Dynamic Personal Attribute Phishing Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods to prevent phishing attacks are inadequate, as users often fail to validate websites correctly, and legitimate communications are hindered by increased skepticism towards links in emails and messages, leading to a need for improved security measures.
Innovation Solution
A method utilizing dynamic personal attributes associated with users, which are provided to them before authentication, allowing users to validate remote servers and distinguish between valid and invalid websites, using out-of-band communications such as emails or instant messages, ensuring the attributes are personal and dynamically updated.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users are educated to be more skeptical of links in emails and instant messages to reduce phishing attack success, then phishing attack effectiveness is reduced, but legitimate communications from providers to users are significantly impeded
Solution Approach 1:
The system performs preliminary authentication by obtaining and verifying a dynamic personal attribute associated with the user before the user clicks on any link in emails or instant messages. This advance verification allows legitimate communications to proceed smoothly while blocking phishing attacks, resolving the contradiction between security and communication flow.
Solution Approach 2:
The user themselves performs the validation by checking whether the dynamic personal attribute obtained from the remote server matches the one received in the email or instant message. This self-service approach empowers users to distinguish legitimate communications from phishing attempts without requiring them to be overly skeptical or manually verify each link.
2Reliability
If static information is displayed to users during login for validation, then users have reference information to determine website legitimacy, but the information can be easily replicated by phishing attackers
Solution Approach 1:
The system replaces static validation information with a dynamic personal attribute that changes over time and is specific to each user. This dynamic attribute is obtained freshly from the remote server during each authentication attempt, making it impossible for phishing attackers to replicate, thus resolving the contradiction between providing validation information and preventing its replication.
Solution Approach 2:
The system changes the parameter being validated from static website information (URL, certificate) to a dynamic personal attribute that is unique to each user and changes with each authentication session. This parameter change makes the validation process resistant to phishing attacks while maintaining user-friendly validation.
3Reliability
If users check website certificates to validate legitimacy, then some phishing attempts can be detected, but users typically cannot distinguish between valid and invalid certificates
Solution Approach 1:
Instead of requiring users to directly interpret complex certificate information, the system copies the essential validation information into a simplified dynamic personal attribute that is easy for users to understand and compare. This copying approach maintains detection capability while eliminating the difficulty of certificate interpretation.
Solution Approach 2:
The system transforms the abstract concept of certificate validity into a concrete, easily distinguishable dynamic personal attribute that users can readily compare. This transformation makes validation as simple as checking whether the displayed attribute matches the expected value, eliminating the complexity of certificate analysis.
Data Source
AI summary
The invention includes a method and apparatus for preventing phishing attacks. A first method, for informing a user that a remote server is valid, includes receiving a request for information available from the remote server where the request includes an identifier, obtaining a dynamic personal attribute associated with the user using the identifier, and propagating the dynamic personal attribute toward the user, wherein the dynamic personal attribute is adapted for use by the user in validating the remote server. The remote server may be a web server, an authentication server, or any other remote device with which the user may desire to authenticate. A second method, for informing a user that a received message is associated with a valid website, includes obtaining a dynamic personal attribute associated with a user, generating a message for the user where the message is adapted to enable the user to request a website and includes the dynamic personal attribute associated with the user, and propagating the message toward the user. The received message may be any type of message, such as an email message, an instant message, a text message, and the like.


