File Attribute Data Tracking for Phishing Awareness

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anti-ransomware technologies fail to provide adequate training for users on handling non-executable attachments that may contain security threats, especially when these attachments are saved and opened at a later time, as they lack information about the file's origin and history, leading to missed opportunities for user education and enhanced security awareness.

Innovation Solution

The system utilizes metadata and attribute data to enhance anti-phishing capabilities by creating and using file attribute data to track the origin and heritage of files, pausing execution of potentially harmful files, and prompting users to confirm actions, allowing for user decision-making and recording user behavior for analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing anti-ransomware technologies are used to protect against security threats, then system security is improved, but user training and education on handling suspicious attachments is lost

Engineering Contradiction:
Improvesystem securityVSAvoiduser training opportunity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system provides feedback to users when they attempt to open suspicious attachments by displaying warnings and educational information about potential threats. This feedback loop allows users to learn from their actions while still maintaining security protection through automated blocking mechanisms.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

An intermediary layer is introduced between the user and the suspicious attachment. This intermediary system analyzes the attachment, determines its threat level, and then mediates the user's access by either blocking it, warning the user, or allowing controlled access based on the assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If automated blocking of suspicious attachments is implemented, then security protection is enhanced, but user awareness and decision-making skills are not developed

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser awareness
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of completely blocking all suspicious attachments, the system applies partial action by allowing some level of user interaction with warnings and educational content. This excessive caution approach provides both protection and learning opportunities without completely restricting user access.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary analysis and assessment of attachments before they reach the user. By pre-evaluating threats and preparing educational content in advance, the system can provide both security protection and user training simultaneously when the user encounters suspicious content.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If files are saved and opened at a later time, then user convenience is improved, but the ability to track file origin and provide training is reduced

Engineering Contradiction:
Improveuser convenienceVSAvoidfile origin tracking
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system performs preliminary actions by embedding metadata and origin information into the file at the time of receipt. This preliminary tagging ensures that even when files are saved and opened later, the origin tracking information remains embedded and accessible for both security analysis and user training purposes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of the original file metadata and origin information and embeds them within the file itself. This copying mechanism ensures that the tracking information travels with the file regardless of when or where it is opened, maintaining both user convenience and traceability.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11295010B2Systems and methods for using attribute data for system protection and security awareness training
Publication Date: 2022.04.05 KNOWBE4 INC
  • US11295010B2 patent drawing
  • US11295010B2 patent drawing
  • US11295010B2 patent drawing

AI summary

The present disclosure describes a system for saving metadata on files and using attribute data files inside a computing system to enhance the ability to provide user interfaces based on actions associated with non-executable attachments like text and document files from untrusted emails, to block execution of potentially harmful executable object downloads and files based on geographic location, and to a create a prompt for users to decide whether to continue execution of potentially harmful executable object downloads and files. The system also records user behavior on reactions to suspicious applications and documents by transmitting a set of attribute data in an attribute data file corresponding to suspicious applications or documents to a server. The system interrupts execution of actions related to untrusted phishing emails in order to give users a choice on whether to proceed with actions.