Device, System, and Method of Detecting Vishing Attacks
Abstract
Devices, systems, and methods of detecting a vishing attack, in which an attacker provides to a victim step-by-step over-the-phone instructions that command the victim to log-in to his bank account and to perform a dictated banking transaction. The system monitors transactions, online operations, user interactions, gestures performed via input units, speed and timing of data entry, and user engagement with User Interface elements. The system detects that the operations performed by the victim, follow a pre-defined playbook of a vishing attack. The system detects that the victim operates under duress or under dictated instructions, as exhibited in irregular doodling activity, data entry rhythm, typographical error introduction rhythm, unique posture of the user, alternating pattern of listening to phone instructions and performing online operations via a computer, and device orientation changes or spatial changes that characterize a device being used to perform an online transaction while also talking on the phone.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A process comprising:
(a) monitoring information that includes at least one of: (i) user interactions of a user that utilizes an electronic device to interact with a computerized service, (ii) operational characteristics of said electronic device; (b) analyzing said information, and determining that a set of operations were performed by said user as part of a vishing attack in which an attacker dictated to said user which operations to perform in said computerized service.
2 . The process of claim 1 , comprising:
monitoring an average typing speed of said user; and based on monitored average typing speed of said user, determining that said set of operations were performed as part of a vishing attack.
3 . The process of claim 1 , comprising:
monitoring an average mouse-click speed of said user; and based on monitored average mouse-clock speed of said user, determining that said set of operations were performed as part of a vishing attack.
4 . The process of claim 1 , comprising:
monitoring a usage-session time-length of multiple usage-sessions of said user; and based on monitored usage-session time-length, determining that said set of operations were performed as part of a vishing attack.
5 . The process of claim 1 , comprising:
monitoring periods of inactivity of said user during usage sessions; and based on monitored inactivity periods, determining that said set of operations were performed as part of a vishing attack.
6 . The process of claim 1 , comprising:
monitoring frequency of on-screen-pointer turns of said user; and based on monitored frequency of on-screen-pointer turns, determining that said set of operations were performed as part of a vishing attack.
7 . The process of claim 1 , comprising:
monitoring an average on-screen distance traveled between clicks of said user; and based on monitored on-screen distance traveled between clicks, determining that said set of operations were performed as part of a vishing attack.
8 . The process of claim 1 , comprising:
monitoring an average speed of movement of on-screen-pointer; and based on monitored average speed of movement of on-screen-pointer, determining that said set of operations were performed as part of a vishing attack.
9 . The process of claim 1 , comprising:
monitoring a ratio of displacement to distance of on-screen-pointer; and based on monitored ratio of displacement to distance, determining that said set of operations were performed as part of a vishing attack.
10 . The process of claim 1 , comprising:
monitoring accelerometer data of said electronic device, and determining that said electronic device is alternated by said user, between (i) a first position in which the electronic device is positioned generally-vertically at the user's ear and is used for talking, and (ii) a second position in which the electronic device is positioned generally-horizontally and is used for operating its touch-screen; based on alternation back-and-forth between the first position and the second position, determining that said set of operations were performed as part of a vishing attack.
11 . The process of claim 1 , comprising:
monitoring gyroscope data of said electronic device, and determining that said electronic device is alternated by said user, between (i) a first position in which the electronic device is positioned generally-vertically at the user's ear and is used for talking, and (ii) a second position in which the electronic device is positioned generally-horizontally and is used for operating its touch-screen; based on alternation back-and-forth between the first position and the second position, determining that said set of operations were performed as part of a vishing attack.
12 . The process of claim 1 , comprising:
monitoring device-orientation data of said electronic device, and determining that said electronic device is alternated by said user, between (i) a first position in which the electronic device is positioned generally-vertically at the user's ear and is used for talking, and (ii) a second position in which the electronic device is positioned generally-horizontally and is used for operating its touch-screen; based on alternation back-and-forth between the first position and the second position, determining that said set of operations were performed as part of a vishing attack.
13 . The process of claim 1 , comprising:
instructing said electronic device to automatically play a particular video clip; checking whether said video clip was actually played by said electronic device; and based on the checking result, determining that said set of operations were performed as part of a vishing attack.
14 . The process of claim 1 , comprising:
instructing said electronic device to automatically play a particular video clip that is non-observable to a user of said electronic device; checking whether said video clip was actually played by said electronic device; and based on the checking result, determining that said set of operations were performed as part of a vishing attack.
15 . The process of claim 1 , comprising:
detecting a set of operations that were performed by said user via said electronic device, which triggers an initial estimation that said set of operations were performed within a vishing attack; determining that said set of operations were performed during a nightly time-slot in which most users in a particular geographic region are asleep; and detecting that said initial estimation of a vishing attack is incorrect.
16 . The process of claim 1 , comprising:
(A) defining a parameter that indicates fluency of navigation of the user through multiple pages and multiple GUI elements of an online interface; (B) tracking fluency of navigation of said user across multiple usage sessions, and updating said parameter; (C) based on said parameter indicating fluency of navigation, determining that said set of operations were performed as part of a vishing attack.
17 . The process of claim 1 , comprising:
(A) defining a parameter that indicates characteristics of letter-chunks that the user enters consecutively; (B) tracking data-entry by the user across multiple usage-sessions, and updating said parameter; (C) based on said parameter indicating characteristics of letter-chunks, determining that said set of operations were performed as part of a vishing attack.
18 . The process of claim 1 ,
wherein determining that said set of operations were performed as part of a vishing attack, is based at least in part on detecting that a single online account of said user was accessed via multiple different login sessions within a pre-defined time period.
19 . The process of claim 1 , comprising:
monitoring characteristics of typing rhythm exhibited by said user; and based on monitored characteristics of typing rhythm, determining that said set of operations were performed as part of a vishing attack.
20 . The process of claim 1 , comprising:
(A) monitoring characteristics of typing rhythm exhibited by said user; (B) determining that typing rhythm in a particular usage-session of said user, is sufficiently different from previous typing rethemes exhibited in multiple previous usage-sessions of said user; and determining that said particular usage-session was part of a vishing attack.
21 . The process of claim 1 , comprising:
instructing said electronic device to automatically play a particular audio clip; checking whether said audio clip was actually played by said electronic device; and based on the checking result, determining that said set of operations were performed as part of a vishing attack.
22 . The process of claim 1 , comprising:
instructing said electronic device to automatically play a silent audio clip; checking whether said silent audio clip was actually played by said electronic device; and based on the checking result, determining that said set of operations were performed as part of a vishing attack.
23 . The process of claim 1 , comprising:
monitoring an average time-gap between on-screen taps that said user performs directly via a touch-screen; and based on monitored average time-gap between on-screen taps that said user performs directly via said touch-screen, determining that said set of operations were performed as part of a vishing attack.
24 . The process of claim 1 , comprising:
monitoring a maximum value of typing speed of said user; and based on monitored maximum value of typing speed of said user, determining that said set of operations were performed as part of a vishing attack.
25 . The process of claim 1 , comprising:
monitoring a minimum value of typing speed of said user; and based on monitored minimum value of typing speed of said user, determining that said set of operations were performed as part of a vishing attack.
26 . The process of claim 1 , comprising:
monitoring a maximum value of mouse-click speed of said user; and based on monitored maximum value of mouse-click speed of said user, determining that said set of operations were performed as part of a vishing attack.
27 . The process of claim 1 , comprising:
monitoring a minimum value of mouse-click speed of said user; and based on monitored minimum value of mouse-click speed of said user, determining that said set of operations were performed as part of a vishing attack.
28 . The process of claim 1 , comprising:
(A) detecting that user interactions, during a process of entering data of a financial transaction, include an average idle-time that is longer than a pre-defined threshold value of N seconds, wherein N is a positive number; (B) based on the detecting of step (A), determining that said financial transaction was entered by a victim of a vishing attack.
29 . The process of claim 1 , comprising:
(A) detecting that user interactions, during a process of entering data of a financial transaction, include a number of idle-time events that is greater by at least N percent than a pre-defined threshold value, wherein N is a positive number; (B) based on the detecting of step (A), determining that said financial transaction was entered by a victim of a vishing attack.
30 . The process of claim 1 , comprising:
(A) detecting that said user interactions, during a process of entering data of a financial transaction, exhibit a pattern of correction of typographical errors that is different from said pattern exhibited in previous usage-sessions of said user; (B) based on step (A), determining that said financial transaction was entered by a victim of a vishing attack.
31 . The process of claim 1 , comprising:
(A) detecting that said user interactions, during a process of performing a financial transaction, exhibit a current number of user-hesitation indicators that is greater than a previous number of user-hesitation indicators that were exhibited in one or more previous usage-sessions of said user; (B) based on step (A), determining that said financial transaction was entered by a victim of a vishing attack.Join the waitlist — get patent alerts
Track US2019158535A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.