Email Phishing Flagging System with Non-Intrusive Warning Levels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email security systems are inadequate in preventing phishing attacks, as they often rely on inconvenient firewalls or user training, and are vulnerable to successful attacks when users are distracted or untrained, especially when personal emails are accessed on enterprise devices.

Innovation Solution

A robust phishing prevention system that uses a non-intrusive interface to clearly flag suspicious emails within the familiar email interface, locking them until the user reviews and interacts with them, providing actionable insights and allowing users to decide on the risk, while generating feedback for the automated system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewalls are used to block suspicious emails before they reach the target, then security protection is improved, but user convenience deteriorates because trusted emails may be blocked and the system becomes unreliable

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary analysis of email characteristics (sender domain, content patterns, links) before delivery to determine phishing risk, then applies appropriate actions (block, flag, or allow) based on the assessment, avoiding the need for broad blocking rules that impact user convenience

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An intermediary phishing detection system is introduced between the email source and the user, which analyzes emails and provides contextual information to help users make informed decisions, rather than using simple block/allow firewalls that affect user experience

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If users are trained to recognize and delete phishing emails, then security awareness is improved, but security reliability deteriorates because untrained or distracted users may still fall for attacks

Engineering Contradiction:
Improveuser trainingVSAvoidsecurity reliability
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The system provides real-time feedback to users by flagging suspicious emails with visual indicators and explaining why they are suspicious, enabling users to make informed decisions without requiring extensive training, while still maintaining high security reliability

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system empowers users to handle phishing emails themselves by providing them with the information needed to make decisions, rather than relying on centralized filtering that may block legitimate emails or require complex user training programs

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If personal email services are accessed on enterprise devices through web browsers, then user accessibility is improved, but security vulnerability increases because the security system becomes blind to phishing attacks from personal accounts

Engineering Contradiction:
Improveemail accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The phishing detection system is designed to work universally across multiple email providers and platforms by analyzing email characteristics rather than relying on provider-specific implementations, enabling it to protect against phishing from both enterprise and personal email accounts

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

A browser extension or email client add-on acts as an intermediary that analyzes emails from any provider at the point of display, providing phishing protection regardless of the email source or access method

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11750647B2Method and apparatus for user protection from external e-mail attack
Publication Date: 2023.09.05 PREKARI INC
  • US11750647B2 patent drawing
  • US11750647B2 patent drawing
  • US11750647B2 patent drawing

AI summary

A method and apparatus are described for user protection from external e-mail attack. Some embodiments pertain to receiving a first e-mail at an e-mail client, receiving a detection of a suspicious element in the first e-mail from a detection system, flagging the first e-mail as suspicious with a first flag and a first warning level in response to receiving the detection, flagging a second e-mail with a second flag and a second warning level, displaying the first and second flags with explanatory text in a mailbox view of the e-mail client without opening the first and second e-mail for display to the user, the suspicious element not being selectable in the mailbox view, and sorting the first and the second e-mail with other e-mails of the mailbox view based on the flag warning levels.