File Attribute Data Tracking for Phishing Awareness
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anti-ransomware technologies fail to provide adequate training for users on handling non-executable attachments that may contain security threats, especially when these attachments are saved and opened at a later time, as they lack information about the file's origin and history, leading to missed opportunities for user education and enhanced security awareness.
Innovation Solution
The system utilizes metadata and attribute data to enhance anti-phishing capabilities by creating and using file attribute data to track the origin and heritage of files, pausing execution of potentially harmful files, and prompting users to confirm actions, allowing for user decision-making and recording user behavior for analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing anti-ransomware technologies are used to protect against security threats, then system security is improved, but user training and education on handling suspicious attachments is lost
Solution Approach 1:
The system provides feedback to users when they attempt to open suspicious attachments by displaying warnings and educational information about potential threats. This feedback loop allows users to learn from their actions while still maintaining security protection through automated blocking mechanisms.
Solution Approach 2:
An intermediary layer is introduced between the user and the suspicious attachment. This intermediary system analyzes the attachment, determines its threat level, and then mediates the user's access by either blocking it, warning the user, or allowing controlled access based on the assessment.
2Reliability
If automated blocking of suspicious attachments is implemented, then security protection is enhanced, but user awareness and decision-making skills are not developed
Solution Approach 1:
Instead of completely blocking all suspicious attachments, the system applies partial action by allowing some level of user interaction with warnings and educational content. This excessive caution approach provides both protection and learning opportunities without completely restricting user access.
Solution Approach 2:
The system performs preliminary analysis and assessment of attachments before they reach the user. By pre-evaluating threats and preparing educational content in advance, the system can provide both security protection and user training simultaneously when the user encounters suspicious content.
3Ease of operation
If files are saved and opened at a later time, then user convenience is improved, but the ability to track file origin and provide training is reduced
Solution Approach 1:
The system performs preliminary actions by embedding metadata and origin information into the file at the time of receipt. This preliminary tagging ensures that even when files are saved and opened later, the origin tracking information remains embedded and accessible for both security analysis and user training purposes.
Solution Approach 2:
The system creates copies of the original file metadata and origin information and embeds them within the file itself. This copying mechanism ensures that the tracking information travels with the file regardless of when or where it is opened, maintaining both user convenience and traceability.
Data Source
AI summary
The present disclosure describes a system for saving metadata on files and using attribute data files inside a computing system to enhance the ability to provide user interfaces based on actions associated with non-executable attachments like text and document files from untrusted emails, to block execution of potentially harmful executable object downloads and files based on geographic location, and to a create a prompt for users to decide whether to continue execution of potentially harmful executable object downloads and files. The system also records user behavior on reactions to suspicious applications and documents by transmitting a set of attribute data in an attribute data file corresponding to suspicious applications or documents to a server. The system interrupts execution of actions related to untrusted phishing emails in order to give users a choice on whether to proceed with actions.


