content

Engineering Contradiction:
Improveproxy detection capabilityVSAvoidattack presence detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

Instead of trying to detect attacks through traditional analysis of content and network traffic, the patent inverts the approach by using attacks themselves as the detection mechanism. Legitimate content and spoofed content both present stimuli, but the system detects the presence of attacks by analyzing whether users generate appropriate interrupt responses, thereby making the attack behavior itself the indicator of malicious content

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS10791126B2System and methods for protecting users from malicious content
Publication Date: 2020.09.29 PAYPAL INC
  • US10791126B2 patent drawing
  • US10791126B2 patent drawing
  • US10791126B2 patent drawing

AI summary

A method, system and device for allowing the secure collection of sensitive information is provided. The device includes a display, and a user interface capable of receiving at least one user-generated interrupt in response to a stimulus generated in response to content received by the device, wherein the action taken upon receiving the user-generated interrupt depends on a classification of the content, the classification identifying the content as trusted or not trusted. The method includes detecting a request for sensitive information in content, determining if an interrupt is generated, determining if the content is trusted, allowing the collection of the sensitive information if the interrupt is generated and the content is trusted, and performing an alternative action if the interrupt is generated and the content is not trusted. The method may include instructions stored on a computer readable medium.