Phishing Response Pollution via Fake Data Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Phishing communications pose a significant threat as they can deceive users into providing sensitive information, and existing email filtering technologies are not effective enough to prevent this, allowing phishers to exploit such information with minimal cost and effort.

Innovation Solution

Generating and transmitting 'fake' sensitive information in response to phishing messages to pollute the phisher's response pool, making it difficult for them to exploit real information, and using AI and NLP to analyze and respond to phishing attempts by mimicking user interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If email filtering technologies are used to block phishing messages, then some phishing emails are filtered out, but many phishing emails still make it through to users' inboxes

Engineering Contradiction:
Improvephishing email filtering effectivenessVSAvoidphishing email delivery success rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system preemptively responds to phishing messages by generating fake sensitive information before the phisher can exploit real user data. This preliminary action pollutes the phisher's response pool, making it harder for them to successfully exploit genuine sensitive information even if their phishing emails bypass filtering mechanisms

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system converts the harmful phishing campaign into a beneficial opportunity by using the phisher's own infrastructure to distribute fake sensitive information. The phisher's email delivery system, which was intended to spread malicious content, is instead used to propagate dummy data that protects real users from exploitation

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Reliability

If phishing messages are quarantined to prevent users from providing real sensitive information, then user security is improved, but phishers can still exploit obtained information with minimal cost

Engineering Contradiction:
Improveuser account securityVSAvoidphishing campaign implementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system introduces an intermediary layer between the phisher and real user data by generating and distributing fake sensitive information through automated botnets. This intermediary data pool acts as a buffer that increases the phisher's operational cost and complexity while maintaining user security through quarantine mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If fake sensitive information is generated and transmitted to pollute phisher response pools, then real sensitive information is protected, but computational resources are required to generate and manage fake data

Engineering Contradiction:
Improvesensitive information protectionVSAvoidcomputational resources for fake data generation
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system employs self-service mechanisms where automated botnets generate and distribute fake sensitive information without requiring continuous human intervention or management. The botnets autonomously execute the fake data generation and distribution tasks, reducing the computational overhead on centralized systems while maintaining protection efficacy

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12015639B2Systems and methods for polluting phishing campaign responses
Publication Date: 2024.06.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12015639B2 patent drawing
  • US12015639B2 patent drawing
  • US12015639B2 patent drawing

AI summary

Techniques for polluting phishing campaign responses with content that includes fake sensitive information of a type that is being sought in phishing messages. Embodiments disclosed herein identify phishing messages that are designed to fraudulently obtain sensitive information. Rather than simply quarantining these phishing messages from users' accounts to prevent users from providing “real” sensitive information, embodiments disclosed herein analyze these phishing messages to determine what type(s) of information is being sought and then respond to these phishing messages with “fake” sensitive information of these type(s). For example, if a phishing message is seeking sensitive credit card and/or banking account information, some fake information of this type(s) may be generated and sent in response to the phishing message. In various implementations, a natural language processing (NLP) model may be used to analyze the phishing message and/or generate a response thereto.