Phishing Protection System Using Dynamic Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for protecting user credentials against phishing attacks are inadequate, particularly when dealing with unassessed or unconfirmed domains, as they often result in excessive delays or fail to provide tailored security responses based on user risk levels.
Innovation Solution
A system that evaluates user risk scores based on phishing susceptibility and role within an organization, applying customized security measures such as blocking interactions, redirecting users, or presenting profile pictures to manage access to unassessed domains, while ensuring user privacy through anonymization and off-device communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional phishing protection methods (blacklisting, DNS filtering) are used, then known phishing sites can be blocked, but they fail to provide effective protection against unassessed or unconfirmed domains
Solution Approach 1:
The system performs preliminary risk assessment and classification of domains before users access them. By evaluating domains in advance and assigning risk levels, the system prepares security responses beforehand, enabling effective protection against unassessed domains without causing delays during actual access attempts.
Solution Approach 2:
The system dynamically adjusts security measures based on real-time risk assessments and user-specific risk scores. Rather than using static blacklists, the system continuously evaluates domains and adapts security responses (such as blocking, warning, or allowing access) based on the assessed risk level and user context, making the protection both reliable and adaptable.
2Reliability
If strict security measures are applied to all users regardless of risk level, then security coverage is maximized, but user experience deteriorates due to excessive delays and unnecessary blocking
Solution Approach 1:
The system applies different security measures to different users based on their individual risk scores and roles within the organization. High-risk users receive stricter security controls, while low-risk users experience minimal interference. This localized approach to security ensures comprehensive coverage while maintaining smooth user experience for legitimate users.
Solution Approach 2:
The system changes security parameters dynamically based on user risk scores and domain risk levels. Rather than applying uniform security measures, the system adjusts the stringency of security controls according to assessed parameters, allowing strict security where needed and relaxed access where safe, thereby balancing security coverage with user experience.
3Adaptability or versatility
If comprehensive risk assessment and customized security measures are implemented for all users, then tailored phishing protection is achieved, but system complexity increases
Solution Approach 1:
The system segments users into different risk categories based on their roles, behaviors, and historical data. By dividing the user base into segments with different risk profiles, the system can apply customized security measures to each segment without having to individually assess and manage every single user, thereby reducing overall system complexity while maintaining adaptability.
4Reliability
If real-time phishing assessment is performed for every user access, then protection timeliness is improved, but processing delays increase
Solution Approach 1:
The system performs domain risk assessments in advance and caches the results, so when users attempt to access domains, the evaluation is already complete or quickly retrieved. This preliminary action eliminates the need for real-time assessment during each access attempt, providing timely protection without causing delays.
Data Source
AI summary
Computer systems and methods to protect user credential against phishing with security measures applied based on determination of phishing risks of locations being visited, phishing susceptibility of users, roles of users, verification of senders of messages, and/or the timing of stages in accessing and interacting with the locations. For example, when a site is unclassified at the onset of being accessed by a user device, security measures can be selectively applied to allow the site to be initially viewed on the user device, but disallow some user interactions to reduce phishing risk. For example, a response to a domain name system (DNS) request can be customized based on a user risk level. For example, a message can be displayed without a profile picture of a contact of a user when the sender of the message appears to be the contact but cannot be verified to be the contact.


