Dynamic Detection Engine Selection for Phishing and Malware Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing sophistication and diversity of malware and phishing attacks make it difficult for users to securely access information channels like web browsers, email, and texts, with existing anti-phishing solutions often providing ad hoc approaches lacking comprehensive mitigation strategies.

Innovation Solution

A malware and phishing detection and mediation (MAPDAM) platform that includes ingestion, detection, and action stages, utilizing detection engines with engineered rules, machine learning, and computer vision to identify and mitigate phishing and malware threats by analyzing URLs, website certificates, and web page content, and communicating with mitigation services for effective action.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multiple detection engines with engineered rules, machine learning, and computer vision are implemented, then detection precision is improved, but device complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system divides the detection process into multiple specialized detection engines, each responsible for specific aspects of malware and phishing detection. These engines process different types of data (URLs, certificates, web page content) using different methodologies (engineered rules, machine learning, computer vision), allowing the system to achieve high detection precision through specialized components rather than a single complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The detection platform is designed as a universal system that can handle multiple types of threats (malware, phishing) through multiple detection engines that share common infrastructure. The engines can be dynamically selected and configured based on the type of data being analyzed, making the system adaptable to different detection needs without requiring separate specialized systems for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a comprehensive set of detection engines is implemented, then reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovereliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically selects and configures appropriate detection engines based on the type of data being analyzed. The platform self-manages the complexity of coordinating multiple detection engines through automated engine selection and configuration, eliminating the need for users to manually manage the complex detection pipeline while maintaining high reliability through comprehensive multi-engine analysis.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If dynamic detection engine selection is implemented, then adaptability is improved, but device complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system dynamically selects and configures detection engines based on the characteristics of the input data and the type of threat being detected. This dynamic adaptation allows the platform to optimize its detection capabilities for different scenarios (URL analysis, certificate verification, web page rendering) without requiring a fixed, overly complex architecture, as the engine selection adapts to the specific detection needs.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11470114B2Malware and phishing detection and mediation platform
Publication Date: 2022.10.11 PAYPAL INC
  • US11470114B2 patent drawing
  • US11470114B2 patent drawing
  • US11470114B2 patent drawing

AI summary

A method for using a malware and phishing detection and mediation platform is discussed. The method includes accessing data from one or more of a monitored portion of website data and a monitored portion of emails, the data indicating a respective potential malware or a suspect phishing element (e.g., Uniform Resource Locator (URL)). The method includes selecting one of a plurality of detection engines for processing the data, where the selecting is based on previous results of previous processing by one or more detection engines. Each of the plurality of detection engines can be for performing one or more respective investigation actions on the plurality of data to determine a particular issue with one of the monitored data. The method also includes determining a mediation action based on a result of processing of the detection engine and the previous processing.