| CPC H04L 63/0876 (2013.01) [H04L 63/123 (2013.01)] | 20 Claims | 

| 
               1. A method comprising: 
            creating, by an authentication plug-in operating in a browser of a host computer, a log file to record data used to determine if the host computer is being controlled by a viewer computer; 
                monitoring, by the authentication plug-in, events for a webpage of a website, the webpage being accessed on the host computer via the browser by the viewer computer, wherein the events relate to at least changes in contents of the webpage, and the monitoring comprises: 
                analyzing the contents of the webpage to determine the events for the webpage, 
                  recording, to the log file, the data related to the events for the webpage, and 
                  based on the analyzing, determining that one of the events corresponds to a particular interaction taking place; and 
                in response to the particular interaction taking place, transmitting, by the host computer, an interaction request message comprising the log file to an authentication server computer, wherein the authentication server computer determines if the particular interaction associated with the interaction request message is authentic or not authentic by analyzing the data in the log file that indicates that the viewer computer initiated the particular interaction on the host computer. 
               |