Detecting non-human users on computer systems
Abstract
A method including collecting, by a processing device, raw data regarding an input to fill a form field. The method further includes converting, by the processing device, the raw data to test data, wherein the test represents behavioral characteristics of the entry of the input. The method further includes identifying a human characteristic model corresponding to the behavior characteristics of the entry of the input. The method further includes generating a predictor from a comparison of the test data against the corresponding human characteristic model. The predictor includes a score indicating a probability that the input originated from a human user or from a malicious code imitating the human user.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
collecting, by a processing device, raw data relating to entry of an input at a form field; converting, by the processing device, the raw data to test data, wherein the test data represents behavioral characteristics of the entry of the input; identifying a human characteristic model corresponding to the behavior characteristics of the entry of the input; and generating a predictor from a comparison of the test data against the corresponding human characteristic model, wherein the predictor comprises a score indicating a probability that the input originated from a human user or from a malicious code imitating the human user.
2 . The method of claim 1 , wherein the human characteristic model comprises aspects of a human input different from aspects of a malicious code input.
3 . The method of claim 1 , wherein the input to fill the form field comprises a user input at a physical user interface device, the physical user interface device comprising one or more of a list of sensor devices to collect the raw data, the list comprising:
a keyboard; a mouse; a touch interface; an accelerometer; and a gyroscope.
4 . The method of claim 1 , wherein the input to fill the form field comprises a user input at a virtual user interface device.
5 . The method of claim 4 , wherein the virtual user interface device comprises a cognitive transform to render the virtual user interface device visually interpretable by the human user and at least partially prohibitive to interpretation by the malicious code.
6 . The method of claim 1 , wherein the input to fill the form field is prompted by display of a response image, wherein the response image is based on a user request and visually incorporates at least a portion of the user request.
7 . The method of claim 6 , wherein the input to fill the form field is checked against a correct interpretation to verify the user request.
8 . A non-transitory computer readable storage medium including instructions that, when executed by a computing system, cause the computing system to perform operations comprising:
generating, by a processing device, a virtual user interface to facilitate a user interaction at the virtual user interface, wherein the virtual user interface comprises a cognitive transform to render the virtual user interface visually interpretable by a human user and at least partially prohibitive to interpretation by malicious code; collecting, by the processing device, an output value from the virtual user interface based on a user interaction with the virtual user interface; collecting, by the processing device, raw data regarding the user interaction at the virtual user interface, wherein the raw data is detected by one or more of a list of sensor devices, the list comprising: a keyboard; a mouse; a touch interface; an accelerometer; and a gyroscope; converting, by the processing device, the raw data to test data, wherein the test data represents behavior characteristics of the human user; identifying, by the processing device, a characteristic model corresponding to the behavior characteristics generating, by the processing device, a predictor from a comparison of the test data against the corresponding characteristic model to differentiate the human user from the malicious code imitating the human user; and analyzing, by the processing device, the output values from the virtual user interface for correctness to differentiate the human user from the malicious code imitating the human user.
9 . The non-transitory computer readable storage medium of claim 8 , wherein the cognitive transform comprises a substitution of at least one image object into the virtual user interface in place of a corresponding character object within the virtual user interface.
10 . The non-transitory computer readable storage medium of claim 9 , wherein a copy of the at least one image object is input into a form field in response to detection of the user interaction at the at least one image object in the virtual user interface.
11 . The non-transitory computer readable storage medium of claim 8 , wherein the cognitive transform comprises a displacement of a first object within the virtual user interface relative to second object of the virtual user interface.
12 . The non-transitory computer readable storage medium of claim 8 , wherein the cognitive transform comprises a re-sequencing of one or more objects within the virtual user interface.
13 . The non-transitory computer readable storage medium of claim 8 , wherein the operations further comprise:
displaying a response image in response to a user request, wherein the response image visually incorporates at least a portion of the user request; and requesting entry of the user interaction at the virtual user interface to interpret the response image.
14 . The non-transitory computer readable storage medium of claim 13 , wherein the operations further comprise comparing the user interaction at the virtual user interface against a correct interpretation to differentiate the human user from the malicious code.
15 . A computing system, comprising:
a data storage device; and a processing device, coupled to the data storage device, to:
receive a user request;
generate a response image based on the user request, wherein at least a portion of the user request is visually incorporated into the response image;
send the response image;
receive a user interpretation of the response image; and
compare the user interpretation against a correct interpretation stored in the data storage device to verify the user request and to differentiate a human user from malicious code imitating the human user.
16 . The computing system of claim 15 , wherein the response image based on the user request comprises a visual distortion of a character within the response image.
17 . The computing system of claim 15 , wherein the response image comprises at least one random character combined with the at least a portion of the user request.
18 . The computing system of claim 15 , wherein the user request and the user interpretation of the response image are input at a virtual user interface, the virtual user interface comprising a cognitive transform to render the virtual user interface visually interpretable by the human user and at least partially prohibitive to interpretation by the malicious code.
19 . The computing system of claim 18 , wherein the cognitive transform comprises one or more of a list of transforms, the list comprising:
a substitution of at least one image object into the virtual user interface in place of a corresponding character object within the virtual user interface; a displacement of a first object within the virtual user interface relative to second object of the virtual user interface; and a re-sequencing of an object within the virtual user interface.
20 . The computing system of claim 15 , the processing device further to:
collect raw data regarding the user request, wherein the raw data is detected by one or more of a list of sensor devices, the list comprising: a keyboard; a mouse; a touch interface; an accelerometer; and a gyroscope; convert the raw data to test data, wherein the test data represents behavior characteristics of the human user; identify a characteristic model corresponding to the behavior characteristics; and generate a predictor from a comparison of the test data against the corresponding characteristic model, wherein the predictor comprises a score indicating a probability that the user request came from a human user or from a malicious code imitating the human user.Join the waitlist — get patent alerts
Track US2017235954A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.