BioCatch - Invisible - Challenges - FINAL-FINAL (23.4.17)
BioCatch - Invisible - Challenges - FINAL-FINAL (23.4.17)
BioCatch - Invisible - Challenges - FINAL-FINAL (23.4.17)
PAPER | Invisible Challenges: BioCatch’s Game-Changing Technology for Online Fraud Prevention
White Paper
1
WHITE PAPER | Invisible Challenges: BioCatch’s Game-Changing Technology for Online Fraud Prevention
Table of Contents
Copyright
This content is copyright of BioCatchTM 2017. All rights reserved.
Any redistribution or reproduction of part or all of the
contents in any form is prohibited other than the following:
• you may print or download to a local hard disk extracts for your personal and non-commercial use only
• you may copy the content to individual third parties for their personal use, but only if you acknowledge the
document as the source of the material
You may not, except with our express written permission, distribute or commercially exploit the content. Nor may you
transmit it or store it in any other website or other form of electronic retrieval system.
2
WHITE PAPER | Invisible Challenges: BioCatch’s Game-Changing Technology for Online Fraud Prevention
Executive Summary
BioCatch is a cybersecurity company that delivers behavioral biometrics, analyzing human-
device interactions, to protect users and data. Banks and other enterprises use BioCatch to
significantly reduce online fraud and protect against a variety of cyber threats, without
compromising the user experience.
One of the key aspects that distinguishes BioCatch as the market leader in behavioral
biometrics is its patent portfolio, which as of this writing is made up of 46 patents, 17 of
them granted or public. Among them, is a group that pertain to a capability called “Invisible
Challenges™”.
Invisible Challenges refer to tests that are invoked into an online session without the user’s
knowledge, but that elicit subconscious responses that can be used to distinguish a
fraudster from a legitimate user.
This powerful mechanism represents the latest generation of fraud prevention tools, that
addresses the weakness of traditional approaches that rely on malware libraries, two-factor
authentication, device ID and other means that the sophisticated fraudsters of today have
figured out how to circumvent.
Invisible Challenges also separates BioCatch from other behavioral biometrics providers that
are focused on traditional keyboard, mouse movements and gesture analysis, in terms of
accuracy and being able to deal with different types of replay attacks, human interaction
simulation and advanced malware injections.
3
WHITE PAPER | Invisible Challenges: BioCatch’s Game-Changing Technology for Online Fraud Prevention
4
WHITE PAPER | Invisible Challenges: BioCatch’s Game-Changing Technology for Online Fraud Prevention
5
WHITE PAPER | Invisible Challenges: BioCatch’s Game-Changing Technology for Online Fraud Prevention
Spinning Wheel
Challenge: Introduce a fluctuation in the way the selection wheel spins.
A common user interaction element in mobile apps is the spinning selection wheel for
dates, time, numbers, etc. This is often used when entering information such as a new
destination account for money transactions.
BioCatch collects passive measures related to spinning the wheel (speed, stopping strategy,
corrections towards the end), but also introduces subtle fluctuations that help us see how
the user subconsciously reacts.
User 1 User 2
User 1: The challenge is injected, and the wheel spins slowly (not kinetically). The user
compensates by a few long and continuous "pushes" to spin the wheel, and adds two
powerful strokes in the other direction for fine-tuning and final targeting.
User 2: The challenge is injected, and the wheel spins slowly (not kinetically). The user
compensates by many small and short "pushes" to spin the wheel. Afterwards, the user
adds several short, concentrated and powerful strokes in the same direction for final
targeting.
6
WHITE PAPER | Invisible Challenges: BioCatch’s Game-Changing Technology for Online Fraud Prevention
Disappearing Mouse
Challenge: Hide the cursor.
Users search for the cursor/mouse in very different and unique ways. Some use wide search
patterns, others use small ones, some are horizontal while others are diagonal, and certain
users always search counter-clockwise. Sometimes users move on a certain learning curve
and their responses vary according to their location on the curve. All these can be captured
as unique parameters, however, typically this is not practical, because the time required for
the user to provide enough relevant mouse movements to accurately authenticate
themselves is too long. Invisible Challenges unconsciously “forces” the user to make various
mouse movements in a very short time, allowing BioCatch to capture adequate data from
the user in 500 milliseconds. This makes it useful for detecting anomalies in user behavior in
near real-time.
The example below shows 25 users, each with a slightly different search pattern for a
missing cursor.
7
WHITE PAPER | Invisible Challenges: BioCatch’s Game-Changing Technology for Online Fraud Prevention
8
WHITE PAPER | Invisible Challenges: BioCatch’s Game-Changing Technology for Online Fraud Prevention
• Risk-based authentication: By definition, risk-based authentication is a method of
applying varying levels of stringency to the authentication processes based on the
risk profile of the person or the sensitivity of the application being accessed. Because
Invisible Challenges are completely transparent to the user, they can be introduced
at different junctures, and in different flavors, to increase the accuracy of the
detection rate. This makes it easy to establish different business rules within an
application, so that higher risk activities, like adding a new payee, changing the
9
WHITE PAPER | Invisible Challenges: BioCatch’s Game-Changing Technology for Online Fraud Prevention
phone number for the account, making large transfers, etc. can have specific
challenges assigned to them in a random manner, while keeping friction and false
positives low.
1
These figures are based on real data coming from the 2 million transactions per month that are monitored by
the BioCatch system, together with numerous simulated transaction experiments.
10
WHITE PAPER | Invisible Challenges: BioCatch’s Game-Changing Technology for Online Fraud Prevention
About BioCatchTM
BioCatch is a cybersecurity company that delivers behavioral biometrics, analyzing human-device
interactions to protect users and data. Banks and other enterprises use BioCatch to significantly
reduce online fraud and protect against a variety of cyber threats, without compromising the user
experience. With an unparalleled patent portfolio and deployments at major banks around the
world that cover tens of millions of users to date, BioCatch has established itself as the industry
leader. The company was founded in 2011 by experts in neural science research, machine
learning and cyber security and is currently deployed in leading banks and e-commerce websites
across North America, Latin America and Europe. For more information, please visit:
www.biocatch.com
Contact Us
www.biocatch.com
[email protected]
@biocatch
www.linkedin.com/company/biocatch
BioCatch and Invisible Challenges are trademarks of BioCatch Ltd. This report refers to BioCatch's registered patents: US 9069942, US 9418221,
US 9450971, US 9477826, US 9483292, US 9531733, US 9531701, US 9547766, US 9558339. Copyright 2017. All rights reserved.
11