Distributed Phishing Detection via Edge Gateway Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current layered security systems are inefficient in processing user-initiated traffic and fail to effectively communicate and share threat intelligence, leading to repeated processing of content and inadequate protection against phishing attacks, as they operate independently without feedback and lack a centralized data store for threat classification.

Innovation Solution

A distributed security system that includes processing nodes and authority nodes to detect phishing sites through whitelisting, blacklisting, and scoring, with data inspection engines and a manager to classify content and update threat lists, preventing access to identified phishing sites.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security processes (content filtering, intrusion detection, virus scanning) are deployed in a layered security system, then security protection coverage is improved, but processing efficiency deteriorates due to repeated inspection of each file by multiple processes

Engineering Contradiction:
Improvesecurity protection coverageVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary security inspection at the network edge gateway before content is distributed to internal systems. The gateway performs content filtering, classification, and threat detection upfront, so that subsequent internal security processes only need to handle already-filtered content, eliminating redundant scanning and improving overall processing efficiency while maintaining comprehensive security coverage

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent divides the security system into distinct functional segments: edge gateway security processes (content filtering, classification), internal security agents, and centralized management. Each segment performs specific security functions, avoiding redundant processing across all layers while maintaining comprehensive protection through coordinated segmentation of security responsibilities

Inventive Principle:
Principle #1Segmentation

2Device complexity

If layered security systems operate independently without communication, then system complexity is reduced, but threat intelligence sharing deteriorates leading to repeated processing of known threats

Engineering Contradiction:
Improvesystem complexityVSAvoidthreat intelligence sharing
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent implements feedback mechanisms where security agents throughout the enterprise continuously report detected threats, infected files, and security events back to the centralized gateway. The gateway maintains updated threat intelligence databases and distributes this information back to all security agents, creating a closed-loop feedback system that enables real-time threat intelligence sharing without significantly increasing system complexity

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent creates a universal threat intelligence database at the gateway that serves multiple security functions and all security agents simultaneously. This centralized repository provides multi-functional service including threat classification, pattern matching, virus signature distribution, and security policy management, enabling comprehensive threat intelligence sharing across the entire enterprise through a single universal system

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9065850B1Phishing detection systems and methods
Publication Date: 2015.06.23 ZSCALER INC
  • US9065850B1 patent drawing
  • US9065850B1 patent drawing
  • US9065850B1 patent drawing

AI summary

The present disclosure provides phishing heuristic systems and methods that detect phishing sites. The present invention may be implemented via a server connected to the Internet, via a distributed security system, and the like. Phishing sites may be detected in a single transaction, i.e. client request plus server reply, while knowing as little as possible about the site being masqueraded. In an exemplary embodiment, a phishing site detection system and method utilized three steps—whitelisting, blacklisting, and scoring. For example, if a particular page meets all requirements of blacklisting without any elements of whitelisting and has a score over a particular threshold, that particular site may be designated as a phishing page.