Bait Information Generation for Malicious Software Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting and mitigating information stealing software and phishing/pharming attacks are ineffective due to the sophisticated design of such threats, which evade detection and pose significant risks to confidentiality and compliance with regulations.

Innovation Solution

A system and method that employs a software agent to generate 'bait' information on electronic devices, simulating user interactions to detect and analyze outgoing traffic for suspicious patterns, correlating this with network traffic to identify and block unwanted software, while also assessing sensitivity and risk levels of transmitted data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based detection methods are used to identify information stealing software, then the detection process is simple and fast, but the effectiveness is limited because such software is carefully designed to avoid detection

Engineering Contradiction:
Improvedetection effectivenessVSAvoiddetection method complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by generating bait information and inserting it into the electronic device before the information stealing software can execute its theft operation. The software agent proactively creates simulated sensitive information and monitors its transmission, allowing detection before actual user data is compromised.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces an intermediary software agent that acts as a mediator between the information stealing software and the actual sensitive data. The agent generates artificial bait information that the stealing software targets instead of real user data, and monitors the communication channel to detect theft attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional phishing mitigation methods are used, then user awareness is improved, but effective phishing attacks remain very common

Engineering Contradiction:
Improvephishing protection effectivenessVSAvoidphishing attack detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system proactively generates bait information representing various phishing targets (login forms, credit card fields, etc.) and inserts it into the device before phishing attacks occur. This preliminary placement of detectable markers enables automatic detection when phishing software attempts to exfiltrate the bait, eliminating reliance on user awareness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The software agent creates copies of sensitive information structures (login credentials, credit card data, personal details) as artificial bait. These copies mimic the format and characteristics of real sensitive data, allowing the system to detect phishing attempts that target these data types without exposing actual user information.

Inventive Principle:
Principle #26Copying

3Reliability

If DNS protection and web browser add-ins are used to mitigate pharming risks, then some protection is provided, but the value is limited

Engineering Contradiction:
Improvepharming attack protectionVSAvoidprotection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention extracts the detection function from complex external systems (DNS protection services, browser add-ins) and implements it within a lightweight software agent that runs locally on the device. The agent independently monitors outgoing traffic for bait information without requiring external validation, simplifying the overall protection architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

4Measurement precision

If the system monitors and analyzes all outgoing traffic to detect information stealing software, then detection accuracy is improved, but system performance and processing overhead increase

Engineering Contradiction:
Improvesoftware detection accuracyVSAvoidsystem performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The software agent creates artificial copies of sensitive information (bait data) that are specifically designed to be detected. Instead of analyzing all outgoing traffic for patterns of sensitive data, the system simply monitors for the transmission of these unique bait copies, dramatically reducing processing requirements while maintaining high detection accuracy.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8959634B2Method and system for protection against information stealing software
Publication Date: 2015.02.17 FORCEPOINT LLC
  • US8959634B2 patent drawing
  • US8959634B2 patent drawing
  • US8959634B2 patent drawing

AI summary

Methods and systems reduce exposure to a dictionary attack while verifying whether data transmitted over a computer network is a password. In one aspect, a method includes performing a search of network traffic based, at least in part, on a weak validation using a Bloom filter based on an organizational password file, determining the existence of a password in the network traffic based only on the weak validation, and determining whether to block, alert, or quarantine the network traffic based at least in part on the existence of the password in the network traffic.