Phishing Probability Scoring Model for Email Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Phishing activities pose a significant challenge due to their deceptive nature, making it difficult for individuals and corporations to detect and prevent fraudulent internet-based attacks, as the emails sent by phishers often appear legitimate and resemble communications from trusted entities.

Innovation Solution

A system and method that utilize a computer program product to calculate a threat score for websites by comparing input data, such as URLs or emails, to historical threat data stored in a database, using keyword combinations and a mathematical algorithm to determine the probability of fraudulent activity, allowing for effective monitoring and potential shutdown of threatening websites.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If phishing emails are made to resemble legitimate communications, then the deception effectiveness is improved, but the detectability worsens

Engineering Contradiction:
Improvedeception effectivenessVSAvoiddetectability
Core Design Contradiction:
Ease of manufactureVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary analysis of emails before they reach users by examining URLs, domains, and content patterns against a database of known phishing characteristics. This advance detection allows the system to identify phishing attempts while they are still in transit, preventing them from reaching end users who would otherwise be deceived by their legitimate appearance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary detection system that acts as a mediator between phishing emails and users. This system analyzes email characteristics, cross-references them with historical phishing data, and blocks suspicious communications before they can deceive users, effectively creating a protective layer that reveals the true nature of disguised phishing attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If corporations implement comprehensive phishing detection systems, then the protection capability is improved, but the system complexity worsens

Engineering Contradiction:
Improveprotection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The detection system is divided into distinct functional modules: URL analysis component, domain verification component, content pattern matching component, and database query component. Each module handles a specific aspect of phishing detection independently, allowing the system to achieve comprehensive protection while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs a multi-functional detection mechanism that simultaneously analyzes multiple email attributes (URLs, domains, content, headers) using a unified approach. This universal detection framework handles various types of phishing attempts through a single system architecture, reducing overall complexity compared to having separate specialized systems for each detection task.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If historical threat data is extensively stored and analyzed, then the detection accuracy is improved, but the data processing time worsens

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies different analysis depths to different email components based on their risk indicators. High-risk elements like suspicious URLs or domains from known phishing sources receive intensive analysis against the full historical database, while low-risk elements undergo lighter validation. This localized quality approach ensures high detection accuracy for critical elements while minimizing processing time for safer content.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial analysis on all emails (basic validation) and excessive analysis only on suspicious elements (full database cross-referencing). This selective approach processes the majority of emails quickly with minimal checks, while applying comprehensive historical data analysis only to emails that trigger suspicion thresholds, thereby balancing accuracy with processing speed.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8769695B2Phish probability scoring model
Publication Date: 2014.07.01 BANK OF AMERICA CORP
  • US8769695B2 patent drawing
  • US8769695B2 patent drawing
  • US8769695B2 patent drawing

AI summary

In general, embodiments of the invention relate to systems, methods, and computer program products for determining the probability that a given website is conducting or is related to fraudulent activity, including phishing activity. More particularly, embodiments of the invention relate to automatically monitoring and scoring URLs for fraudulent activity by parsing keywords, combinations of keywords, and other relevant data from an input communication, such as an email, and analyzing the data obtained against a database containing a plurality of grading factors.