Web Integrity Validator for MITB Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Man-in-the-Browser (MITB) attacks bypass cryptographic mechanisms and are difficult to detect, causing significant damage and being undetectable by current antivirus systems, leading to unauthorized data collection and fraud.

Innovation Solution

A system and method using a JavaScript-based Web Integrity Validator (WIV) that employs a fingerprinting mechanism, a mutating mechanism, defensive mechanisms, and a central database to detect and deter fraudulent activity by differentiating between legitimate and altered data, and communicating this information back to financial institutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic mechanisms (passwords, credentials, encryption, SSL) are used to protect data, then security is improved, but Man-in-the-Browser attacks can still bypass these mechanisms undetected

Engineering Contradiction:
ImprovesecurityVSAvoidattack detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a code snippet as an intermediary component that acts as a witness between the user's browser and the website. This code snippet monitors and verifies the integrity of data and interface elements, detecting alterations made by MITB attacks that bypass traditional cryptographic mechanisms. The intermediary code operates within the browser environment to provide real-time integrity validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback by having the code snippet continuously monitor browser interface elements and send integrity verification data back to the server. The server compares received data against expected values and provides feedback about detected alterations, enabling real-time detection of MITB attacks that would otherwise remain undetected.

Inventive Principle:
Principle #23Feedback

2Reliability

If antivirus applications are used to scan for compromises, then some security threats are detected, but MITB attacks remain undetectable as they fail to trigger antivirus warnings

Engineering Contradiction:
Improvethreat detectionVSAvoidattack evasion
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces traditional antivirus scanning mechanisms with a browser-based integrity verification system. Instead of relying on external antivirus software to detect threats, the system embeds verification code directly in the browser environment, substituting mechanical antivirus scanning with real-time cryptographic integrity checks of browser interface elements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary action by embedding integrity verification code snippets in web pages before they are fully executed by the browser. This pre-positioned code actively monitors and verifies the integrity of interface elements as they are rendered, preventing MITB attacks from establishing themselves undetected rather than detecting them after the fact.

Inventive Principle:
Principle #10Preliminary action

3Difficulty of detecting and measuring

If individualized surveillance of target machines is implemented to detect attacks, then attack detection capability is improved, but system complexity and resource requirements increase significantly

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsurveillance system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts the surveillance function from complex individualized machine monitoring and consolidates it into a standardized code snippet that can be deployed uniformly across multiple browsers. The code snippet contains only the essential integrity verification logic needed to detect MITB attacks, removing unnecessary complexity while maintaining detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The integrity verification code snippet is designed as a universal component that can operate across different browsers and target machines with identical functionality. This single standardized code performs multiple functions including monitoring interface elements, verifying data integrity, and detecting alterations, eliminating the need for customized surveillance systems for each target machine.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Difficulty of detecting and measuring

If code snippets are embedded in web pages for integrity verification, then MITB attack detection is enabled, but the system must protect against the code snippet itself being compromised

Engineering Contradiction:
ImproveMITB attack detectionVSAvoidcode snippet compromise
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing defensive code within the integrity verification snippet itself. This embedded defensive code actively detects attempts to compromise, alter, or debug the verification snippet, and responds by invalidating the verification or alerting the server. This pre-built protection counteracts potential compromise attempts before they can succeed.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system implements dynamics by making the code snippet's behavior adaptive and responsive to its environment. The snippet continuously monitors its own integrity and the integrity of the pages it verifies, dynamically adjusting its verification behavior based on detected anomalies. This dynamic response enables the snippet to detect and respond to compromise attempts in real-time.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9584543B2Method and system for web integrity validator
Publication Date: 2017.02.28 HUMAN SECURITY INC
  • US9584543B2 patent drawing
  • US9584543B2 patent drawing

AI summary

A computer-implemented method and system for the validation of a true browsing user on a website is disclosed. The invention allows for the collection of data regarding the evolving threat landscape created by online attackers. The system and method fingerprint user behavior to detect differences between a local user, a remote/foreign user, and an automated script. The system then covertly transmits that information back to a financial institution client without giving online attackers the opportunity to notice such transmittal. Certain embodiments of the invention also correspond with the browsing user to validate their identity. The claimed system and method proactively reveal attackers and attack ploys, additionally enabling institutions and security consultants to adapt to attacks in an automated fashion.