Phishing Detection Using Individual Trustworthiness Weights

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods to detect phishing attacks are inadequate in distinguishing between accurate and inaccurate identifications, leading to uncertainty in determining the trustworthiness of individuals' responses, which affects the classification of messages as phishing attacks.

Innovation Solution

Conducting simulated phishing attacks and monitoring individuals' responses to calculate trustworthiness levels, allowing for the weighting of responses from trustworthy individuals more heavily than untrustworthy ones, thereby improving the accuracy of phishing attack classification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If simulated phishing attacks are conducted to train individuals, then individuals become more knowledgeable about phishing attacks, but the system cannot distinguish between accurate and inaccurate identifications by individuals

Engineering Contradiction:
Improveindividual knowledgeabilityVSAvoidresponse accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system implements feedback by analyzing individual responses to simulated phishing attacks and using this information to calculate trustworthiness levels. The feedback loop continues as these trustworthiness levels are then applied to weight responses in real phishing detection, improving the system's ability to distinguish accurate from inaccurate identifications over time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes the parameter of response weighting by introducing trustworthiness levels that are calculated based on individual performance in simulated attacks. This parameter transformation allows the system to differentiate between reliable and unreliable responses, converting unweighted responses into weighted assessments.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If all individual responses are treated equally, then the system captures all potential phishing threats, but false alarms increase due to untrustworthy responses

Engineering Contradiction:
Improvephishing detection coverageVSAvoidfalse alarms
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by assigning different trustworthiness weights to different individuals based on their specific performance characteristics. Instead of treating all responses uniformly, each individual's response is weighted according to their demonstrated ability to accurately identify phishing attacks, thereby reducing false alarms from untrustworthy sources while maintaining coverage.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If trustworthiness levels are calculated based on simulated attack responses, then accurate phishing identification is improved, but the complexity of the detection system increases

Engineering Contradiction:
Improvephishing identification accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary action by conducting simulated phishing attacks and calculating trustworthiness levels before actual phishing detection begins. This advance preparation establishes the weighting framework in advance, so that when real phishing detection occurs, the system can apply pre-calculated weights without adding operational complexity to the detection process itself.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9253207B2Collaborative phishing attack detection
Publication Date: 2016.02.02 COFENSE INC

AI summary

Described herein are methods, network devices and machine-readable storage media for detecting whether a message is a phishing attack based on the collective responses from one or more individuals who have received that message. The individuals may flag the message as a possible phishing attack, and/or may provide a numerical ranking indicating the likelihood that the message is a possible phishing attack. As responses from different individuals may have a different degree of reliability, each response from an individual may be weighted with a corresponding trustworthiness level of that individual, in an overall determination as to whether a message is a phishing attack. A trustworthiness level of an individual may indicate a degree to which the response of that individual can be trusted and/or relied upon, and may be determined by how well that individual recognized simulated phishing attacks.