IP Library Granted Patent US 9,838,373
Granted Patent B2
US 9,838,373 · App. 15/347,061 · Granted Dec 5, 2017

System, device, and method of detecting a remote access user

Inventor: Avi Turgeman (Cambridge, MA)
Assignee: BioCatch Ltd.
H04L63/08G06F3/0487G06F3/04812G06F3/04883G06F21/31G06F21/55H04L63/145H04L63/1416G06F2203/04801H04L63/102H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,838,373
App. No.
15/347,061
Granted
Dec 5, 2017
Kind
B2
Abstract

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a possible attacker. The methods include monitoring of user-side input-unit interactions, in general and in response to an interference introduced to user-interface elements. The monitored interactions are used for detecting an attacker that utilizes a remote access channel; for detecting a malicious automatic script, as well as malicious code injection; to identify a particular hardware assembly; to perform user segmentation or user characterization; to enable a visual login process with implicit two-factor authentication; to enable stochastic cryptography; and to detect that multiple users are utilizing the same subscription account.

Claims (86)

1. A method comprising:

determining whether a human user, who utilizes a computing device to interact with a computerized service via a communication channel, (i) is a human user that is co-located physically near said computing device, or (ii) is a human user that is located remotely from said computing device and is operating remotely said computer device via a remote access channel;

wherein the determining comprises:

(a) monitoring interactions of the user with an input unit of said computing device, in response to one or more communication lags that are exhibited by said communication channel;

(b) based on monitored user interactions via the input unit in response to said one or more communication lags, determining whether said human user (i) is a human user that is co-located physically at said computing device, or (ii) is a human user that is located remotely from said computing device and is controlling remotely said computing device via said remote access channel.

2. The method of claim 1 , comprising:

injecting a communication latency into said communication channel between said computing device and said computerized service;

introducing an input/output aberration that causes said input unit of said computing device to exhibit abnormal behavior;

determining an actual reaction time of said user to said input/output aberration;

if the actual reaction time of said user to the input/output aberration, is greater than a pre-defined reaction-time threshold value, then determining that the user is located remotely from said computing device and is controlling remotely said computing device via said remote access channel.

3. The method of claim 1 , comprising:

injecting a communication latency into said communication channel between said computing device and said computerized service;

introducing an input/output aberration that causes said input unit of said computing device to exhibit abnormal behavior;

determining an actual reaction time of said user to said input/output aberration;

defining a reference reaction time that characterizes a maximum time that elapses between (I) generation of said input/output aberration to a local user, and (II) sensing of a reaction by the local user to said input/output aberration;

if the actual reaction time of said user to the input/output aberration, is greater than said reference reaction time, then determining that the user is located remotely from said computing device and is controlling remotely said computing device via said remote access channel.

4. The method of claim 1 , comprising:

injecting a communication latency into said communication channel between said computing device and said computerized service;

introducing an input/output aberration that causes said input unit of said computing device to exhibit abnormal behavior;

determining a time-length of a time-gap between (I) introduction of said input/output aberration, and (II) first discovery of the input/output aberration by the user as exhibited by commencement of a corrective action by the user;

if the time-length of said time-gap, is greater than a pre-defined time-gap threshold value that characterizes non-remote users, then determining that the user is located remotely from said computing device and is controlling remotely said computing device via said remote access channel.

5. The method of claim 1 , comprising:

injecting a communication latency into said communication channel between said computing device and said computerized service;

introducing an input/output aberration that causes said input unit of said computing device to exhibit abnormal behavior;

determining a time-length of a time-gap between (I) introduction of said input/output aberration, and (II) an end of a corrective action that the user performed in response to said input/output aberration;

if the time-length of said time-gap, is greater than a pre-defined time-gap threshold value that characterizes non-remote users, then determining that the user is located remotely from said computing device and is controlling remotely said computing device via said remote access channel.

6. The method of claim 1 , comprising:

hiding a mouse-pointer on a screen of said computerized service;

monitoring input unit reactions of said user in response to the hiding of the mouse-pointer;

based on the input unit reactions of said user in response to the hiding of the mouse-pointer, determining whether said user is (i) co-located physically at said computing device, or (ii) is located remotely rom said computing device and controlling remotely said computing device via said remote access channel.

7. The method of claim 1 , comprising:

temporarily hiding an on-screen pointer of said computerized service;

monitoring input unit reactions of said user in response to the hiding of the on-screen pointer;

detecting latency in said input unit reactions of said user in response to the hiding of the on-screen pointer;

based on detected latency in the input unit reactions of said user in response to the hiding of the on-screen pointer, determining whether said user is (i) co-located physically at said computing device, or (ii) is located remotely rom said computing device and controlling remotely said computing device via said remote access channel.

8. The method of claim 1 , comprising:

causing an on-screen pointer to deviate relative to its regular on-screen route;

monitoring input unit reactions of said user in response to deviation of the on-screen pointer;

detecting latency in said input unit reactions of said user in response to the deviation of the on-screen pointer;

based on detected latency in the input unit reactions of said user in response to the deviation of the on-screen pointer, determining whether said user is (i) co-located physically at said computing device, or (ii) is located remotely rom said computing device and controlling remotely said computing device via said remote access channel.

9. The method of claim 1 , comprising:

sampling multiple interactions of said user with said input unit of said computing device;

based on a frequency of said sampling, determining latency of communications between said user and the computerized service;

based on said latency of communications, determining whether said user is (i) co-located physically at said computing device, or (ii) is located remotely from said computing device and controlling remotely said computing device via said remote access channel.

10. The method of claim 1 , comprising:

sampling multiple interactions of said user with said input unit of said computing device;

based on a frequency of said sampling, determining latency of communications between said user and the computerized service;

based on said latency of communications, determining whether said user is (i) co-located physically at said computing device, or (ii) is located remotely from said computing device and controlling remotely said computing device via said remote access channel.

11. The method of claim 1 , comprising:

sampling multiple interactions of said user with a computer mouse;

if said sampling indicates generally-smooth movement of the computer mouse, then, determining that said user is co-located physically near said computing device.

12. The method of claim 1 , comprising:

sampling multiple interactions of said user with a computer mouse;

if said sampling indicates generally-rough movement of the computer mouse, then, determining that said user is located remotely from said computing device and controlling remotely said computing device via said remote access channel.

13. The method of claim 1 , comprising:

sampling multiple interactions of said user with a computer mouse;

if said sampling indicates generally-linear movement of the computer mouse, then, determining that said user is located remotely from said computing device and controlling remotely said computing device via said remote access channel.

14. The method of claim 1 , comprising:

sampling multiple interactions of said user with a computer mouse;

if said sampling indicates sharp-turn movements of the computer mouse, then, determining that said user is located remotely from said computing device and controlling remotely said computing device via said remote access channel.

15. The method of claim 1 , comprising:

sampling multiple interactions of said user with said input unit;

if a frequency of said multiple interactions is below a pre-defined threshold, then, determining that said user is located remotely from said computing device and controlling remotely said computing device via said remote access channel;

if the frequency of said multiple interactions is above the pre-defined threshold, then, determining that said user is co-located physically near said computing device.

16. The method of claim 1 , comprising:

overloading a data transfer communication channel of the computing device that is used for accessing said computerized service;

measuring an effect of said overloading on frequency of sampling user interactions via an input unit;

based on the measured effect of said overloading, determining whether said user is (i) co-located physically at said computing device, or (ii) is located remotely from said computing device and controlling remotely said computing device via said remote access channel.

17. The method of claim 1 , comprising:

sampling user interactions with an input unit of a mobile computing device;

analyzing temporal relationship between touch events and accelerometer events of sampled user interactions with said input unit of the mobile computing device;

based on analysis of temporal relationship between touch and accelerometer events, of sampled user interactions with said input unit of the mobile computing device, determining whether the said mobile computing device is controlled remotely via said remote access channel.

18. The method of claim 1 , comprising:

sampling user interactions with an input unit of a mobile computing device;

analyzing temporal relationship between touch movement events and accelerometer events, of sampled user interactions with said input unit of the mobile computing device;

based on analysis of temporal relationship between touch movement event and accelerometer events, of sampled user interactions with said input unit of the mobile computing device, determining whether the said mobile computing device is controlled remotely via said remote access channel.

19. The method of claim 1 , comprising:

(A) sampling touch-based gestures of a touch-screen of a mobile computing device;

(B) sampling accelerometer data of said mobile computing device, during a time period which at least partially overlaps said sampling of touch-based gestures of the touch-screen of the mobile computing device;

(C) based on a mismatch between (i) sampled touch-based gestures, and (ii) sampled accelerometer data, determining that the mobile computing device was controlled remotely via said remote access channel.

20. The method of claim 1 , comprising:

(A) sampling touch-based gestures of a touch-screen of a mobile computing device;

(B) sampling accelerometer data of said mobile computing device, during a time period which at least partially overlaps said sampling of touch-based gestures of the touch-screen of the mobile computing device;

(C) determining that sampled touch-based gestures indicate that a user operated the mobile computing device at a particular time-slot;

(D) determining that the sampled accelerometer data indicate that the mobile computing device was not moved during said particular time-slot;

(E) based on the determining of step (C) and the determining of step (D), determining that the mobile computing device was controlled remotely via said remote access channel during said particular time-slot.

Assignments (4)
INTELLECTUAL PROPERTY SECURITY AGREEMENT TERMINATION UNDER REEL/FRAME: 049480/0823 Recorded Sep 14, 2020
From: KREOS CAPITAL VI (EXPERT FUND) LP
To: BIOCATCH LTD.
Reel/Frame 053769/0729 →
SECURITY INTEREST Recorded Jun 16, 2019
From: BIOCATCH LTD.
To: KREOS CAPITAL VI (EXPERT FUND) L.P.
Reel/Frame 049480/0823 →
CHANGE OF ADDRESS Recorded Jun 13, 2019
From: BIOCATCH LTD.
To: BIOCATCH LTD.
Reel/Frame 049459/0302 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2016
From: TURGEMAN, AVI
To: BIOCATCH LTD.
Reel/Frame 040484/0547 →
Continuity (10)
Continuation In Part 14325393 · Jul 8, 2014
Continuation In Part 13922271 · Jun 20, 2013
Continuation In Part 13877676
Continuation In Part 14320653 · Jul 1, 2014
Continuation In Part 14320656 · Jul 1, 2014
Continuation In Part 15347061
Continuation In Part 14736287 · Jun 11, 2015
Provisional Application 61843915 · Jul 9, 2013
Provisional Application 61417479 · Nov 29, 2010
Related Publication 20170054702A1 · Feb 23, 2017