Vishing Attack Detection via Behavioral Biometrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively detect and prevent 'vishing' attacks, where victims are tricked into performing online financial transactions under false pretenses via telephone instructions, as existing security measures are ineffective in distinguishing between legitimate and fraudulent user interactions.

Innovation Solution

A computerized system that monitors and analyzes user interactions in real-time to detect vishing attacks by identifying patterns and behaviors indicative of duress, such as following pre-defined 'playbooks' and unusual typing or mouse movements, and autonomously takes mitigation actions to prevent fraudulent transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing security measures are used to monitor user interactions, then system security is maintained, but the system cannot distinguish between legitimate and fraudulent user interactions in vishing attacks

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments user interaction monitoring into multiple independent analysis modules: typing pattern analysis, mouse movement analysis, audio analysis, and playbook detection. Each module processes specific behavioral aspects separately and contributes to the overall fraud detection decision, enabling precise differentiation without requiring a single overly complex system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces behavioral biometrics as an intermediary layer between user actions and security decisions. Instead of directly analyzing raw interactions, the system uses behavioral patterns as mediators to indirectly detect fraudulent intent, improving detection precision while maintaining manageable system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time monitoring of user interactions is implemented to detect vishing attacks, then fraud detection capability is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvefraud detection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of behavioral patterns continuously in the background before fraudulent actions occur. Typing patterns, mouse movements, and audio characteristics are pre-processed and stored as baseline data, enabling rapid real-time detection without intensive processing during critical transaction moments

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial monitoring strategies by focusing computational resources on high-risk interaction sequences identified through playbook detection. Instead of analyzing every user action with full complexity, the system intensively monitors specific suspicious patterns while using lighter analysis for routine interactions, reducing overall processing time

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If behavioral analysis is used to detect fraudulent patterns, then detection accuracy is improved, but false positives may increase affecting legitimate users

Engineering Contradiction:
Improvefraud detection precisionVSAvoidfalse positive impact
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system merges multiple independent behavioral indicators (typing patterns, mouse movements, audio analysis, playbook matching) into a unified fraud assessment. By combining several weak signals into a strong composite indicator, the system achieves high detection precision while the multi-factor approach naturally reduces false positives, as legitimate users are unlikely to exhibit multiple suspicious patterns simultaneously

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250016199A1Device, System, and Method of Detecting Vishing Attacks
Publication Date: 2025.01.09 BIOCATCH
  • US20250016199A1 patent drawing

AI summary

Devices, systems, and methods of detecting a vishing attack, in which an attacker provides to a victim step-by-step over-the-phone instructions that command the victim to log-in to his bank account and to perform a dictated banking transaction. The system monitors transactions, online operations, user interactions, gestures performed via input units, speed and timing of data entry, and user engagement with User Interface elements. The system detects that the operations performed by the victim, follow a pre-defined playbook of a vishing attack. The system detects that the victim operates under duress or under dictated instructions, as exhibited in irregular doodling activity, data entry rhythm, typographical error introduction rhythm, unique posture of the user, alternating pattern of listening to phone instructions and performing online operations via a computer, and device orientation changes or spatial changes that characterize a device being used to perform an online transaction while also talking on the phone.