Terminal Device OTP Phishing Detection via Preliminary Communication Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Phishing attacks pose a significant threat to electronic transactions, as fraudsters deceive users into revealing sensitive information, such as one-time-passwords (OTPs), leading to unauthorized access and financial losses, with existing security measures like dynamic passcode authentication being insufficient in preventing such attacks.
Innovation Solution
Implementing a method on a terminal device to receive and analyze OTPs, identifying a validity period, and using risk scoring data models to determine if a remote entity is malicious, initiating a risk mitigation process if the entity is deemed fraudulent, which may include alerts, transaction termination, or blacklisting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dynamic passcode based identity authentication is implemented, then transaction security is improved, but vulnerability to phishing attacks increases
Solution Approach 1:
The system performs preliminary analysis of communications occurring during the OTP validity period before the transaction is completed. By detecting and analyzing communications from remote entities during this critical time window, the system can identify phishing attempts before they succeed, blocking malicious communications in advance while allowing legitimate transactions to proceed
Solution Approach 2:
The system introduces an intermediary analysis layer between the OTP transmission and the transaction completion. This intermediary component monitors and analyzes communications during the OTP validity period, acting as a mediator that can identify and block phishing attempts without interfering with legitimate authentication processes
2Ease of operation
If OTP validity period is extended to allow user flexibility, then ease of operation is improved, but exposure to phishing attacks increases
Solution Approach 1:
The system performs preliminary detection and analysis of communications during the entire OTP validity period. By monitoring communications in advance and identifying phishing patterns early, the system can maintain extended validity periods for user convenience while protecting against phishing through early detection and blocking of malicious communications
3Measurement precision
If comprehensive communication analysis is performed during OTP validity period, then detection accuracy is improved, but device complexity increases
Solution Approach 1:
The system extracts and analyzes only the essential elements of communications during the OTP validity period, such as sender identification, communication timing, and basic content patterns. By focusing on extracting only the critical phishing indicators rather than analyzing entire communications in detail, the system achieves high detection accuracy while minimizing processing complexity on the terminal device
Solution Approach 2:
The system employs a multi-functional communication analysis mechanism that can handle various types of communications (voice, text, data messages) using a unified analysis framework. This universal approach allows the system to detect phishing across multiple communication channels without requiring separate complex analysis systems for each channel, thereby improving detection accuracy while controlling overall device complexity
Data Source
AI summary
The invention provides systems, methods and computer program products for securing electronic transactions and users of electronic transaction services from phishing attacks by malicious attackers and fraudsters. A terminal device receives a first data communication comprising an OTP associated with a requested electronic transaction, and identifies a validity period associated with the OTP. The terminal device responds to detection of a second data communication between the terminal device and a remote entity during the identified validity period, by extracting content from the second data communication. The extracted content is analyzed and a risk decision is generated based on output of the analysis of the extracted content. The risk decision determines whether the remote entity comprises, or is controlled by, a malicious attacker. Responsive to the risk decision determining that the remote entity comprises, or is controlled by, a malicious attacker, the terminal device may initiate a risk mitigation process.


