Automated Phishing Detection Rule Evolution via Recursive Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional phishing detection technologies are inefficient in addressing new and constantly changing threats, and they have a significant response time delay due to manual or semi-automatic analysis, leading to a high number of users falling victim to phishing attacks.

Innovation Solution

A system and method for automatically developing and evolving phishing detection rules by applying a set of predefined criteria to quantitative scores of predefined parameters, recursively generating new rules to detect and mitigate phishing content in incoming data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual or semi-automatic analysis is used to detect phishing threats, then detection accuracy can be maintained, but response time becomes significantly delayed

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system automatically evolves detection rules by analyzing phishing patterns and generating updated rules without human intervention. The rule evolution engine autonomously processes phishing indicators, adjusts rule parameters, and creates new detection rules, enabling the system to serve itself in maintaining and improving detection capabilities while reducing response time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback mechanism where detection results and phishing patterns are continuously analyzed to evolve and refine detection rules. The rule evolution engine uses feedback from detected phishing indicators and quantitative scores to automatically adjust and generate improved detection rules, creating a closed-loop system that adapts over time.

Inventive Principle:
Principle #23Feedback

2Reliability

If conventional phishing detection technologies are used, then known threats can be detected, but new and constantly changing threats cannot be addressed efficiently

Engineering Contradiction:
Improvedetection reliability for known threatsVSAvoidability to detect new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The detection rules are made dynamic through automatic evolution. Instead of static rules that require manual updates, the system continuously adapts rules based on analyzed phishing patterns and quantitative scores. The rule evolution engine dynamically generates updated rules that reflect current phishing tactics, enabling the system to maintain reliability for known threats while adapting to new threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary analysis of phishing patterns and evolves detection rules in advance before new threats fully manifest. By continuously analyzing incoming data and pre-evolving rules based on emerging patterns, the system prepares detection capabilities ahead of time, enabling faster response to new threats while maintaining protection against known threats.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If manual analysis methods are employed, then detection rules can be carefully crafted, but the process becomes time-consuming and inefficient

Engineering Contradiction:
Improverule crafting qualityVSAvoidrule development efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The manual mechanical process of rule crafting is replaced with an automated computational system. The rule evolution engine uses algorithms to analyze phishing patterns, calculate quantitative scores, and generate detection rules automatically. This substitution of manual mechanical analysis with automated computational processing maintains rule quality while dramatically improving development efficiency and speed.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The rule evolution engine acts as an intermediary between raw phishing data and final detection rules. Instead of direct manual analysis, the engine processes data through automated analysis, pattern recognition, and rule generation steps, serving as a mediator that transforms raw information into refined detection rules with high efficiency while preserving quality through systematic processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3065367B1System and method for automated phishing detection rule evolution
Publication Date: 2018.02.07 AO KASPERSKY LAB
  • EP3065367B1 patent drawingFigure 1A
  • EP3065367B1 patent drawingFigure 1B
  • EP3065367B1 patent drawingFigure 1C

AI summary

System and method for automatically developing phishing detection rules. Based on detected phishing indicia, a quantitative score is computed for each of a plurality of predefined parameters, with each of the parameters relating to at least one of the phishing indicia. A requirement for evolving a phishing detection rule is assessed, and a new phishing detection rule is generated based on selected parameter scores meeting the rule evolution criteria and on corresponding content of the phishing indicia relating to those selected parameter scores. New phishing detection rules are applied recursively to detect phishing indicia, and more new rules can be further evolved in recursive fashion.