Vishing Attack Detection via Behavioral Biometrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively detect and prevent 'vishing' attacks, where victims are tricked into performing online financial transactions under false pretenses via telephone instructions, as existing security measures are ineffective in distinguishing between legitimate and fraudulent user interactions.
Innovation Solution
A computerized system that monitors and analyzes user interactions in real-time to detect vishing attacks by identifying patterns and behaviors indicative of duress, such as following pre-defined 'playbooks' and unusual typing or mouse movements, and autonomously takes mitigation actions to prevent fraudulent transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing security measures are used to monitor user interactions, then system security is maintained, but the system cannot distinguish between legitimate and fraudulent user interactions in vishing attacks
Solution Approach 1:
The system segments user interaction monitoring into multiple independent analysis modules: typing pattern analysis, mouse movement analysis, audio analysis, and playbook detection. Each module processes specific behavioral aspects separately and contributes to the overall fraud detection decision, enabling precise differentiation without requiring a single overly complex system
Solution Approach 2:
The system introduces behavioral biometrics as an intermediary layer between user actions and security decisions. Instead of directly analyzing raw interactions, the system uses behavioral patterns as mediators to indirectly detect fraudulent intent, improving detection precision while maintaining manageable system complexity
2Reliability
If real-time monitoring of user interactions is implemented to detect vishing attacks, then fraud detection capability is improved, but processing time and computational resources increase
Solution Approach 1:
The system performs preliminary analysis of behavioral patterns continuously in the background before fraudulent actions occur. Typing patterns, mouse movements, and audio characteristics are pre-processed and stored as baseline data, enabling rapid real-time detection without intensive processing during critical transaction moments
Solution Approach 2:
The system applies partial monitoring strategies by focusing computational resources on high-risk interaction sequences identified through playbook detection. Instead of analyzing every user action with full complexity, the system intensively monitors specific suspicious patterns while using lighter analysis for routine interactions, reducing overall processing time
3Measurement precision
If behavioral analysis is used to detect fraudulent patterns, then detection accuracy is improved, but false positives may increase affecting legitimate users
Solution Approach 1:
The system merges multiple independent behavioral indicators (typing patterns, mouse movements, audio analysis, playbook matching) into a unified fraud assessment. By combining several weak signals into a strong composite indicator, the system achieves high detection precision while the multi-factor approach naturally reduces false positives, as legitimate users are unlikely to exhibit multiple suspicious patterns simultaneously
Data Source
AI summary
Devices, systems, and methods of detecting a vishing attack, in which an attacker provides to a victim step-by-step over-the-phone instructions that command the victim to log-in to his bank account and to perform a dictated banking transaction. The system monitors transactions, online operations, user interactions, gestures performed via input units, speed and timing of data entry, and user engagement with User Interface elements. The system detects that the operations performed by the victim, follow a pre-defined playbook of a vishing attack. The system detects that the victim operates under duress or under dictated instructions, as exhibited in irregular doodling activity, data entry rhythm, typographical error introduction rhythm, unique posture of the user, alternating pattern of listening to phone instructions and performing online operations via a computer, and device orientation changes or spatial changes that characterize a device being used to perform an online transaction while also talking on the phone.
