Obfuscated Tracking Element for Automated Phishing Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies struggle to proactively detect and mitigate phishing attempts in a vast and ever-changing online environment, requiring manual user or administrator intervention and are susceptible to detection by malicious actors.

Innovation Solution

Embedding an obfuscated tracking element in web pages that automatically detects and reports potential phishing sites by determining the current environment location, sending obfuscated data payloads to a phishing identification system, and performing mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual user or administrator intervention is used to detect phishing attempts, then detection can be performed with simple tools, but the detection speed and coverage are insufficient in a vast and ever-changing online environment

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system enables automated phishing detection by embedding tracking elements in web pages that automatically monitor and report phishing attempts without requiring manual user or administrator intervention. The tracking elements self-report when they detect their content has been copied to phishing sites, providing continuous automated surveillance of the online environment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system proactively embeds tracking elements in web pages before phishing attempts occur. These tracking elements are pre-positioned to monitor for copying and unauthorized use, enabling detection before users are impacted by phishing attacks rather than reacting after incidents occur.

Inventive Principle:
Principle #10Preliminary action

2Extent of automation

If tracking elements are embedded in web pages to detect phishing, then automated detection is achieved, but malicious actors may detect and silence the tracking elements

Engineering Contradiction:
Improveautomated detectionVSAvoidtracking element undetectability
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The tracking elements are designed to blend locally with legitimate web page content, making them indistinguishable from normal page elements. By matching the visual and structural characteristics of surrounding content, the tracking elements maintain local quality that prevents detection by malicious actors while preserving their monitoring functionality.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses tracking elements as intermediaries that operate covertly within phishing pages. These intermediaries report phishing activity indirectly through encoded communications, allowing the system to gather intelligence without the tracking elements being directly detected or targeted by malicious actors.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the tracking element monitors and reports phishing attempts in real-time, then user information is protected, but the system requires continuous monitoring and communication infrastructure

Engineering Contradiction:
Improveuser information protectionVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The tracking elements perform monitoring and reporting in periodic intervals rather than continuously. They check for phishing conditions at scheduled times and report when changes are detected, reducing system resource consumption while maintaining effective protection of user information through regular surveillance.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20250247423A1Performing automated detection of phishing web sites using embedded tracking element
Publication Date: 2025.07.31 TARGET BRANDS INC
  • US20250247423A1 patent drawing
  • US20250247423A1 patent drawing
  • US20250247423A1 patent drawing

AI summary

In some implementations, a method performed by data processing apparatuses includes serving a web page comprising an embedded markup image and a detection script. The detection script is configured to cause a client device to, in response to loading the embedded markup image, determine a current environment location indicative of a source of the web page, determine whether the current environment location matches a domain associated with a subject system, generate an obfuscated data payload based on the current environment location, and send a request to a predetermined endpoint in response to determining that the current environment location does not match the domain associated with the subject system. The request includes the obfuscated data payload.