Phishing Detection Using User Trustworthiness Weighting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting phishing attacks are inadequate as they fail to effectively differentiate between accurate and inaccurate identifications by individuals, leading to uncertainty in classifying messages as phishing threats.

Innovation Solution

The approach involves conducting simulated phishing attacks to assess individuals' responses, assigning trustworthiness levels based on their performance, and weighting responses accordingly to determine the likelihood of a message being a real phishing attack.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple individuals independently analyze a flagged message to determine if it is a phishing attack, then the detection coverage is improved, but the uncertainty in classification increases due to inconsistent responses from different individuals

Engineering Contradiction:
Improvephishing attack detection accuracyVSAvoidmessage classification certainty
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system implements feedback by collecting responses from multiple individuals about the same flagged message, then using this feedback to compute a confidence score that reflects the consistency and reliability of the classification. The confidence score is derived from analyzing whether multiple independent reviewers agree on the phishing status, transforming individual uncertain judgments into a aggregated reliable metric.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies a universal confidence scoring mechanism that works across different flagged messages and different groups of reviewers. This multi-functional approach allows the same methodology to be applied regardless of which individuals are reviewing which messages, creating a consistent framework for evaluating classification certainty across the entire system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If computer software or security experts are used to provide official determination of flagged messages, then the measurement precision is improved, but the device complexity and resource requirements increase

Engineering Contradiction:
Improvephishing message classification accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing ordinary users to independently analyze and classify flagged messages without requiring external security experts or complex automated software. Each user applies their own judgment to evaluate whether a message is phishing, and the system aggregates these self-service classifications to reach a confident determination.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The confidence score acts as an intermediary that mediates between multiple individual judgments and the final classification decision. Rather than directly relying on complex software or expert analysis, the system uses this intermediate metric to translate diverse user responses into a unified confidence level that drives the final phishing determination.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If trustworthiness levels are assigned to individuals based on their response accuracy to simulated phishing attacks, then the detection accuracy is improved, but the time and resources required for assessment increase

Engineering Contradiction:
Improveindividual response reliabilityVSAvoidtrustworthiness assessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by conducting simulated phishing attacks beforehand to assess and establish trustworthiness levels for each user before they are needed for actual phishing detection. This advance assessment creates a ready-to-use reliability metric that can be quickly applied when real flagged messages need evaluation, avoiding the need for time-consuming assessments at the moment of detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial action by using only the essential trustworthiness metrics derived from simulated phishing responses, rather than comprehensively evaluating all possible user characteristics. This selective approach captures the most relevant reliability indicator while minimizing the time and resources required for assessment.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9398038B2Collaborative phishing attack detection
Publication Date: 2016.07.19 COFENSE INC
  • US9398038B2 patent drawing
  • US9398038B2 patent drawing
  • US9398038B2 patent drawing

AI summary

Described herein are methods, network devices and machine-readable storage media for detecting whether a message is a phishing attack based on the collective responses from one or more individuals who have received that message. The individuals may flag the message as a possible phishing attack, and/or may provide a numerical ranking indicating the likelihood that the message is a possible phishing attack. As responses from different individuals may have a different degree of reliability, each response from an individual may be weighted with a corresponding trustworthiness level of that individual, in an overall determination as to whether a message is a phishing attack. A trustworthiness level of an individual may indicate a degree to which the response of that individual can be trusted and/or relied upon, and may be determined by how well that individual recognized simulated phishing attacks.