Web Integrity Validator for MITB Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Man-in-the-Browser (MITB) attacks bypass cryptographic mechanisms and are difficult to detect, causing significant damage and being undetectable by current antivirus systems, leading to unauthorized data collection and fraud.
Innovation Solution
A system and method using a JavaScript-based Web Integrity Validator (WIV) that employs a fingerprinting mechanism, a mutating mechanism, defensive mechanisms, and a central database to detect and deter fraudulent activity by differentiating between legitimate and altered data, and communicating this information back to financial institutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic mechanisms (passwords, credentials, encryption, SSL) are used to protect data, then security is improved, but Man-in-the-Browser attacks can still bypass these mechanisms undetected
Solution Approach 1:
The patent introduces a code snippet as an intermediary component that acts as a witness between the user's browser and the website. This code snippet monitors and verifies the integrity of data and interface elements, detecting alterations made by MITB attacks that bypass traditional cryptographic mechanisms. The intermediary code operates within the browser environment to provide real-time integrity validation.
Solution Approach 2:
The system implements feedback by having the code snippet continuously monitor browser interface elements and send integrity verification data back to the server. The server compares received data against expected values and provides feedback about detected alterations, enabling real-time detection of MITB attacks that would otherwise remain undetected.
2Reliability
If antivirus applications are used to scan for compromises, then some security threats are detected, but MITB attacks remain undetectable as they fail to trigger antivirus warnings
Solution Approach 1:
The patent replaces traditional antivirus scanning mechanisms with a browser-based integrity verification system. Instead of relying on external antivirus software to detect threats, the system embeds verification code directly in the browser environment, substituting mechanical antivirus scanning with real-time cryptographic integrity checks of browser interface elements.
Solution Approach 2:
The system performs preliminary action by embedding integrity verification code snippets in web pages before they are fully executed by the browser. This pre-positioned code actively monitors and verifies the integrity of interface elements as they are rendered, preventing MITB attacks from establishing themselves undetected rather than detecting them after the fact.
3Difficulty of detecting and measuring
If individualized surveillance of target machines is implemented to detect attacks, then attack detection capability is improved, but system complexity and resource requirements increase significantly
Solution Approach 1:
The patent extracts the surveillance function from complex individualized machine monitoring and consolidates it into a standardized code snippet that can be deployed uniformly across multiple browsers. The code snippet contains only the essential integrity verification logic needed to detect MITB attacks, removing unnecessary complexity while maintaining detection capability.
Solution Approach 2:
The integrity verification code snippet is designed as a universal component that can operate across different browsers and target machines with identical functionality. This single standardized code performs multiple functions including monitoring interface elements, verifying data integrity, and detecting alterations, eliminating the need for customized surveillance systems for each target machine.
4Difficulty of detecting and measuring
If code snippets are embedded in web pages for integrity verification, then MITB attack detection is enabled, but the system must protect against the code snippet itself being compromised
Solution Approach 1:
The patent applies preliminary anti-action by implementing defensive code within the integrity verification snippet itself. This embedded defensive code actively detects attempts to compromise, alter, or debug the verification snippet, and responds by invalidating the verification or alerting the server. This pre-built protection counteracts potential compromise attempts before they can succeed.
Solution Approach 2:
The system implements dynamics by making the code snippet's behavior adaptive and responsive to its environment. The snippet continuously monitors its own integrity and the integrity of the pages it verifies, dynamically adjusting its verification behavior based on detected anomalies. This dynamic response enables the snippet to detect and respond to compromise attempts in real-time.
Data Source
AI summary
A computer-implemented method and system for the validation of a true browsing user on a website is disclosed. The invention allows for the collection of data regarding the evolving threat landscape created by online attackers. The system and method fingerprint user behavior to detect differences between a local user, a remote/foreign user, and an automated script. The system then covertly transmits that information back to a financial institution client without giving online attackers the opportunity to notice such transmittal. Certain embodiments of the invention also correspond with the browsing user to validate their identity. The claimed system and method proactively reveal attackers and attack ploys, additionally enabling institutions and security consultants to adapt to attacks in an automated fashion.

