Information Protection System for Phishing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Spoofing and phishing attacks in network environments, particularly targeting user information on web pages, remain prevalent due to the inability of existing solutions to effectively protect users from fraudulent web sites that mimic legitimate ones, especially with the use of form fill applications.

Innovation Solution

An information protection system that includes a parser to identify fields within a user interface, a detection module to verify the authenticity of the source, and a form fill module to provide warnings or disable data entry in case of fraudulent activity, ensuring user information is only submitted to verified sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If form fill applications are used to automatically provide user information, then productivity and ease of operation are improved, but users become more vulnerable to spoofing and phishing attacks

Engineering Contradiction:
Improveform fill efficiencyVSAvoidspoofing attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary verification system that acts as a mediator between the form fill application and the web page. This intermediary checks the authenticity of the web page by verifying SSL certificates and domain information before allowing the form fill application to populate user information, thus preventing spoofing attacks while maintaining automated form filling functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the verification module continuously monitors and provides information about the authenticity of the web page to the form fill application. Based on this feedback, the system can enable or disable form filling functionality, alert users about potential phishing attempts, or block submission to fraudulent sites

Inventive Principle:
Principle #23Feedback

2Device complexity

If small icons or toolbars are used to indicate fraudulent web pages, then device complexity is minimized, but users ignore these warnings and security protection is ineffective

Engineering Contradiction:
Improvesecurity indicator simplicityVSAvoidsecurity warning effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Instead of using uniform small icons throughout the interface, the patent applies different visual qualities and styles to security indicators based on the level of risk detected. High-risk fraudulent sites receive prominent, unavoidable warnings with distinctive visual characteristics, while lower-risk sites receive subtler indicators, making the security feedback more noticeable and actionable

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent enhances security indicators by adding multiple dimensions of communication beyond simple icons. This includes visual dimensions (color-coded warnings, overlay graphics), textual dimensions (descriptive alert messages), and spatial dimensions (positioning warnings to block form submission buttons), creating a multi-dimensional security warning system that cannot be easily ignored

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If users are warned about fraudulent sites, then security awareness is improved, but users may still inadvertently submit information due to lack of awareness or urgency

Engineering Contradiction:
Improvesecurity warning capabilityVSAvoiduser information submission
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies preliminary anti-action by implementing preventive measures before user information can be submitted to fraudulent sites. The verification module checks the web page authenticity in advance, and if fraud is detected, the system proactively blocks the form submission capability or requires additional user confirmation, preventing the harmful action before it can occur

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent performs preliminary verification and authentication checks before enabling the form fill functionality. By pre- validating the web page's legitimacy through SSL certificate verification and domain checking, the system ensures that automated form filling only occurs on authenticated, safe websites, eliminating the need for users to manually assess security risks

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9135469B2Information protection system
Publication Date: 2015.09.15 PAYPAL INC
  • US9135469B2 patent drawing
  • US9135469B2 patent drawing
  • US9135469B2 patent drawing

AI summary

A method and a system to protect information are provided. For example, a system comprises a parser to parse user interface information to be included within a user interface to be displayed to a user by an information display application. The parser also identifies at least one field, within the user interface, to receive user information from a user. A detection module is provided to determine whether the user interface information is associated with fraudulent activity. A form fill module, in response to determining that the user interface is associated with fraudulent activity, provides a warning indicia in or over the at least one field, when the user interface is presented to a user by the display application. The form fill module may also disable the functionality of a user display application to automatically form fill the identified fields.