Dynamic Malicious Email Scrubbing for User Security Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of electronic communications, particularly online and mobile activities, poses a significant challenge in identifying unsecure or malicious communications before they initiate unauthorized actions, compromising users' electronic information and device security.

Innovation Solution

A system and method for dynamically repurposing and targeting malicious electronic communications across various channels, involving blocking, scrubbing, and repurposing to create clean communications for user training, while escalating authentication requirements based on user actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If malicious electronic communications are blocked entirely, then user security is improved, but user training opportunity is lost

Engineering Contradiction:
Improveuser securityVSAvoiduser training opportunity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system converts harmful malicious communications into beneficial training materials by scrubbing malicious content while preserving the structural appearance of legitimate communications. This allows users to train on real phishing attempts without exposing them to actual harm, transforming a security threat into an educational resource.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The system introduces an intermediary layer between malicious communications and users - a scrubbing mechanism that removes harmful elements while maintaining the communicative structure. This intermediary enables safe interaction with potentially harmful content for training purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If real malicious communications are used for training, then training realism is improved, but user safety deteriorates

Engineering Contradiction:
Improvetraining realismVSAvoiduser safety
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system converts harmful malicious communications into beneficial training materials by scrubbing malicious content while preserving the structural appearance of legitimate communications. This allows users to train on real phishing attempts without exposing them to actual harm, transforming a security threat into an educational resource.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The system extracts and removes the harmful elements (malicious links, viruses, phishing content) from the communication while retaining the benign structural elements (formatting, branding, message structure). This separation allows the communication to serve as training material without its harmful components.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If authentication requirements are escalated continuously, then security is improved, but user convenience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts authentication requirements based on real-time analysis of user behavior and communication characteristics. Authentication intensity varies continuously rather than remaining static, adapting to the perceived risk level of each interaction to balance security and convenience.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops that monitor user actions, communication patterns, and security events to continuously adjust authentication requirements. This feedback mechanism ensures authentication policies respond to actual risk conditions rather than following fixed rigid rules.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10992701B2Systems and methods for dynamic targeting of secure repurposed cross-channel electronic communications
Publication Date: 2021.04.27 BANK OF AMERICA CORP
  • US10992701B2 patent drawing
  • US10992701B2 patent drawing
  • US10992701B2 patent drawing

AI summary

Embodiments of the invention are directed to a system, method, or computer program product for dynamic targeting and training via repurposing malicious electronic communications via scrubbing for transmission within the entity. In this way, the invention may receive malicious electronic communications, block those communications, scrub the malicious data from the communication, and repurpose the now clean electronic communication as repurposed malicious electron communications configured for facilitating training and authentication escalation of user application access.