VM Detection via Communication Interference Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures fail to effectively differentiate between legitimate users and fraudulent users, particularly those using Virtual Machines (VMs) to bypass device-oriented identification methods, allowing hackers to evade detection and perform malicious activities.

Innovation Solution

The system employs user interaction monitoring and analysis to extract unique features from user interactions, comparing them to stored profiles and known automated scripts or bot mechanisms, and introduces communication interferences to detect VMs by analyzing responses, thereby differentiating between human users and VM-based attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device-oriented identification methods are used, then authentication can be performed, but fraudulent users using Virtual Machines can bypass detection

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidVM-based fraud
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces communication interferences as an intermediary mechanism to detect VM-based fraud. By injecting artificial disruptions into the communication session between the user device and server, the system can observe how different types of devices respond to these interferences, thereby identifying VMs without directly analyzing device properties that fraudsters can mask.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter being measured from static device properties (which can be faked in VMs) to dynamic response characteristics. By measuring how devices respond to communication interferences in real-time, the system captures behavioral parameters that are difficult to replicate in virtualized environments, improving authentication reliability.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If communication interferences are introduced to detect VMs, then VM-based fraud can be detected, but user interaction monitoring complexity increases

Engineering Contradiction:
ImproveVM fraud detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining multiple types of communication interferences (packet duplication, packet dropping, error code insertion, network congestion, latency injection) and their expected responses for different device types. This preparation allows the system to efficiently detect VMs during actual authentication without requiring complex real-time analysis of unknown interference patterns.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by monitoring how user devices respond to introduced communication interferences and using these responses to identify VMs. The feedback loop captures the device's reaction to interference (such as retransmission behavior, error handling, or connection persistence) and compares it against known patterns to determine whether the device is virtualized, managing complexity through pattern recognition rather than raw analysis.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10049209B2Device, method, and system of differentiating between virtual machine and non-virtualized device
Publication Date: 2018.08.14 BIOCATCH
  • US10049209B2 patent drawing
  • US10049209B2 patent drawing
  • US10049209B2 patent drawing

AI summary

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a cyber-attacker. An end-user device (a desktop computer, a laptop computer, a smartphone, a tablet, or the like) interacts and communicates with a server of a computerized server (a banking website, an electronic commerce website, or the like). The interactions are monitored, tracked and logged. Communication interferences are intentionally introduced to the communication session; and the server tracks the response or the reaction of the end-user device to such communication interferences. The system determines whether the user is a legitimate human user; or a cyber-attacker posing as a legitimate human user but actually utilizing a Virtual Machine.