Vishing Attack Detection via Behavioral Anomaly Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures are ineffective in detecting and preventing 'vishing' attacks, where victims are tricked into performing online transactions under false pretenses via telephone instructions, as they involve legitimate users using their regular credentials and IP addresses, making it difficult to distinguish between voluntary and coerced actions.

Innovation Solution

A system that monitors and analyzes user interactions in real-time to detect vishing attacks by identifying patterns and behavioral anomalies, such as following pre-defined 'playbooks' and duress indicators, to differentiate between legitimate and coerced actions, and autonomously takes mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (credentials and IP addresses) are used for authentication, then user convenience is maintained, but the system cannot distinguish between voluntary and coerced actions in vishing attacks

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication verification process into multiple independent analysis components: device sensor data collection (accelerometer, gyroscope, microphone), user interaction pattern analysis, audio analysis for duress detection, and playbook matching. Each component processes specific aspects of user behavior separately, then combines results to make comprehensive authentication decisions, thereby improving reliability without overwhelming complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary detection system that sits between the user's authentication actions and the system's trust decision. This intermediary layer collects and analyzes multiple indirect indicators (device orientation, typing patterns, audio characteristics, interaction sequences) to infer whether coercion is occurring, enabling reliable detection without requiring direct modification of core authentication mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the system monitors and analyzes user interactions in real-time to detect vishing attacks, then detection accuracy improves, but processing time and computational resources increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidreal-time processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing playbook patterns of known vishing attack sequences and pre-configuring detection rules for suspicious behaviors. The system prepares detection templates and analysis frameworks in advance, allowing real-time user interactions to be quickly matched against predefined patterns rather than requiring full analytical processing for every action, thereby maintaining high detection accuracy while reducing processing time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies skipping by implementing incremental analysis that processes user interactions in streams rather than waiting for complete sessions. The system continuously evaluates incoming data against detection criteria and can immediately flag suspicious patterns without waiting for the entire authentication process to complete, reducing detection latency while maintaining precision through continuous monitoring

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS10970394B2System, device, and method of detecting vishing attacks
Publication Date: 2021.04.06 BIOCATCH
  • US10970394B2 patent drawing

AI summary

Devices, systems, and methods of detecting a vishing attack, in which an attacker provides to a victim step-by-step over-the-phone instructions that command the victim to log-in to his bank account and to perform a dictated banking transaction. The system monitors transactions, online operations, user interactions, gestures performed via input units, and user engagement with User Interface elements. The system detects that the operations performed by the victim, follow a pre-defined playbook of a vishing attack. The system detects that the victim operates under duress or under dictated instructions, as exhibited in irregular doodling activity, data entry rhythm, typographical error introduction rhythm, unique posture of the user, alternating pattern of listening to phone instructions and performing online operations via a computer, and device orientation changes or spatial changes that characterize a device being used to perform an online transaction while also talking on the phone.