IP Library Granted Patent US 10,404,729
Granted Patent B2
US 10,404,729 · App. 15/369,106 · Granted Sep 3, 2019

Device, method, and system of generating fraud-alerts for cyber-attacks

Inventor: Avi Turgeman (Cambridge, MA)
Assignee: BIOCATCH LTD.
H04L63/1425G06F3/03543G06F3/03547G06F3/041G06F3/0488G06F3/0489G06F21/31G06F21/316G06F21/32G06F21/554H04L63/08H04L63/1408G06F2221/2133
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,404,729
App. No.
15/369,106
Granted
Sep 3, 2019
Kind
B2
Abstract

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a cyber-attacker. An end-user device (a desktop computer, a laptop computer, a smartphone, a tablet, or the like) interacts and communicates with a server of a computerized server (a banking website, an electronic commerce website, or the like). The interactions are monitored, tracked and logged. User Interface (UI) interferences are intentionally introduced to the communication session; and the server tracks the response or the reaction of the end-user to such communication interferences. The system determines whether the user is a legitimate human user; or a cyber-attacker posing as the legitimate human user. The system displays gauges indicating cyber fraud scores or cyber-attack threat-levels. The system extrapolates from observed fraud incidents and utilizes a rules engine to automatically search for similar fraud events and to automatically detect fraud events or cyber-attackers.

Claims (107)

1. A method comprising:

(a) monitoring user interactions of a user, who utilizes a computing device to interact with a computerized service during a usage session;

(b) for each particular type of data entry method that the user utilizes during said usage session:

(b1) determining a current number of occurrences of utilization of said particular type of data entry method during said usage session, and generating output corresponding to said current number of occurrences during said usage session;

(b2) determining a ratio between (A) said current number of occurrences of utilization of said particular type of data entry method during said usage session, and (B) an average number of occurrences of utilization of said particular type of data entry method during previous usage sessions of said user; and generating output corresponding to said ratio;

(b3) based on (i) said current number of occurrences, and (ii) said average number of occurrences during previous usage sessions of said user, determining whether said user is an authorized user or a cyber-attacker;

wherein the determining of step (b3) is performed by:

(A) determining that in the current usage session of said user, K percent of interactions with a particular user-interface element are performed via a computer mouse;

(B) determining that in previous usage sessions of said user, M percent of interactions with said particular user-interface element were performed via the computer mouse;

(C) determining that K is different than M by at least N percent, wherein N is a pre-defined threshold number of percent-points;

(D) based on the determining of step (C), determining that the current usage session is attributed to a cyber-attacker and not to the authorized user.

2. A method comprising:

(a) monitoring user interactions of a user, who utilizes a computing device to interact with a computerized service during a usage session;

(b) for each particular type of data entry method that the user utilizes during said usage session:

(b1) determining a current number of occurrences of utilization of said particular type of data entry method during said usage session, and generating output corresponding to said current number of occurrences during said usage session;

(b2) determining a ratio between (A) said current number of occurrences of utilization of said particular type of data entry method during said usage session, and (B) an average number of occurrences of utilization of said particular type of data entry method during previous usage sessions of said user; and generating output corresponding to said ratio;

(b3) based on (i) said current number of occurrences, and (ii) said average number of occurrences during previous usage sessions of said user, determining whether said user is an authorized user or a cyber-attacker;

wherein the determining of step (b3) is performed by:

(A) determining that in the current usage session of said user, K percent of interactions with a particular user-interface element are performed by a touch-pad;

(B) determining that in previous usage sessions of said user, M percent of interactions with said particular user-interface element were performed via the touch-pad;

(C) determining that K is different than M by at least N percent, wherein N is a pre-defined threshold number of percent-points;

(D) based on the determining of step (C), determining that the current usage session is attributed to a cyber-attacker and not to the authorized user.

3. A method comprising:

(a) monitoring user interactions of a user, who utilizes a computing device to interact with a computerized service during a usage session;

(b) for each particular type of data entry method that the user utilizes during said usage session:

(b1) determining a current number of occurrences of utilization of said particular type of data entry method during said usage session, and generating output corresponding to said current number of occurrences during said usage session;

(b2) determining a ratio between (A) said current number of occurrences of utilization of said particular type of data entry method during said usage session, and (B) an average number of occurrences of utilization of said particular type of data entry method during previous usage sessions of said user; and generating output corresponding to said ratio;

(b3) based on (i) said current number of occurrences, and (ii) said average number of occurrences during previous usage sessions of said user, determining whether said user is an authorized user or a cyber-attacker;

wherein the determining of step (b3) is performed by:

(A) determining that in the current usage session of said user, K percent of interactions with a particular user-interface element are performed by a keyboard;

(B) determining that in previous usage sessions of said user, M percent of interactions with said particular user-interface element were performed via the keyboard;

(C) determining that K is different than M by at least N percent, wherein N is a pre-defined threshold number of percent-points;

(D) based on the determining of step (C), determining that the current usage session is attributed to a cyber-attacker and not to the authorized user.

4. A method comprising:

(a) monitoring user interactions of a user, who utilizes a computing device to interact with a computerized service during a usage session;

(b) for each particular type of data entry method that the user utilizes during said usage session:

(b1) determining a current number of occurrences of utilization of said particular type of data entry method during said usage session, and generating output corresponding to said current number of occurrences during said usage session;

(b2) determining a ratio between (A) said current number of occurrences of utilization of said particular type of data entry method during said usage session, and (B) an average number of occurrences of utilization of said particular type of data entry method during previous usage sessions of said user; and generating output corresponding to said ratio;

(b3) based on (i) said current number of occurrences, and (ii) said average number of occurrences during previous usage sessions of said user, determining whether said user is an authorized user or a cyber-attacker;

wherein the determining of step (b3) is performed by:

(A) determining that in the current usage session of said user, K percent of interactions with a particular user-interface element are performed by a touch-screen;

(B) determining that in previous usage sessions of said user, M percent of interactions with said particular user-interface element were performed via the touch-screen;

(C) determining that K is different than M by at least N percent-points, wherein N is a pre-defined threshold number of percent-points;

(D) based on the determining of step (C), determining that the current usage session is attributed to a cyber-attacker and not to the authorized user.

5. A method comprising:

(a) monitoring user interactions of a user, who utilizes a computing device to interact with a computerized service during a usage session;

(b) for each particular type of data entry method that the user utilizes during said usage session:

(b1) determining a current number of occurrences of utilization of said particular type of data entry method during said usage session, and generating output corresponding to said current number of occurrences during said usage session;

(b2) determining a ratio between (A) said current number of occurrences of utilization of said particular type of data entry method during said usage session, and (B) an average number of occurrences of utilization of said particular type of data entry method during previous usage sessions of said user; and generating output corresponding to said ratio;

(b3) based on (i) said current number of occurrences, and (ii) said average number of occurrences during previous usage sessions of said user, determining whether said user is an authorized user or a cyber-attacker;

wherein the determining of step (b3) is performed by:

(A) determining that in the current usage session of said user, a majority of interactions with a particular user-interface element are performed via a keyboard;

(B) determining that in previous usage sessions of said user, a majority of interactions with said particular user-interface element were performed via an input-unit other than the keyboard;

(C) based on the cumulative determining operations of steps (A) and (B), determining that the current usage session is attributed to a cyber-attacker and not to the authorized user.

6. A method comprising:

(a) monitoring user interactions of a user, who utilizes a computing device to interact with a computerized service during a usage session;

(b) for each particular type of data entry method that the user utilizes during said usage session:

(b1) determining a current number of occurrences of utilization of said particular type of data entry method during said usage session, and generating output corresponding to said current number of occurrences during said usage session;

(b2) determining a ratio between (A) said current number of occurrences of utilization of said particular type of data entry method during said usage session, and (B) an average number of occurrences of utilization of said particular type of data entry method during previous usage sessions of said user; and generating output corresponding to said ratio;

(b3) based on (i) said current number of occurrences, and (ii) said average number of occurrences during previous usage sessions of said user, determining whether said user is an authorized user or a cyber-attacker;

wherein the determining of step (b3) is performed by:

(A) determining that in the current usage session of said user, a majority of interactions with a particular user-interface element are performed via a touch-screen;

(B) determining that in previous usage sessions of said user, a majority of interactions with said particular user-interface element were performed via an input-unit other than the touch-screen;

(C) based on the cumulative determining operations of steps (A) and (B), determining that the current usage session is attributed to a cyber-attacker and not to the authorized user.

7. A method comprising:

(a) monitoring user interactions of a user, who utilizes a computing device to interact with a computerized service during a usage session;

(b) for each particular type of data entry method that the user utilizes during said usage session:

(b1) determining a current number of occurrences of utilization of said particular type of data entry method during said usage session, and generating output corresponding to said current number of occurrences during said usage session;

(b2) determining a ratio between (A) said current number of occurrences of utilization of said particular type of data entry method during said usage session, and (B) an average number of occurrences of utilization of said particular type of data entry method during previous usage sessions of said user; and generating output corresponding to said ratio;

(b3) based on (i) said current number of occurrences, and (ii) said average number of occurrences during previous usage sessions of said user, determining whether said user is an authorized user or a cyber-attacker;

wherein the determining of step (b3) is performed by:

(A) determining that in the current usage session of said user, a majority of interactions with a particular user-interface element are performed via a computer mouse;

(B) determining that in previous usage sessions of said user, a majority of interactions with said particular user-interface element were performed via an input-unit other than the computer mouse;

(C) based on the cumulative determining operations of steps (A) and (B), determining that the current usage session is attributed to a cyber-attacker and not to the authorized user.

8. A method comprising:

(a) monitoring user interactions of a user, who utilizes a computing device to interact with a computerized service during a usage session;

(b) for each particular type of data entry method that the user utilizes during said usage session:

(b1) determining a current number of occurrences of utilization of said particular type of data entry method during said usage session, and generating output corresponding to said current number of occurrences during said usage session;

(b2) determining a ratio between (A) said current number of occurrences of utilization of said particular type of data entry method during said usage session, and (B) an average number of occurrences of utilization of said particular type of data entry method during previous usage sessions of said user; and generating output corresponding to said ratio;

(b3) based on (i) said current number of occurrences, and (ii) said average number of occurrences during previous usage sessions of said user, determining whether said user is an authorized user or a cyber-attacker;

wherein the determining of step (b3) is performed by:

(A) determining that in the current usage session of said user, a majority of interactions with a particular user-interface element are performed via a touch-pad;

(B) determining that in previous usage sessions of said user, a majority of interactions with said particular user-interface element were performed via an input-unit other than the touch-pad;

(C) based on the cumulative determining operations of steps (A) and (B), determining that the current usage session is attributed to a cyber-attacker and not to the authorized user.

9. A method comprising:

(a) monitoring user interactions of a user, who utilizes a computing device to interact with a computerized service during a usage session;

(b) for each particular type of data entry method that the user utilizes during said usage session:

(b1) determining a current number of occurrences of utilization of said particular type of data entry method during said usage session, and generating output corresponding to said current number of occurrences during said usage session;

(b2) determining a ratio between (A) said current number of occurrences of utilization of said particular type of data entry method during said usage session, and (B) an average number of occurrences of utilization of said particular type of data entry method during previous usage sessions of said user; and generating output corresponding to said ratio;

(b3) based on (i) said current number of occurrences, and (ii) said average number of occurrences during previous usage sessions of said user, determining whether said user is an authorized user or a cyber-attacker;

wherein the determining of step (b3) is performed by:

(A) defining a first data-entry method that users can utilize to engage with a particular user-interface element;

(B) defining a second, different, data-entry method that users can utilize to engage with said particular user-interface element;

(C) for a particular usage session of said user, which is being reviewed for possible fraud, comparing between: (I) a number of times that said user utilized the first data-entry method to engage with said particular user-interface element during said particular usage session being reviewed, and (II) a number of times that said user utilized the second data-entry method to engage with said particular user-interface element during said particular usage session being reviewed.

10. The method of claim 9 ,

wherein step (b2) further comprises:

determining also a user-to-population ratio between (A) said current number of occurrences of utilization of said particular type of data entry method during said usage session by said user, and (B) an average number of occurrences of utilization of said particular type of data entry method during previous usage sessions of a group of users; and generating output corresponding to said user-to-population ratio.

11. A method comprising:

(a) monitoring user interactions of a user, who utilizes a computing device to interact with a computerized service during a usage session;

(b) for each particular type of data entry method that the user utilizes during said usage session:

(b1) determining a current number of occurrences of utilization of said particular type of data entry method during said usage session, and generating output corresponding to said current number of occurrences during said usage session;

(b2) determining a ratio between (A) said current number of occurrences of utilization of said particular type of data entry method during said usage session, and (B) an average number of occurrences of utilization of said particular type of data entry method during previous usage sessions of said user; and generating output corresponding to said ratio;

(b3) based on (i) said current number of occurrences, and (ii) said average number of occurrences during previous usage sessions of said user, determining whether said user is an authorized user or a cyber-attacker;

wherein the determining of step (b3) is performed by:

(A) defining a first data-entry method that users can utilize to engage with a particular user-interface element;

(B) defining a second, different, data-entry method that users can utilize to engage with said particular user-interface element;

(C) for all previous usage session of said user with said computerized service, comparing between: (I) an aggregate number of times that said user utilized the first data-entry method to engage with said particular user-interface element during all previous usage sessions, and (II) an aggregate number of times that said user utilized the second data-entry method to engage with said particular user-interface element during all previous usage sessions.

Assignments (4)
INTELLECTUAL PROPERTY SECURITY AGREEMENT TERMINATION UNDER REEL/FRAME: 049480/0823 Recorded Sep 14, 2020
From: KREOS CAPITAL VI (EXPERT FUND) LP
To: BIOCATCH LTD.
Reel/Frame 053769/0729 →
SECURITY INTEREST Recorded Jun 16, 2019
From: BIOCATCH LTD.
To: KREOS CAPITAL VI (EXPERT FUND) L.P.
Reel/Frame 049480/0823 →
CHANGE OF ADDRESS Recorded Jun 13, 2019
From: BIOCATCH LTD.
To: BIOCATCH LTD.
Reel/Frame 049459/0302 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2016
From: TURGEMAN, AVI
To: BIOCATCH LTD.
Reel/Frame 040741/0550 →
Continuity (16)
Continuation In Part 14675765 · Apr 1, 2015
Continuation In Part 14566723 · Dec 11, 2014
Continuation 13922271 · Jun 20, 2013
Continuation In Part 13877676
Continuation In Part 14320653 · Jul 1, 2014
Continuation In Part 14320656 · Jul 1, 2014
Continuation In Part 14325393 · Jul 8, 2014
Continuation In Part 14325394 · Jul 8, 2014
Continuation In Part 14325395 · Jul 8, 2014
Continuation In Part 14325396 · Jul 8, 2014
Continuation In Part 14325397 · Jul 8, 2014
Continuation In Part 14325398 · Jul 8, 2014
Provisional Application 61973855 · Apr 2, 2014
Provisional Application 61417479 · Nov 29, 2010
Provisional Application 61843915 · Jul 9, 2013
Related Publication 20170085587A1 · Mar 23, 2017
Cited By (22)
US 12,190,330 US 12,204,564 US 12,216,794 US 12,238,101 US 12,259,882 US 12,265,896 US 12,277,232 US 12,288,233 US 12,299,065 US 12,328,324 US 12,353,405 US 12,381,915 US 12,406,263 US 12,412,140 US 12,520,142 US 12,536,329 US 12,591,828 US 12,609,938 US 12,641,108 US 12,688,324 US 12,694,044 US 12,718,167