Image Timer Embedding for Spoofed Email Device Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-phishing technologies cannot identify the devices used to construct spoofed websites and emails, making it difficult to trace and prosecute individuals involved in phishing attacks.

Innovation Solution

Embedding a timer in images on web servers that records the time of removal and associates it with device forensic data, allowing for identification of the device used to copy images later found in spoofed emails or websites by matching the image-timer value with database-stored time-of-removal values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If anti-phishing software is used to identify phishing content, then detection capability is improved, but the ability to identify devices used to construct spoofed websites and emails remains insufficient

Engineering Contradiction:
Improvedetection capabilityVSAvoiddevice identification information
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The patent applies preliminary action by embedding a timer in images before they are stolen and used in phishing attacks. The timer records the time of removal from the legitimate website, creating a timestamped marker that survives the theft process. This preliminary timing action enables later identification of the device used to steal the image, solving the information loss problem without requiring complex real-time monitoring of device actions.

Inventive Principle:
Principle #10Preliminary action

2Difficulty of detecting and measuring

If images are embedded with timer data, then device tracking capability is improved, but image processing complexity increases

Engineering Contradiction:
Improvedevice tracking capabilityVSAvoidimage processing complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent uses copying by embedding timer data directly into the image file itself, creating a copy of the image that contains additional metadata (the timestamp). This copied image with embedded timer information can then be detected and traced back to the device that stole it, enabling device tracking without requiring complex image processing systems - the timer data is simply read from the image file during normal analysis.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8209309B1Download detection
Publication Date: 2012.06.26 BANK OF AMERICA CORP
  • US8209309B1 patent drawing
  • US8209309B1 patent drawing
  • US8209309B1 patent drawing

AI summary

Embodiments of the invention relate to systems, methods, and computer program products for identifying devices used in connection with email and website spoofing. For example, the invention can be used to identify the device that was used to copy an image from a target website, where, after being copied, the image is used as part of a spoofed email or website. In an embodiment, a timer is embedded in an image residing on a web server that hosts a target website. The embedded timer is configured to record the time at which the image is removed from the web server and store that time in the image for later retrieval. Also, the time at which the image was removed, along with a device forensic of the device used to download the image, is stored in a database. If the image later appears as part of a spoofed email or website, the time at which the image was removed from the web server is obtained from the timer embedded in the image. Then, the database is searched for the corresponding time and device forensic, which can be used to identify the device used to copy the image from the target website.