Phishing Campaign Ranker Using User Response Scores

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Phishing campaigns pose a significant risk to computing systems and networks due to their deceptive nature and high response rates from recipients, making it difficult to prevent security breaches even with large recipient pools.

Innovation Solution

A system that ranks phishing campaigns based on user response likelihood scores, determining priority scores for each campaign and ranking them for immediate review, allowing administrators to focus on the most threatening campaigns first.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators review all phishing campaigns equally, then comprehensive security coverage is achieved, but time consumption and review efficiency deteriorate

Engineering Contradiction:
Improvesecurity coverageVSAvoidreview time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments phishing campaigns into different priority levels based on calculated priority scores. By dividing the review workload into high-priority and low-priority segments, administrators can focus their time on the most critical campaigns first while maintaining comprehensive security coverage through systematic review of all campaigns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary analysis of phishing campaigns by calculating priority scores based on multiple factors (response rates, user profiles, campaign characteristics) before administrator review. This preliminary ranking action allows administrators to immediately identify and address the most threatening campaigns without wasting time on less critical ones.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If administrators focus on high-priority campaigns first, then review efficiency is improved, but risk of missing low-priority threats worsens

Engineering Contradiction:
Improvereview efficiencyVSAvoidthreat detection completeness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements dynamic priority scoring that can be adjusted based on changing threat landscapes and organizational risk profiles. The priority scores are not static but can be recalculated as new information becomes available, allowing the system to adapt to emerging threats while maintaining efficient review workflows.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where administrator decisions and outcomes from campaign reviews feed back into the priority scoring model. This continuous feedback loop improves the accuracy of priority calculations over time, ensuring that both high-priority and previously low-priority campaigns are appropriately identified and reviewed.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If phishing score assessment is made more detailed, then accuracy of user response likelihood prediction is improved, but system complexity worsens

Engineering Contradiction:
Improvephishing score accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system uses multiple parameters (user response history, campaign characteristics, temporal factors) to calculate phishing scores, adjusting the weight and relevance of each parameter based on observed patterns. This parameter-based approach achieves detailed and accurate assessment without requiring overly complex system architecture, as the complexity is managed through configurable parameter weighting rather than structural complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9729573B2Phishing campaign ranker
Publication Date: 2017.08.08 BANK OF AMERICA CORP
  • US9729573B2 patent drawing
  • US9729573B2 patent drawing
  • US9729573B2 patent drawing

AI summary

According to one embodiment, an apparatus is configured to store a plurality of phishing scores, each phishing score of the plurality of phishing scores indicating a likelihood that a user will respond to a phishing email The apparatus is communicatively coupled to the memory and is configured to determine that a plurality of phishing campaigns are occurring. For each phishing campaign of the plurality of phishing campaigns, the apparatus is configured to determine that a plurality of users responded to the phishing campaign and to determine a priority score for the phishing campaign based on the phishing score of each user of the plurality of users. The apparatus is further configured to rank the plurality of phishing campaigns based on the priority score of each phishing campaign, wherein the phishing campaign of the plurality of phishing campaigns with the highest rank is reviewed first.