Phishing Protection System Using Dynamic Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for protecting user credentials against phishing attacks are inadequate, particularly when dealing with unassessed or unconfirmed domains, as they often result in excessive delays or fail to provide tailored security responses based on user risk levels.

Innovation Solution

A system that evaluates user risk scores based on phishing susceptibility and role within an organization, applying customized security measures such as blocking interactions, redirecting users, or presenting profile pictures to manage access to unassessed domains, while ensuring user privacy through anonymization and off-device communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional phishing protection methods (blacklisting, DNS filtering) are used, then known phishing sites can be blocked, but they fail to provide effective protection against unassessed or unconfirmed domains

Engineering Contradiction:
Improvephishing protection effectivenessVSAvoidability to handle unassessed domains
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary risk assessment and classification of domains before users access them. By evaluating domains in advance and assigning risk levels, the system prepares security responses beforehand, enabling effective protection against unassessed domains without causing delays during actual access attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts security measures based on real-time risk assessments and user-specific risk scores. Rather than using static blacklists, the system continuously evaluates domains and adapts security responses (such as blocking, warning, or allowing access) based on the assessed risk level and user context, making the protection both reliable and adaptable.

Inventive Principle:
Principle #15Dynamics

2Reliability

If strict security measures are applied to all users regardless of risk level, then security coverage is maximized, but user experience deteriorates due to excessive delays and unnecessary blocking

Engineering Contradiction:
Improvesecurity coverageVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different security measures to different users based on their individual risk scores and roles within the organization. High-risk users receive stricter security controls, while low-risk users experience minimal interference. This localized approach to security ensures comprehensive coverage while maintaining smooth user experience for legitimate users.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes security parameters dynamically based on user risk scores and domain risk levels. Rather than applying uniform security measures, the system adjusts the stringency of security controls according to assessed parameters, allowing strict security where needed and relaxed access where safe, thereby balancing security coverage with user experience.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If comprehensive risk assessment and customized security measures are implemented for all users, then tailored phishing protection is achieved, but system complexity increases

Engineering Contradiction:
Improvetailored security response capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments users into different risk categories based on their roles, behaviors, and historical data. By dividing the user base into segments with different risk profiles, the system can apply customized security measures to each segment without having to individually assess and manage every single user, thereby reducing overall system complexity while maintaining adaptability.

Inventive Principle:
Principle #1Segmentation

4Reliability

If real-time phishing assessment is performed for every user access, then protection timeliness is improved, but processing delays increase

Engineering Contradiction:
Improveprotection timelinessVSAvoidaccess delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs domain risk assessments in advance and caches the results, so when users attempt to access domains, the evaluation is already complete or quickly retrieved. This preliminary action eliminates the need for real-time assessment during each access attempt, providing timely protection without causing delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12079755B2Computer systems and methods to protect user credential against phishing
Publication Date: 2024.09.03 LOOKOUT INC
  • US12079755B2 patent drawing
  • US12079755B2 patent drawing
  • US12079755B2 patent drawing

AI summary

Computer systems and methods to protect user credential against phishing with security measures applied based on determination of phishing risks of locations being visited, phishing susceptibility of users, roles of users, verification of senders of messages, and/or the timing of stages in accessing and interacting with the locations. For example, when a site is unclassified at the onset of being accessed by a user device, security measures can be selectively applied to allow the site to be initially viewed on the user device, but disallow some user interactions to reduce phishing risk. For example, a response to a domain name system (DNS) request can be customized based on a user risk level. For example, a message can be displayed without a profile picture of a contact of a user when the sender of the message appears to be the contact but cannot be verified to be the contact.