Phishing Attempt Search Interface Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large and distributed IT networks face difficulties in identifying and correlating phishing attacks, making it challenging to detect and respond to phishing attempts effectively.

Innovation Solution

A phishing attempt search interface is implemented to receive notifications of phishing attempts, allowing for the identification of affected recipients and providing a summary to facilitate appropriate security measures, including the ability to search for additional targets and perform security actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security monitoring methods are used in large distributed IT networks, then network security coverage is maintained, but the ability to identify and correlate phishing attacks deteriorates due to network complexity and distribution

Engineering Contradiction:
Improvephishing attack detection capabilityVSAvoidnetwork distribution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple phishing attempt notifications into a single consolidated view within the security management node. By aggregating notifications from multiple recipients and sources into one interface, the system maintains reliable phishing detection while reducing the operational complexity of managing distributed security monitoring across large networks.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If comprehensive security monitoring is implemented across all recipients, then phishing attack detection accuracy improves, but the time required to process and analyze notifications increases

Engineering Contradiction:
Improvephishing attack identification accuracyVSAvoidnotification processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary aggregation and consolidation of phishing notifications automatically as they are received at the security management node. By pre-processing and organizing notifications before analysis, the system maintains high identification accuracy while reducing the time required for security personnel to process and respond to phishing attempts.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If detailed tracking of each phishing notification is maintained, then security response precision improves, but the complexity of managing and correlating data increases

Engineering Contradiction:
Improvesecurity response precisionVSAvoiddata management complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent merges detailed tracking information from multiple phishing notifications into consolidated data structures within the security management node. The interface presents aggregated views that maintain precise security response capabilities while simplifying data management complexity through unified correlation of recipient information, notification details, and attack patterns.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11374970B2Phishing attempt categorization/aggregation interface
Publication Date: 2022.06.28 SERVICENOW INC
  • US11374970B2 patent drawing
  • US11374970B2 patent drawing
  • US11374970B2 patent drawing

AI summary

Systems, methods, and media are used to identify phishing attacks. A notification of a phishing attempt with a parameter associated with a recipient of the phishing attempt is received at a security management node. In response, an indication of the phishing attempt is presented in a phishing attempt search interface. The reported phishing attempts may be aggregated based upon specified criteria to avoid redundant incidents that may hinder remediation efforts.