IP Library Granted Patent US 10,069,852
Granted Patent B2
US 10,069,852 · App. 15/840,035 · Granted Sep 4, 2018

Detection of computerized bots and automated cyber-attack modules

Inventors: Avi Turgeman (Cambridge, MA); Itai Novick (Rehovot, IL)
Assignee: BIOCATCH LTD.
H04L63/1416G01R29/26G06F21/121G06F21/316G06F21/552G06F21/554G06Q20/4014G06Q20/4016H04L63/08H04L63/126H04L63/1441G06F2221/2133H04L63/083H04L63/102H04L2463/082H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,069,852
App. No.
15/840,035
Granted
Sep 4, 2018
Kind
B2
Abstract

Devices, systems, and methods of detecting whether an electronic device or computerized device or computer, is being controlled by a legitimate human user, or by an automated cyber-attack unit or malware or automatic script. The system monitors interactions performed via one or more input units of the electronic device. The system searches for abnormal input-user interactions; or for an abnormal discrepancy between: the input-unit gestures that were actually registered by the input unit, and the content that the electronic device reports as allegedly entered via such input units. A discrepancy or abnormality indicates that more-possibly, or necessarily or certainly, a malware or automated script is controlling the electronic device, rather than a legitimate human user. Optionally, an input-output aberration or interference is injected, in order to check for manual corrective actions that only a human user, and not an automated script, is able to perform.

Claims (82)

1. A method comprising:

(A) detecting an automated malware that emulates human interactions with a computerized service;

wherein the detecting of step (A) comprises:

(a) monitoring input-unit interactions of an electronic device that is utilized by a user to interact with said computerized service;

(b) injecting an input-output aberration into a web-page, and monitoring whether manual corrective actions were manually performed in response to the input-output aberration;

(c) analyzing said input-unit interactions;

(d) determining that it is humanly-impossible for a human to perform said input-user interactions;

(e) based on the determining of step (d), determining that said input-unit interactions were necessarily performed by said automated script that emulates human interactions, and not by a human user;

wherein the determining of step (e), that said input-unit interactions were necessarily performed by said automated script, is further based on: detecting that corrective actions that were performed in response to said input-output aberration were insufficient to adequately cure the input-output aberration.

2. A method comprising:

(A) detecting an automated malware that emulates human interactions with a computerized service;

wherein the detecting of step (A) comprises:

(a) monitoring input-unit interactions of an electronic device that is utilized by a user to interact with said computerized service;

(b) injecting an input-output aberration into a web-page, and monitoring whether manual corrective actions were manually performed in response to the input-output aberration;

(c) analyzing said input-unit interactions;

(d) determining that it is humanly-impossible for a human to perform said input-user interactions;

(e) based on the determining of step (d), determining that said input-unit interactions were necessarily performed by said automated script that emulates human interactions, and not by a human user;

wherein the method comprises:

(i) monitoring key-down events, and key-up events, during a usage session in which said electronic device exhibits reception of keyboard input;

(ii) determining that the number of key-down events does not match the number of key-up events, during said usage session;

(iii) based on step (ii), determining that said input-unit interactions were necessarily performed by said automated script that emulates human interactions, and not by a human user.

3. A method comprising:

(A) detecting an automated malware that emulates human interactions with a computerized service;

wherein the detecting of step (A) comprises:

(a) monitoring input-unit interactions of an electronic device that is utilized by a user to interact with said computerized service;

(b) injecting an input-output aberration into a web-page, and monitoring whether manual corrective actions were manually performed in response to the input-output aberration;

(c) analyzing said input-unit interactions;

(d) determining that it is humanly-impossible for a human to perform said input-user interactions;

(e) based on the determining of step (d), determining that said input-unit interactions were necessarily performed by said automated script that emulates human interactions, and not by a human user;

wherein the method comprises:

(i) monitoring key-down events, and monitoring key-up events, during a usage session in which said electronic device exhibits reception of keyboard input;

(ii) determining that the order of the key-down events and the key-up events, during said usage session, does not match an expected order of key-down events and key-up events that is expected to be observed if an input unit of said electronic device is utilized for typing by a human user;

(iii) based on step (ii), determining that said input-unit interactions were necessarily performed by said automated script that emulates human interactions, and not by a human user.

4. A method comprising:

(A) detecting an automated malware that emulates human interactions with a computerized service;

wherein the detecting of step (A) comprises:

(a) monitoring input-unit interactions of an electronic device that is utilized by a user to interact with said computerized service;

(b) injecting an input-output aberration into a web-page, and monitoring whether manual corrective actions were manually performed in response to the input-output aberration;

(c) analyzing said input-unit interactions;

(d) determining that it is humanly-impossible for a human to perform said input-user interactions;

(e) based on the determining of step (d), determining that said input-unit interactions were necessarily performed by said automated script that emulates human interactions, and not by a human user;

wherein the method comprises:

(i) continuously monitoring mouse events, during a usage session in which said electronic device exhibits reception of mouse-based input;

(ii) determining that during a first period of time within said usage session, the monitored mouse events exhibit a first sampling rate;

(iii) determining that during a second period of time within said usage session, the monitored mouse events exhibit a second, different, sampling rate;

(iv) based on steps (ii) and (iii), determining that said electronic device is necessarily controlled by an automated module, and not by a legitimate human user.

5. A method comprising:

(A) detecting an automated malware that emulates human interactions with a computerized service;

wherein the detecting of step (A) comprises:

(a) monitoring input-unit interactions of an electronic device that is utilized by a user to interact with said computerized service;

(b) injecting an input-output aberration into a web-page, and monitoring whether manual corrective actions were manually performed in response to the input-output aberration;

(c) analyzing said input-unit interactions;

(d) determining that it is humanly-impossible for a human to perform said input-user interactions;

(e) based on the determining of step (d), determining that said input-unit interactions were necessarily performed by said automated script that emulates human interactions, and not by a human user;

wherein the method comprises:

(i) continuously monitoring keyboard events, during a usage session in which said electronic device exhibits reception of keyboard-based input;

(ii) determining that during a first period of time within said usage session, the monitored keyboard events exhibit a first sampling rate;

(iii) determining that during a second period of time within said usage session, the monitored keyboard events exhibit a second, different, sampling rate;

(iv) based on steps (ii) and (iii), determining that said electronic device is necessarily controlled by an automated attacking module, and not by a legitimate human user.

6. A method comprising:

(A) detecting an automated malware that emulates human interactions with a computerized service;

wherein the detecting of step (A) comprises:

(a) monitoring input-unit interactions of an electronic device that is utilized by a user to interact with said computerized service;

(b) injecting an input-output aberration into a web-page, and monitoring whether manual corrective actions were manually performed in response to the input-output aberration;

(c) analyzing said input-unit interactions;

(d) determining that it is humanly-impossible for a human to perform said input-user interactions;

(e) based on the determining of step (d), determining that said input-unit interactions were necessarily performed by said automated script that emulates human interactions, and not by a human user;

wherein the method comprises:

(i) detecting that an input-unit level of the electronic device reports that a message of M characters was manually entered via an input-unit of the electronic device;

(ii) detecting that said electronic device sends to a remote server, an outgoing message of N characters that was allegedly typed on said electronic device, wherein N is different than M;

(iii) based on the determining of steps (i) and (ii), further determining that said electronic device is necessarily controlled by an automated module, and not by a legitimate human user.

7. A method comprising:

(A) detecting an automated script that emulates human interactions with a computerized service;

wherein the detecting of step (A) comprises:

(a) monitoring input-unit interactions of an electronic device that is utilized by a user to interact with said computerized service;

(b) allocating to each monitored input-unit interaction, a respective score-value that quantifies, on a scale of M to N, how difficult it is for a human user to perform said input-unit interaction;

(c) determining a weighted score that corresponds to a set of multiple monitored input-user interactions, based on the respective score-value of each one of said multiple monitored input-user interactions;

(d) if said weighted score is greater than a threshold value, then determining that said set of multiple monitored input-unit interactions were necessarily performed by said automated script, and not by a human user.

8. The method of claim 7 ,

wherein the monitoring of step (a) comprises: monitoring input-unit interactions in response to an input-output aberration that was injected into a web-page and that requires manual corrective actions.

9. The method of claim 7 ,

wherein the monitoring of step (a) comprises: monitoring input-unit interactions in response to an input-output aberration that was injected into an application element and that requires manual corrective actions.

Assignments (4)
INTELLECTUAL PROPERTY SECURITY AGREEMENT TERMINATION UNDER REEL/FRAME: 049480/0823 Recorded Sep 14, 2020
From: KREOS CAPITAL VI (EXPERT FUND) LP
To: BIOCATCH LTD.
Reel/Frame 053769/0729 →
SECURITY INTEREST Recorded Jun 16, 2019
From: BIOCATCH LTD.
To: KREOS CAPITAL VI (EXPERT FUND) L.P.
Reel/Frame 049480/0823 →
CHANGE OF ADDRESS Recorded Jun 13, 2019
From: BIOCATCH LTD.
To: BIOCATCH LTD.
Reel/Frame 049459/0302 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2018
From: TURGEMAN, AVI; NOVICK, ITAI
To: BIOCATCH LTD.
Reel/Frame 045029/0666 →
Continuity (12)
Continuation In Part 15465623 · Mar 22, 2017
Continuation In Part 15198199 · Jun 30, 2016
Continuation In Part 15194593 · Jun 28, 2016
Continuation In Part 14736287 · Jun 11, 2015
Continuation In Part 14325394 · Jul 8, 2014
Continuation In Part 14325393 · Jul 8, 2014
Continuation In Part 13922271 · Jun 20, 2013
Continuation In Part 13877676
Provisional Application 62190264 · Jul 9, 2015
Provisional Application 61843915 · Jul 9, 2013
Provisional Application 61417479 · Nov 29, 2010
Related Publication 20180103047A1 · Apr 12, 2018
Cited By (62)
US 12,192,026 US 12,200,038 US 12,200,083 US 12,200,084 US 12,218,776 US 12,218,777 US 12,229,210 US 12,231,253 US 12,231,519 US 12,250,089 US 12,250,090 US 12,260,364 US 12,261,712 US 12,277,187 US 12,277,188 US 12,277,189 US 12,278,878 US 12,278,880 US 12,284,069 US 12,287,873 US 12,289,383 US 12,292,951 US 12,294,481 US 12,301,401 US 12,309,123 US 12,309,241 US 12,323,287 US 12,323,500 US 12,323,501 US 12,332,960 US 12,341,860 US 12,355,855 US 12,356,042 US 12,368,789 US 12,375,516 US 12,375,582 US 12,380,455 US 12,411,902 US 12,413,648 US 12,425,492 US 12,438,956 US 12,445,511 US 12,457,273 US 12,483,635 US 12,517,972 US 12,524,490 US 12,524,491 US 12,536,243 US 12,542,764 US 12,549,645 US 12,563,130 US 12,587,429 US 12,587,430 US 12,587,579 US 12,603,809 US 12,652,330 US 12,659,218 US 12,671,750 US 12,706,984 US 12,719,734 US 12,719,735 US 12,719,945