Phishing Score-Based Email Delivery Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Phishing emails pose a significant risk to computing systems and networks due to their deceptive nature, making it difficult to prevent all recipients from falling victim, especially when sent to large user groups.

Innovation Solution

A system that utilizes phishing scores to differentiate between users likely to respond to phishing emails and those less likely, delaying or preventing communication of such emails to high-risk users based on the actions of low-risk users, thereby improving network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If phishing emails are sent to all users simultaneously, then the communication efficiency is high, but the risk of phishing spread increases significantly

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidphishing spread risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the user base into different risk groups based on phishing scores, sending emails to low-risk users first and high-risk users later. This segmentation allows the system to maintain communication efficiency while reducing phishing spread risk by isolating potential infection sources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by sending phishing emails to low-risk users before high-risk users. This preliminary testing allows the system to detect phishing emails early and prevent their spread to the entire organization, thereby reducing harm while maintaining overall communication efficiency.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If phishing emails are delayed or sent selectively to certain user groups, then the risk of phishing spread is reduced, but the communication efficiency decreases

Engineering Contradiction:
Improvephishing spread riskVSAvoidcommunication efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent changes the parameter of email delivery timing based on user risk scores. By dynamically adjusting delivery parameters (timing, recipient selection) according to phishing scores, the system reduces phishing spread risk while minimizing the impact on communication efficiency through automated, score-based decisions.

Inventive Principle:
Principle #35Parameter changes

3Quantity of substance

If all users are exposed to phishing emails simultaneously, then the testing coverage is comprehensive, but the effectiveness of phishing prevention is reduced

Engineering Contradiction:
Improvetesting coverageVSAvoidphishing prevention effectiveness
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent applies preliminary action by testing phishing emails on low-risk users first before exposing high-risk users. This staged approach maintains comprehensive testing coverage while improving prevention effectiveness by containing potential phishing spread within the low-risk group.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical approach of simultaneous email distribution with an automated, intelligence-based system that uses phishing scores to determine delivery timing and recipient selection. This substitution enables comprehensive testing while maintaining prevention effectiveness through automated risk-based routing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10110623B2Delaying phishing communication
Publication Date: 2018.10.23 BANK OF AMERICA CORP
  • US10110623B2 patent drawing
  • US10110623B2 patent drawing
  • US10110623B2 patent drawing

AI summary

According to one embodiment, an apparatus is configured to store a plurality of phishing scores, each phishing score of the plurality of phishing scores indicating a likelihood that a user of a plurality of users will respond to a phishing email. The apparatus is configured to receive an email, to select a first subset of the plurality of users based on the phishing score of each user in the first subset, and to select a second subset of the plurality of users based on the phishing score of each user in the second subset, wherein each user in the second subset is determined to be more likely to respond to a phishing email than each user in the first subset. The apparatus is configured to communicate the email to the first subset and to communicate the email to the second subset based on the first subset's responses to the email.