Obfuscated Tracking Element for Automated Phishing Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies struggle to proactively detect and mitigate phishing attempts in a vast and ever-changing online environment, requiring manual user or administrator intervention and are susceptible to detection by malicious actors.
Innovation Solution
Embedding an obfuscated tracking element in web pages that automatically detects and reports potential phishing sites by determining the current environment location, sending obfuscated data payloads to a phishing identification system, and performing mitigation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual user or administrator intervention is used to detect phishing attempts, then detection can be performed with simple tools, but the detection speed and coverage are insufficient in a vast and ever-changing online environment
Solution Approach 1:
The system enables automated phishing detection by embedding tracking elements in web pages that automatically monitor and report phishing attempts without requiring manual user or administrator intervention. The tracking elements self-report when they detect their content has been copied to phishing sites, providing continuous automated surveillance of the online environment.
Solution Approach 2:
The system proactively embeds tracking elements in web pages before phishing attempts occur. These tracking elements are pre-positioned to monitor for copying and unauthorized use, enabling detection before users are impacted by phishing attacks rather than reacting after incidents occur.
2Extent of automation
If tracking elements are embedded in web pages to detect phishing, then automated detection is achieved, but malicious actors may detect and silence the tracking elements
Solution Approach 1:
The tracking elements are designed to blend locally with legitimate web page content, making them indistinguishable from normal page elements. By matching the visual and structural characteristics of surrounding content, the tracking elements maintain local quality that prevents detection by malicious actors while preserving their monitoring functionality.
Solution Approach 2:
The system uses tracking elements as intermediaries that operate covertly within phishing pages. These intermediaries report phishing activity indirectly through encoded communications, allowing the system to gather intelligence without the tracking elements being directly detected or targeted by malicious actors.
3Reliability
If the tracking element monitors and reports phishing attempts in real-time, then user information is protected, but the system requires continuous monitoring and communication infrastructure
Solution Approach 1:
The tracking elements perform monitoring and reporting in periodic intervals rather than continuously. They check for phishing conditions at scheduled times and report when changes are detected, reducing system resource consumption while maintaining effective protection of user information through regular surveillance.
Data Source
AI summary
In some implementations, a method performed by data processing apparatuses includes serving a web page comprising an embedded markup image and a detection script. The detection script is configured to cause a client device to, in response to loading the embedded markup image, determine a current environment location indicative of a source of the web page, determine whether the current environment location matches a domain associated with a subject system, generate an obfuscated data payload based on the current environment location, and send a request to a predetermined endpoint in response to determining that the current environment location does not match the domain associated with the subject system. The request includes the obfuscated data payload.


