IP Library Granted Patent US 10,474,815
Granted Patent B2
US 10,474,815 · App. 15/372,420 · Granted Nov 12, 2019

System, device, and method of detecting malicious automatic script and code injection

Inventor: Avi Turgeman (Cambridge, MA)
Assignee: BIOCATCH LTD.
G06F21/554G06F21/316G06F21/32H04L63/145G06F21/31G06F21/55G06F2221/034G06F2221/21G06F2221/2133
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,474,815
App. No.
15/372,420
Granted
Nov 12, 2019
Kind
B2
Abstract

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a possible attacker. The methods include monitoring of user-side input-unit interactions, in general and in response to an interference introduced to user-interface elements. The monitored interactions are used for detecting an attacker that utilizes a remote access channel; for detecting a malicious automatic script, as well as malicious code injection; to identify a particular hardware assembly; to perform user segmentation or user characterization; to enable a visual login process with implicit two-factor authentication; to enable stochastic cryptography; and to detect that multiple users are utilizing the same subscription account.

Claims (22)

1. A method comprising:

determining that a first string that was inputted via manual keyboard input by a user, who utilizes an electronic device to interact with a computerized service, was replaced with a second string by a malware automatic script that is running on said electronic device;

wherein the determining comprises:

(a) at said electronic device, monitoring keystrokes that are actually entered manually through a keyboard unit of said electronic device;

(b) generating a first data-item that indicates the number of keystrokes that were actually entered manually through said keyboard unit based on client-side monitoring of typing of said first string that was typed in a particular on-screen field;

(c1) at a remote server that is in communication with said electronic device, receiving a second string that was transmitted by the electronic device to said remote server wherein said second string is submitted to said remote server by said electronic device as reflecting manual keyboard entry of said user in said particular on-screen field;

(c2) at said remote server, receiving from said electronic device the first data-item which indicates the number of keystrokes that were actually entered manually through said keyboard unit based on client-side monitoring of typing of said first string that was typed in said particular on-screen field;

(c3) at said remote server, determining the character length of said second string that was received at said remote server;

(d) detecting that (I) the value of the first data-item that was received at said remote server at step (c2) which indicates the number of keystrokes that were actually entered manually through said keyboard unit based on client-side monitoring of client-side data, is different from (II) the character length that was determined by the remote server in step (c2) for the second string that was received at said remote server in step (c1);

(e) based on the detecting of step (d), determining that a malware automatic script was running on said electronic device, and replaced (I) the first string that was manually entered into said particular on-screen field, with (II) the second, different, string.

2. The method of claim 1 , wherein said keyboard unit of the electronic device is a hardware-based physical keyboard.

3. The method of claim 1 , wherein said keyboard unit of the electronic device is an on-screen keyboard that is operated via a touch-screen of said electronic device.

4. A non-transitory storage medium having stored thereon instructions that, when executed by a hardware processor, cause the hardware processor to perform a method comprising:

determining that a first string that was inputted via manual keyboard input by a user, who utilizes an electronic device to interact with a computerized service, was replaced with a second string by a malware automatic script that is running on said electronic device;

wherein the determining comprises:

(a) at said electronic device, monitoring keystrokes that are actually entered manually through a keyboard unit of said electronic device;

(b) generating a first data-item that indicates the number of keystrokes that were actually entered manually through said keyboard unit based on client-side monitoring of typing of said first string that was typed in a particular on-screen field;

(c1) at a remote server that is in communication with said electronic device, receiving a second string that was transmitted by the electronic device to said remote server wherein said second string is submitted to said remote server by said electronic device as reflecting manual keyboard entry of said user in said particular on-screen field;

(c2) at said remote server, receiving from said electronic device the first data-item which indicates the number of keystrokes that were actually entered manually through said keyboard unit based on client-side monitoring of typing of said first string that was typed in said particular on-screen field;

(c3) at said remote server, determining the character length of said second string that was received at said remote server;

(d) detecting that (I) the value of the first data-item that was received at said remote server at step (c2) which indicates the number of keystrokes that were actually entered manually through said keyboard unit based on client-side monitoring of client-side data, is different from (II) the character length that was determined by the remote server in step (c2) for the second string that was received at said remote server in step (c1);

(e) based on the detecting of step (d), determining that a malware automatic script was running on said electronic device, and replaced (I) the first string that was manually entered into said particular on-screen field, with (II) the second, different, string.

Assignments (4)
INTELLECTUAL PROPERTY SECURITY AGREEMENT TERMINATION UNDER REEL/FRAME: 049480/0823 Recorded Sep 14, 2020
From: KREOS CAPITAL VI (EXPERT FUND) LP
To: BIOCATCH LTD.
Reel/Frame 053769/0729 →
SECURITY INTEREST Recorded Jun 16, 2019
From: BIOCATCH LTD.
To: KREOS CAPITAL VI (EXPERT FUND) L.P.
Reel/Frame 049480/0823 →
CHANGE OF ADDRESS Recorded Jun 13, 2019
From: BIOCATCH LTD.
To: BIOCATCH LTD.
Reel/Frame 049459/0302 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 25, 2016
From: TURGEMAN, AVI
To: BIOCATCH LTD.
Reel/Frame 040762/0097 →
Continuity (8)
Continuation In Part 14325394 · Jul 8, 2014
Continuation In Part 13922271 · Jun 20, 2013
Continuation In Part 13877676
Continuation In Part 14320653 · Jul 1, 2014
Continuation In Part 14320656 · Jul 1, 2014
Provisional Application 61843915 · Jul 9, 2013
Provisional Application 61417479 · Nov 29, 2010
Related Publication 20170091450A1 · Mar 30, 2017
Cited By (5)
US 12,306,700 US 12,381,910 US 12,386,980 US 12,399,959 US 12,682,029