Automated Phish Baiting System for Tracking Compromised Accounts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face difficulties in detecting and tracking phishing scams, as victims often unknowingly provide personal information to deceptive websites, making it hard to identify compromised accounts and locate unscrupulous parties.

Innovation Solution

An automated system, referred to as a cyber phish baiting system, provides fake information to phishing websites, tracks the use of this information to identify compromised accounts by logging IP addresses, and locates unscrupulous parties by tracing these addresses, using a database to populate fake credentials into phishing websites and emulate human interaction to avoid detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual baiting of phishing websites is performed by company analysts, then tracking of phishing activity is possible, but the process is time-consuming and labor-intensive

Engineering Contradiction:
Improvephishing tracking efficiencyVSAvoidtime required for manual baiting
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs automatic baiting of phishing websites without requiring manual analyst intervention. The automated system independently identifies phishing sites, submits fake credentials, tracks IP addresses, and flags compromised accounts, enabling the organization to monitor phishing attempts without continuous human effort.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of analysts visiting websites and entering credentials is replaced with an automated computer-based system that programmatically navigates phishing sites, submits test credentials, and tracks results through IP address logging and database queries.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If victims provide personal information directly to phishing websites, then phishing scams succeed, but companies cannot detect which accounts are compromised

Engineering Contradiction:
Improveaccount security monitoringVSAvoiddifficulty of identifying compromised accounts
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary baiting actions by submitting fake credentials to phishing websites before real victims are targeted. This proactive approach allows the system to pre-identify phishing sites and track their IP addresses, establishing a baseline for detecting compromised accounts before actual damage occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by tracking IP addresses from phishing submissions and cross-referencing them with login attempts on legitimate company websites. When matching IP addresses are detected, the system automatically flags those accounts as potentially compromised, providing continuous security monitoring feedback.

Inventive Principle:
Principle #23Feedback

3Productivity

If automated systems are used to bait phishing websites, then tracking efficiency improves, but the system complexity increases

Engineering Contradiction:
Improvephishing baiting automationVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The automated system performs multiple functions within a single integrated platform: it identifies phishing websites, navigates to them, submits fake credentials, logs IP addresses, queries databases for account information, and flags compromised accounts. This multi-functional approach consolidates what would otherwise require multiple separate tools and processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses intermediate components such as databases to store URL lists and credential information, and employs intermediary processes like IP address tracking and cross-referencing to connect phishing site data with account security data. These intermediaries simplify the overall system architecture by breaking down complex operations into manageable modular components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9027126B2Method and apparatus for baiting phishing websites
Publication Date: 2015.05.05 BANK OF AMERICA CORP
  • US9027126B2 patent drawing
  • US9027126B2 patent drawing
  • US9027126B2 patent drawing

AI summary

A cyber fraud phish baiting system for baiting a phishing website is disclosed. The cyber fraud phish baiting system is configured to store a plurality of URLs in a database and enter each of the URLs into a browser to view internet resources linked to the URLs. It is configured to scan the internet resources for information requests, obtain information responsive to the information requests from a database, enter responsive information into the information requests, and store the information requests and the responsive information entered into the information requests for each of the URLs. The internet resource may be a phishing website, and fake information is entered into the information requests.