Phishing Email Action Pause and Confirm Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-ransomware technologies do not provide users with the autonomy to make decisions regarding suspect phishing emails, lacking training on how to approach or act upon such emails, and traditional methods of customizing notifications are slow and cumbersome.

Innovation Solution

A system that allows users to review and confirm actions associated with untrusted emails, providing autonomy in decision-making and enabling administrators to dynamically customize notifications through a user interface, which includes a driver monitoring processes, a monitor library, and a user console to pause and manage URL requests, and display configurable notifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anti-ransomware technologies automatically remove threats without user involvement, then security protection is improved, but user autonomy and training opportunities are lost

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser autonomy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system introduces an intermediary confirmation interface between the threat detection and automatic removal processes. When a phishing email or malicious attachment is detected, the system pauses execution and presents a confirmation dialog to the user, allowing them to review the threat assessment and make an informed decision before the protective action is taken. This mediator layer preserves user autonomy while maintaining security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional notification customization methods are used, then system control is maintained, but customization speed and user experience are reduced

Engineering Contradiction:
Improvesystem controlVSAvoidcustomization speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables administrators to customize notification content, timing, and delivery methods directly through a web-based interface without requiring system administrator intervention or complex configuration procedures. Users can independently modify notification settings, select templates, and adjust parameters according to their needs, significantly accelerating the customization process while maintaining system control through approved templates and guidelines.

Inventive Principle:
Principle #25Self-service

3Loss of information

If users are given the opportunity to review and confirm actions with untrusted emails, then user training and awareness are improved, but system productivity is reduced

Engineering Contradiction:
Improveuser awarenessVSAvoidsystem productivity
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The system applies selective pausing only to emails that meet specific risk criteria rather than blocking all external communications. The confirmation interface is presented based on risk assessment algorithms that analyze sender reputation, email content, attachment types, and user behavior patterns. This partial action approach provides training opportunities for high-risk scenarios while minimizing interruptions for low-risk communications, thereby preserving overall system productivity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11930028B2Systems and methods for providing user interfaces based on actions associated with untrusted emails
Publication Date: 2024.03.12 KNOWBE4 INC
  • US11930028B2 patent drawing
  • US11930028B2 patent drawing
  • US11930028B2 patent drawing

AI summary

The present disclosure describes a system that notifies users regarding specific user decisions with respect to solution phishing emails. The system notifies users when users perform specific actions with respect to the untrusted phishing emails. The system pauses execution of these actions and prompts the user to confirm whether to take the actions or to revert back to review the actions. In contrast from anti-ransomware technologies which are entirely in control, the system gives the user autonomy in deciding actions relating to untrusted phishing emails. The system interrupts execution of actions related to untrusted phishing emails in order to give users a choice on whether to proceed with actions.