AI Voice Analysis for Phishing Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems are inadequate in effectively detecting and mitigating employee-targeted phishing attacks, particularly voice phishing (vishing), which poses a significant threat to organizations like financial institutions, requiring substantial resources for employee training and threat management.

Innovation Solution

A computing platform with a processor, communication interface, and memory monitors endpoint devices for suspicious calls, applies voice-to-text analysis, validates caller information against threat scripts, updates security threat scores, and terminates potentially malicious calls, while using machine learning to enhance threat detection and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional training and monitoring methods are used to protect employees from phishing attacks, then employee awareness may be improved, but resource consumption and inability to detect sophisticated attacks increase

Engineering Contradiction:
Improvephishing attack detection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent replaces manual employee training and human monitoring with an automated AI-based system that uses voice-to-text conversion, machine learning models, and natural language processing to detect phishing attempts in real-time, eliminating the need for continuous human resource投入

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service by automatically monitoring communications, detecting threats, and alerting employees without requiring human analysts to review each interaction, allowing the system to protect itself and its users autonomously

Inventive Principle:
Principle #25Self-service

2Speed

If automated monitoring systems are implemented to detect phishing calls in real-time, then threat detection speed is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system segments the complex threat detection task into distinct modular components: voice-to-text conversion module, initial validation module (checking caller ID, phone numbers), threat script matching module, and machine learning analysis module, allowing each to operate independently and be maintained separately

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary AI layer that sits between the communication channels and the detection logic, using natural language processing to translate various communication formats into a unified analysis framework, simplifying the overall system architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive validation and analysis of all call data is performed, then detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary validation checks on basic call data elements (caller ID, phone number formats, basic threat script matching) before subjecting the conversation to more time-consuming machine learning analysis, filtering out obvious threats early and preserving resources for complex cases

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies a tiered analysis approach where not all calls receive the full extent of analysis - routine calls receive basic validation while only suspicious calls trigger comprehensive machine learning analysis, optimizing the balance between accuracy and processing time

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12028375B2Detecting and protecting against employee targeted phishing attacks
Publication Date: 2024.07.02 BANK OF AMERICA CORP
  • US12028375B2 patent drawing
  • US12028375B2 patent drawing
  • US12028375B2 patent drawing

AI summary

Methods, systems, computer-readable media, and apparatuses for detecting and protecting against employee targeted phishing attacks. In some embodiments, a computing platform may monitor an endpoint device. The computing platform may receive a notification that a call has started on the endpoint device. The computing platform may receive data associated with the call. The computing platform may apply voice-to-text analysis of the received data. The computing platform may perform initial validations of the received data converted to text. The computing platform may match the text against threat actor scripts. The computing platform may update an information security threat score. The computing platform may send a message to the endpoint device indicating that a potential information security threat has been detected.