IP Library Granted Patent US 10,834,590
Granted Patent B2
US 10,834,590 · App. 15/885,819 · Granted Nov 10, 2020

Method, device, and system of differentiating between a cyber-attacker and a legitimate user

Inventors: Avi Turgeman (Cambridge, MA); Oren Kedem (Tel Aviv, IL); Uri Rivner (Mazkeret Batya, IL)
Assignee: BIOCATCH LTD.
H04W12/06G06F3/041G06F21/31G06F21/316G06F21/554G06F21/83H04L63/0861H04M1/72522G06F21/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,834,590
App. No.
15/885,819
Granted
Nov 10, 2020
Kind
B2
Abstract

Devices, systems, and methods of detecting user identity, differentiating between users of a computerized service, and detecting a cyber-attacker. A user utilizes a desktop computer, a laptop computer, a smartphone, a tablet, or other electronic device, to interact with a banking website or application, a retailer website or application, or other computerized service. Input-unit interactions are monitored, logged, and analyzed. Based on several types of analysis of the input-unit interactions, a score is generated to reflect fraud-relatedness or attack-relatedness of the input-unit interactions. Based on the score, the system estimates or determines whether the user is an attacker, and initiates attach-mitigation operations or fraud-mitigation operations.

Claims (30)

1. A process comprising:

(a) monitoring input-unit interactions of a user, who utilizes during a usage session one or more input units of an electronic device to fill-out data in a fillable form of a computerized service;

(b1) if said input-unit interactions indicate that said user utilized keyboard shortcuts for data entry and for in-page navigation, then increasing an attack-relatedness score of said usage session;

(b2) detecting a particular typing rhythm of said user in said usage session; and if said particular typing rhythm matches one or more typing rhythms that are pre-defined as typing rhythms of attackers, then increasing said attack-relatedness score of said usage session;

wherein steps (b1) and (b2) analyze a batch of input-unit interactions which includes interactions that were performed across multiple fillable forms that were filled by said user;

wherein steps (b1) and (b2) analyze a batch of input-unit interactions which includes interactions across multiple web-pages that belong to a single usage session of said user;

(c) if said attack-relatedness score is greater than a particular threshold value, then: determining that said input-unit interactions are part of an attack, and initiating one or more mitigation operations.

2. The process of claim 1 ,

wherein steps (b1) through (b2) further analyze a batch of input-unit interactions which includes interactions that were performed within a single fillable form.

3. The process of claim 1 ,

wherein steps (b1) through (b2) analyze said batch of input-unit interactions which are interactions of a new user (I) that is not logged-in to said computerized service and (II) that is accessing said computerized service for his first time and (III) that is not associated with any pre-defined user profile derived from prior visits of said user.

4. The process of claim 1 ,

wherein steps (b1) through (b2) analyze said batch of input-unit interactions which are interactions of a user that already passed a CAPTCHA challenge and already proved to the computerized service that he is a human and not a machine.

5. The process of claim 1 ,

wherein steps (b1) through (b2) analyze said batch of input-unit interactions which are interactions of an already logged-in user that had successfully authenticated himself to the computerized service; wherein the process comprises determining that said user is an attacker even though he had successfully authenticated himself to the computerized service.

6. A non-transitory storage medium having stored thereon instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform a method comprising:

(a) monitoring input-unit interactions of a user, who utilizes during a usage session one or more input units of an electronic device to fill-out data in a fillable form of a computerized service;

(b1) if said input-unit interactions indicate that said user utilized keyboard shortcuts for data entry and for in-page navigation, then increasing an attack-relatedness score of said usage session;

(b2) detecting a particular typing rhythm of said user in said usage session; and if said particular typing rhythm matches one or more typing rhythms that are pre-defined as typing rhythms of attackers, then increasing said attack-relatedness score of said usage session;

wherein steps (b1) and (b2) analyze a batch of input-unit interactions which includes interactions that were performed across multiple fillable forms that were filled by said user;

wherein steps (b1) and (b2) analyze a batch of input-unit interactions which includes interactions across multiple web-pages that belong to a single usage session of said user;

(c) if said attack-relatedness score is greater than a particular threshold value, then: determining that said input-unit interactions are part of an attack, and initiating one or more mitigation operations.

7. A system comprising:

one or more hardware processors, that are configured to perform:

(a) monitoring input-unit interactions of a user, who utilizes during a usage session one or more input units of an electronic device to fill-out data in a fillable form of a computerized service;

(b1) if said input-unit interactions indicate that said user utilized keyboard shortcuts for data entry and for in-page navigation, then increasing an attack-relatedness score of said usage session;

(b2) detecting a particular typing rhythm of said user in said usage session; and if said particular typing rhythm matches one or more typing rhythms that are pre-defined as typing rhythms of attackers, then increasing said attack-relatedness score of said usage session;

wherein steps (b1) and (b2) analyze a batch of input-unit interactions which includes interactions that were performed across multiple fillable forms that were filled by said user;

wherein steps (b1) and (b2) analyze a batch of input-unit interactions which includes interactions across multiple web-pages that belong to a single usage session of said user;

(c) if said attack-relatedness score is greater than a particular threshold value, then: determining that said input-unit interactions are part of an attack, and initiating one or more mitigation operations.

Assignments (4)
INTELLECTUAL PROPERTY SECURITY AGREEMENT TERMINATION UNDER REEL/FRAME: 049480/0823 Recorded Sep 14, 2020
From: KREOS CAPITAL VI (EXPERT FUND) LP
To: BIOCATCH LTD.
Reel/Frame 053769/0729 →
SECURITY INTEREST Recorded Jun 16, 2019
From: BIOCATCH LTD.
To: KREOS CAPITAL VI (EXPERT FUND) L.P.
Reel/Frame 049480/0823 →
CHANGE OF ADDRESS Recorded Jun 13, 2019
From: BIOCATCH LTD.
To: BIOCATCH LTD.
Reel/Frame 049459/0302 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2018
From: TURGEMAN, AVI; KEDEM, OREN; RIVNER, URI
To: BIOCATCH LTD.
Reel/Frame 045112/0558 →
Continuity (16)
Continuation In Part 14675764 · Apr 1, 2015
Continuation In Part 14566723 · Dec 11, 2014
Continuation 13922271 · Jun 20, 2013
Continuation In Part 13877676
Continuation In Part 14320653 · Jul 1, 2014
Continuation In Part 14320656 · Jul 1, 2014
Continuation In Part 14325393 · Jul 8, 2014
Continuation In Part 14325394 · Jul 8, 2014
Continuation In Part 14325395 · Jul 8, 2014
Continuation In Part 14325396 · Jul 8, 2014
Continuation In Part 14325397 · Jul 8, 2014
Continuation In Part 14325398 · Jul 8, 2014
Provisional Application 61973855 · Apr 2, 2014
Provisional Application 61417479 · Nov 29, 2010
Provisional Application 61843915 · Jul 9, 2013
Related Publication 20180160309A1 · Jun 7, 2018
Cited By (22)
US 12,190,330 US 12,204,564 US 12,216,794 US 12,238,101 US 12,259,882 US 12,265,896 US 12,277,232 US 12,288,233 US 12,299,065 US 12,353,405 US 12,381,915 US 12,406,263 US 12,412,140 US 12,520,142 US 12,536,329 US 12,591,828 US 12,609,938 US 12,641,108 US 12,688,324 US 12,694,044 US 12,717,932 US 12,718,167