Phishing Engine for Dormant Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cybersecurity approaches are reactive and fail to predictively address evolving cyber threats that exploit social media and social networks, leading to increased risks for individuals and organizations.

Innovation Solution

A predictive and active social risk management system that uses a scoring algorithm to assess vulnerabilities by analyzing social entity interactions, generating reports, and initiating security actions based on risk thresholds, including the use of a phishing engine to track and mitigate phishing attempts and impersonation threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional reactive security measures are used, then endpoint and network security are maintained, but predictive identification of dormant malicious entities is lost

Engineering Contradiction:
Improvesecurity defense reliabilityVSAvoidresponse time to threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by proactively generating test hyperlinks and scanning social networks to identify dormant malicious entities before they can initiate attacks. The phishing engine creates test links and monitors their selection by social entities, enabling early detection and prediction of potential threats rather than waiting for reactive responses after breaches occur.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If social media platforms are monitored continuously, then predictive threat identification is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system introduces a phishing engine as an intermediary component that acts as a mediator between the monitoring system and social networks. This engine generates test hyperlinks and facilitates controlled interactions with social entities, enabling precise threat detection through structured experiments rather than unstructured continuous monitoring, thereby managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates copies of potential phishing scenarios by generating test hyperlinks that mimic real phishing attempts. These synthetic test cases allow the system to measure and analyze entity behavior in controlled conditions, improving detection accuracy without requiring direct monitoring of all actual social media interactions.

Inventive Principle:
Principle #26Copying

3Measurement precision

If hyperlinks are generated and distributed to assess vulnerability, then predictive risk assessment is improved, but exposure to phishing attempts increases

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidexposure to phishing threats
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system converts the potential harm of phishing exposure into a benefit by using controlled test hyperlinks to assess vulnerability. Instead of avoiding all phishing-like content, the system deliberately introduces benign test links that simulate phishing attempts, allowing it to measure and improve security posture by transforming the harmful exposure into a diagnostic tool.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS10999130B2Identification of vulnerability to social phishing
Publication Date: 2021.05.04 ZEROFOX INC
  • US10999130B2 patent drawing
  • US10999130B2 patent drawing
  • US10999130B2 patent drawing

AI summary

A computer-implemented method includes generating, by one or more processors, a hyperlink targeting a Uniform Resource Locator (URL), detecting a selection of the generated hyperlink by one or more social entities across one or more social networks, generating a report, wherein the generated report includes analytical details regarding the selection of the generated hyperlink by the one or more social entities, and providing the generated report to a user associated with a protected social entity.