Intent-Based Anti-Phishing Software for Link Authenticity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current browser technologies are ineffective in preventing users from accessing fake websites that resemble legitimate ones, leading to unauthorized data access, as they rely solely on user selection without authenticating the intent behind the link clicks.

Innovation Solution

An anti-phishing system utilizing anti-phishing software that continuously monitors user activity, analyzes link content to determine authenticity based on implied user intent, and employs sandbox mode to evaluate potential phishing links, blocking or allowing access accordingly, and communicates command signals to applications to manage access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If browsers allow users to access websites selected by users, then user freedom and ease of operation are improved, but security and reliability deteriorate as users can access fake phishing websites

Engineering Contradiction:
Improveuser freedom to access websitesVSAvoidsecurity against phishing attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary anti-phishing software layer between the user and the website. This software monitors user activity, detects potential phishing links, and intercepts navigation attempts before the user reaches the fake website. The intermediary analyzes link authenticity and blocks malicious sites while allowing legitimate ones, thus maintaining user freedom while improving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary analysis of links and websites before the user actually navigates to them. By pre-evaluating the authenticity of links and pre-blocking phishing attempts, the system prevents users from accessing harmful sites in the first place, rather than reacting after the fact.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If anti-phishing software analyzes link content to determine authenticity, then measurement precision and reliability are improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improveaccuracy in detecting phishing linksVSAvoidsoftware complexity for content analysis
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The anti-phishing software performs partial analysis by focusing on key indicators of phishing (such as URL patterns, website content characteristics, and link context) rather than analyzing every aspect of each link in exhaustive detail. This selective approach maintains high detection accuracy while reducing computational complexity and processing overhead.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the system blocks access to potential phishing content, then security and reliability are improved, but loss of information increases as legitimate links may be incorrectly blocked

Engineering Contradiction:
Improvesecurity against phishingVSAvoidblocking of legitimate links
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system incorporates feedback mechanisms where user interactions with blocked links are monitored and used to refine the anti-phishing algorithms. When users attempt to access legitimately blocked sites, the system learns from this feedback and adjusts its blocking criteria, gradually reducing false positives while maintaining security against actual phishing threats.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12063247B1Intent-based anti-phishing management systems and methods
Publication Date: 2024.08.13 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US12063247B1 patent drawing
  • US12063247B1 patent drawing
  • US12063247B1 patent drawing

AI summary

Embodiments are described herein relating to systems and methods for blocking access to phishing-related content accessible via links that are presented via applications being executed on electronic devices based at least in part on implied intent on the part of users using the electronic devices. For example, anti-phishing software may be configured to detect selection of potential phishing-related links that are presented via the applications being executed on the electronic devices, to determine authenticity of the potential phishing-related links, and to take appropriate action based on the authenticity of the potential phishing-related links. For example, the anti-phishing software may be configured to analyze content associated with the potential phishing-related links (e.g., to estimate user intent) and/or to access potential phishing-related content at locations corresponding to the potential phishing-related links (e.g., in an isolated sandbox mode) to determine whether to block or allow access to the potential phishing-related content based on the authenticity of the potential phishing-related links.