US2019158535A1PendingUtilityA1

Device, System, and Method of Detecting Vishing Attacks

Assignee: BIOCATCH LTDPriority: Nov 21, 2017Filed: Nov 13, 2018Published: May 23, 2019
Est. expiryNov 21, 2037(~11.3 yrs left)· nominal 20-yr term from priority
G06F 21/316G06F 21/554G06F 16/00G06F 3/03543G01C 9/00G06F 3/04883H04L 63/1483H04W 12/12H04L 67/02H04L 63/1425G06F 3/0227G06Q 20/4016H04W 12/128H04W 12/68
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Devices, systems, and methods of detecting a vishing attack, in which an attacker provides to a victim step-by-step over-the-phone instructions that command the victim to log-in to his bank account and to perform a dictated banking transaction. The system monitors transactions, online operations, user interactions, gestures performed via input units, speed and timing of data entry, and user engagement with User Interface elements. The system detects that the operations performed by the victim, follow a pre-defined playbook of a vishing attack. The system detects that the victim operates under duress or under dictated instructions, as exhibited in irregular doodling activity, data entry rhythm, typographical error introduction rhythm, unique posture of the user, alternating pattern of listening to phone instructions and performing online operations via a computer, and device orientation changes or spatial changes that characterize a device being used to perform an online transaction while also talking on the phone.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A process comprising:
 (a) monitoring information that includes at least one of: (i) user interactions of a user that utilizes an electronic device to interact with a computerized service, (ii) operational characteristics of said electronic device;   (b) analyzing said information, and determining that a set of operations were performed by said user as part of a vishing attack in which an attacker dictated to said user which operations to perform in said computerized service.   
     
     
         2 . The process of  claim 1 , comprising:
 monitoring an average typing speed of said user; and based on monitored average typing speed of said user, determining that said set of operations were performed as part of a vishing attack.   
     
     
         3 . The process of  claim 1 , comprising:
 monitoring an average mouse-click speed of said user; and based on monitored average mouse-clock speed of said user, determining that said set of operations were performed as part of a vishing attack.   
     
     
         4 . The process of  claim 1 , comprising:
 monitoring a usage-session time-length of multiple usage-sessions of said user; and based on monitored usage-session time-length, determining that said set of operations were performed as part of a vishing attack.   
     
     
         5 . The process of  claim 1 , comprising:
 monitoring periods of inactivity of said user during usage sessions; and based on monitored inactivity periods, determining that said set of operations were performed as part of a vishing attack.   
     
     
         6 . The process of  claim 1 , comprising:
 monitoring frequency of on-screen-pointer turns of said user; and based on monitored frequency of on-screen-pointer turns, determining that said set of operations were performed as part of a vishing attack.   
     
     
         7 . The process of  claim 1 , comprising:
 monitoring an average on-screen distance traveled between clicks of said user; and based on monitored on-screen distance traveled between clicks, determining that said set of operations were performed as part of a vishing attack.   
     
     
         8 . The process of  claim 1 , comprising:
 monitoring an average speed of movement of on-screen-pointer; and based on monitored average speed of movement of on-screen-pointer, determining that said set of operations were performed as part of a vishing attack.   
     
     
         9 . The process of  claim 1 , comprising:
 monitoring a ratio of displacement to distance of on-screen-pointer; and based on monitored ratio of displacement to distance, determining that said set of operations were performed as part of a vishing attack.   
     
     
         10 . The process of  claim 1 , comprising:
 monitoring accelerometer data of said electronic device, and determining that said electronic device is alternated by said user, between (i) a first position in which the electronic device is positioned generally-vertically at the user's ear and is used for talking, and (ii) a second position in which the electronic device is positioned generally-horizontally and is used for operating its touch-screen;   based on alternation back-and-forth between the first position and the second position, determining that said set of operations were performed as part of a vishing attack.   
     
     
         11 . The process of  claim 1 , comprising:
 monitoring gyroscope data of said electronic device, and determining that said electronic device is alternated by said user, between (i) a first position in which the electronic device is positioned generally-vertically at the user's ear and is used for talking, and (ii) a second position in which the electronic device is positioned generally-horizontally and is used for operating its touch-screen;   based on alternation back-and-forth between the first position and the second position, determining that said set of operations were performed as part of a vishing attack.   
     
     
         12 . The process of  claim 1 , comprising:
 monitoring device-orientation data of said electronic device, and determining that said electronic device is alternated by said user, between (i) a first position in which the electronic device is positioned generally-vertically at the user's ear and is used for talking, and (ii) a second position in which the electronic device is positioned generally-horizontally and is used for operating its touch-screen;   based on alternation back-and-forth between the first position and the second position, determining that said set of operations were performed as part of a vishing attack.   
     
     
         13 . The process of  claim 1 , comprising:
 instructing said electronic device to automatically play a particular video clip;   checking whether said video clip was actually played by said electronic device; and based on the checking result, determining that said set of operations were performed as part of a vishing attack.   
     
     
         14 . The process of  claim 1 , comprising:
 instructing said electronic device to automatically play a particular video clip that is non-observable to a user of said electronic device;   checking whether said video clip was actually played by said electronic device; and based on the checking result, determining that said set of operations were performed as part of a vishing attack.   
     
     
         15 . The process of  claim 1 , comprising:
 detecting a set of operations that were performed by said user via said electronic device, which triggers an initial estimation that said set of operations were performed within a vishing attack;   determining that said set of operations were performed during a nightly time-slot in which most users in a particular geographic region are asleep; and detecting that said initial estimation of a vishing attack is incorrect.   
     
     
         16 . The process of  claim 1 , comprising:
 (A) defining a parameter that indicates fluency of navigation of the user through multiple pages and multiple GUI elements of an online interface;   (B) tracking fluency of navigation of said user across multiple usage sessions, and updating said parameter;   (C) based on said parameter indicating fluency of navigation, determining that said set of operations were performed as part of a vishing attack.   
     
     
         17 . The process of  claim 1 , comprising:
 (A) defining a parameter that indicates characteristics of letter-chunks that the user enters consecutively;   (B) tracking data-entry by the user across multiple usage-sessions, and updating said parameter;   (C) based on said parameter indicating characteristics of letter-chunks, determining that said set of operations were performed as part of a vishing attack.   
     
     
         18 . The process of  claim 1 ,
 wherein determining that said set of operations were performed as part of a vishing attack, is based at least in part on detecting that a single online account of said user was accessed via multiple different login sessions within a pre-defined time period.   
     
     
         19 . The process of  claim 1 , comprising:
 monitoring characteristics of typing rhythm exhibited by said user; and based on monitored characteristics of typing rhythm, determining that said set of operations were performed as part of a vishing attack.   
     
     
         20 . The process of  claim 1 , comprising:
 (A) monitoring characteristics of typing rhythm exhibited by said user;   (B) determining that typing rhythm in a particular usage-session of said user, is sufficiently different from previous typing rethemes exhibited in multiple previous usage-sessions of said user; and determining that said particular usage-session was part of a vishing attack.   
     
     
         21 . The process of  claim 1 , comprising:
 instructing said electronic device to automatically play a particular audio clip;   checking whether said audio clip was actually played by said electronic device; and based on the checking result, determining that said set of operations were performed as part of a vishing attack.   
     
     
         22 . The process of  claim 1 , comprising:
 instructing said electronic device to automatically play a silent audio clip;   checking whether said silent audio clip was actually played by said electronic device; and   based on the checking result, determining that said set of operations were performed as part of a vishing attack.   
     
     
         23 . The process of  claim 1 , comprising:
 monitoring an average time-gap between on-screen taps that said user performs directly via a touch-screen; and based on monitored average time-gap between on-screen taps that said user performs directly via said touch-screen, determining that said set of operations were performed as part of a vishing attack.   
     
     
         24 . The process of  claim 1 , comprising:
 monitoring a maximum value of typing speed of said user; and based on monitored maximum value of typing speed of said user, determining that said set of operations were performed as part of a vishing attack.   
     
     
         25 . The process of  claim 1 , comprising:
 monitoring a minimum value of typing speed of said user; and based on monitored minimum value of typing speed of said user, determining that said set of operations were performed as part of a vishing attack.   
     
     
         26 . The process of  claim 1 , comprising:
 monitoring a maximum value of mouse-click speed of said user; and based on monitored maximum value of mouse-click speed of said user, determining that said set of operations were performed as part of a vishing attack.   
     
     
         27 . The process of  claim 1 , comprising:
 monitoring a minimum value of mouse-click speed of said user; and based on monitored minimum value of mouse-click speed of said user, determining that said set of operations were performed as part of a vishing attack.   
     
     
         28 . The process of  claim 1 , comprising:
 (A) detecting that user interactions, during a process of entering data of a financial transaction, include an average idle-time that is longer than a pre-defined threshold value of N seconds, wherein N is a positive number;   (B) based on the detecting of step (A), determining that said financial transaction was entered by a victim of a vishing attack.   
     
     
         29 . The process of  claim 1 , comprising:
 (A) detecting that user interactions, during a process of entering data of a financial transaction, include a number of idle-time events that is greater by at least N percent than a pre-defined threshold value, wherein N is a positive number;   (B) based on the detecting of step (A), determining that said financial transaction was entered by a victim of a vishing attack.   
     
     
         30 . The process of  claim 1 , comprising:
 (A) detecting that said user interactions, during a process of entering data of a financial transaction, exhibit a pattern of correction of typographical errors that is different from said pattern exhibited in previous usage-sessions of said user;   (B) based on step (A), determining that said financial transaction was entered by a victim of a vishing attack.   
     
     
         31 . The process of  claim 1 , comprising:
 (A) detecting that said user interactions, during a process of performing a financial transaction, exhibit a current number of user-hesitation indicators that is greater than a previous number of user-hesitation indicators that were exhibited in one or more previous usage-sessions of said user;   (B) based on step (A), determining that said financial transaction was entered by a victim of a vishing attack.

Join the waitlist — get patent alerts

Track US2019158535A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.