Phishing Report Clustering and ML Scoring for Security Triage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in quickly discerning malicious messages from a large volume of reported threats, leading to time-consuming processing and false positive reports for network security personnel.

Innovation Solution

A system with a phishing simulation module generates simulated phishing messages and allows users to report suspicious messages, which are then processed using a management console to determine if they are malicious, updating user reputation scores and aiding administrators in triaging incoming reports through message clustering and rule creation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are provided with a user interface to report suspected phishing attacks, then user awareness and reporting capability are improved, but the volume of false positive reports increases, making processing more time-consuming

Engineering Contradiction:
Improveuser reporting capabilityVSAvoidprocessing time for security personnel
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system automatically analyzes reported messages using machine learning models to determine whether they are phishing attacks or false positives, eliminating the need for manual review of every report by security personnel. The system serves itself by autonomously filtering and prioritizing reports based on their maliciousness score.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of security personnel reviewing each reported message is replaced with an automated electronic system using machine learning algorithms and AI models that can rapidly analyze message content, metadata, and patterns to classify reports without human intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Quantity of substance

If a large volume of phishing reports are collected from users, then the system captures more threats, but it becomes more difficult to quickly discern malicious messages from legitimate ones

Engineering Contradiction:
Improvenumber of reported threatsVSAvoiddifficulty of discerning malicious messages
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The system continuously learns from analyzed reports by updating its machine learning models with new data about phishing patterns and false positives. This feedback loop improves the accuracy of the maliciousness score over time, enabling the system to better distinguish malicious messages from legitimate ones as the volume of reports increases.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically adjusts the maliciousness score threshold and weighting parameters based on the evolving characteristics of phishing attacks and organizational patterns. By changing these parameters, the system adapts to new threat landscapes while maintaining efficient discrimination between malicious and legitimate messages.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If manual processing of phishing reports is used, then detailed analysis can be performed, but the response time to phishing attacks is significantly delayed

Engineering Contradiction:
Improveanalysis depthVSAvoidresponse speed to phishing attacks
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The analysis process is segmented into two stages: an automated initial assessment using machine learning models that provides rapid maliciousness scoring, and a secondary manual review stage for only those messages that require deeper analysis. This segmentation enables most reports to be processed quickly while maintaining the option for detailed analysis when needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary automated analysis of all reported messages before they reach security personnel, pre-classifying them with maliciousness scores and key findings. This preliminary action filters out obvious false positives and prioritizes genuine threats, so that when security personnel do review messages, they can focus their detailed analysis on the most suspicious cases.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9906554B2Suspicious message processing and incident response
Publication Date: 2018.02.27 COFENSE INC
  • US9906554B2 patent drawing
  • US9906554B2 patent drawing
  • US9906554B2 patent drawing

AI summary

The present invention relates to methods, network devices, and machine-readable media for an integrated environment for automated processing of reports of suspicious messages, and furthermore, to a network for distributing information about detected phishing attacks.