Bait Information Detection for Malicious Software
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting information stealing software and mitigating phishing and pharming attacks are ineffective due to the sophisticated design of such threats, which often evade detection and pose significant risks to confidentiality and compliance with regulations.
Innovation Solution
A system and method that employs a software agent to generate 'bait' information on electronic devices, simulating user interactions to detect unwanted software by analyzing traffic patterns and correlating output with known bait data, using a management unit, traffic analyzer, and decision system to identify and block malicious activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If signature-based detection methods are used to identify information stealing software, then the detection process is simple and fast, but the detection effectiveness is limited because such software is carefully designed to avoid detection
Solution Approach 1:
The system performs preliminary actions by installing bait information and software agents on electronic devices before actual information stealing attempts occur. These agents proactively monitor and detect stealing software by comparing transmitted information against the planted bait, enabling early detection before significant damage occurs.
Solution Approach 2:
The invention introduces an intermediary mechanism - the bait information and software agents - that mediates between the user's computer and potential information stealers. Instead of directly detecting stealing software, the system uses these intermediaries to indirectly identify malicious activity by observing what information is transmitted.
2Ease of operation
If current phishing mitigation methods such as helping users identify legitimate sites and alerting users to fraudulent websites are used, then user awareness is improved, but effective phishing attacks remain very common
Solution Approach 1:
The system implements self-service protection by automatically monitoring and analyzing information transmission without requiring user intervention. The software agents and bait information work autonomously to detect phishing attempts, eliminating the need for users to manually identify fraudulent sites while providing reliable automated protection.
3Reliability
If DNS protection and web browser add-ins are used to mitigate pharming risks, then some protection is provided, but these measures are of limited value against sophisticated pharming attacks
Solution Approach 1:
The invention extracts the detection function from complex DNS protection systems and browser add-ins, isolating it into dedicated software agents that specifically monitor information transmission patterns. This extraction simplifies the overall system while maintaining effective detection capabilities by focusing on the core function of identifying stolen information.
4Productivity
If information stealing software is allowed to operate undetected, then system performance is maintained, but confidential information is compromised and regulatory compliance is violated
Solution Approach 1:
The system converts the harmful behavior of information stealing software into a beneficial detection mechanism. By planting bait information that mimics confidential data, the system causes stealing software to inadvertently reveal its presence by transmitting the bait, thereby converting the malware's stealing action into a self-incriminating event that aids detection.
Data Source
AI summary
A system and method for identifying infection of unwanted software on an electronic device is disclosed. A software agent configured to generate a bait and is installed on the electronic device. The bait can simulate a situation in which the user performs a login session and submits personal information or it may just contain artificial sensitive information. Parameters may be inserted into the bait such as the identity of the electronic device that the bait is installed upon. The output of the electronic device is monitored and analyzed for attempts of transmitting the bait. The output is analyzed by correlating the output with the bait and can be done by comparing information about the bait with the traffic over a computer network in order to decide about the existence and the location of unwanted software. Furthermore, it is possible to store information about the bait in a database and then compare information about a user with the information in the database in order to determine if the electronic device that transmitted the bait contains unwanted software.


