Fraud Sandbox Proxy for Phishing Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users are at risk of providing sensitive information to untrusted entities due to fraudulent schemes, such as phishing, where illegitimate websites request private information, leading to potential harm.
Innovation Solution
A financial institution computing system acts as a proxy, verifying the legitimacy of network destinations and if untrusted, it transmits virtual sandbox content to the user's device, encrypts user input, and alerts the user, preventing sensitive information from being sent to untrusted entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users access network destinations directly, then ease of operation is improved, but security against fraudulent entities deteriorates
Solution Approach 1:
The patent introduces a financial institution computing system as an intermediary between the user computing device and network destinations. This intermediary verifies the legitimacy of network destinations before allowing communication, thus maintaining ease of operation while improving security against fraudulent entities.
2Loss of information
If substitution content is transmitted to untrusted entities, then loss of information is reduced, but device complexity increases
Solution Approach 1:
The patent creates substitution content that mimics the appearance and functionality of legitimate content requests. This copying approach prevents sensitive information loss by redirecting users to safe alternatives while maintaining the user experience, thus reducing information loss without significantly increasing device complexity.
3Reliability
If user input is encrypted before transmission, then security is improved, but processing time increases
Solution Approach 1:
The patent performs legitimacy verification and content substitution before the user submits sensitive information. By conducting security checks in advance, the system minimizes the need for time-consuming encryption operations on actual sensitive data, thus improving security while reducing processing time losses.
Data Source
AI summary
A financial institution computing system associated with a financial institution includes a network interface configured to communicate data over a network, and a processing circuit comprising a memory and a processor. The memory has instructions stored thereon that cause the processor to receive, by the network interface, a content request from a user computing device associated with a user, the content request requesting content from a network destination, determine if the network destination is associated with a trusted entity, determine that the requested content prompts the user to input sensitive information, and transmit, by the network interface substitution content to the user computing device responsive to determining that the network destination is illegitimate and to determining that the requested content includes at least one field into which the user may input sensitive information, the substitution content including at least one prompt requesting the user to input sensitive information.


