Anti-Phishing Server Audit Trail Reconstruction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current email and web browser technologies do not provide adequate defenses against information compromise, leading to a need for protecting users from electronic fraud and identity theft.

Innovation Solution

A system and method for preventing and mitigating information compromise, including an anti-phishing server that processes reports of fraudulent messages, reconstructs audit trails, and adjusts account risk, while also managing image registration and access control to prevent unauthorized use of images.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current email and web browser technology is used, then basic communication and browsing functions are provided, but adequate defense against information compromise and identity theft is not provided

Engineering Contradiction:
Improvesecurity defense capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an anti-phishing server as an intermediary component between users and electronic networks. This server receives reports of fraudulent messages, processes them through audit trail reconstruction, and provides security analysis without requiring complex security mechanisms to be embedded in every email client or web browser, thus improving reliability while managing system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security system is segmented into distinct functional modules: a reporting mechanism for receiving fraud reports, an audit trail reconstruction component for analyzing message history, and an image registration system for verifying visual elements. This segmentation allows each component to specialize in specific security tasks, improving overall security effectiveness while maintaining manageable complexity

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive security measures are implemented to protect against phishing and identity theft, then user security is enhanced, but system complexity and operational overhead increase

Engineering Contradiction:
Improveuser security protectionVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service mechanisms where the anti-phishing server automatically processes security reports and reconstructs audit trails without requiring manual intervention from security experts. The image registration system automatically verifies visual elements in messages, providing security protection while minimizing operational overhead and maintaining ease of use for end users

Inventive Principle:
Principle #25Self-service

3Reliability

If image registration and access control mechanisms are implemented, then unauthorized use of images is prevented, but processing time and system resources are consumed

Engineering Contradiction:
Improveimage authorization controlVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-registering legitimate images in an image registry before they are used in electronic messages. This allows the anti-phishing server to quickly verify image authorization by checking against the pre-established registry, preventing unauthorized image use while minimizing processing time during message analysis, as the verification process simply involves checking whether an image exists in the pre-populated registry

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7971246B1Identity theft countermeasures
Publication Date: 2011.06.28 ROSKIND JAMES A DR
  • US7971246B1 patent drawing
  • US7971246B1 patent drawing
  • US7971246B1 patent drawing

AI summary

In some embodiments, techniques for computer security comprise preventing and/or mitigating identity theft such as phishing.