Automated PII Detection on Dark Web Sites

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are inefficient in identifying and verifying compromised personally identifiable information (PII) on the dark web, making it difficult to determine the extent of risk associated with PII data breaches, as traditional methods are burdensome and impractical due to the vast number of unindexed websites on the dark web.

Innovation Solution

A system configured to identify PII data patterns on various websites, using a crawler to extract and process data, and an AI engine to verify PII, which compares extracted data to a database of compromised PII, assigning a risk score and prioritizing further searches based on detected URLs and PII patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional manual methods are used to search dark web sites for compromised PII, then the ability to verify compromised information is improved, but the time required and operational burden increase significantly due to the vast number of unindexed websites

Engineering Contradiction:
Improveverification capabilityVSAvoidsearch time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-service by deploying crawlers that autonomously navigate and search dark web sites without human intervention. The system automatically extracts PII data, compares it against compromised PII databases, and generates risk scores, eliminating the need for manual searching while maintaining verification reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical searching with automated computer-based systems. Crawlers automatically traverse dark web sites, extract data programmatically, and perform comparisons algorithmically, substituting human manual operations with automated mechanical processes that are both faster and more consistent

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If automated crawlers search all dark web sites, then the productivity of PII detection is improved, but the device complexity and resource requirements increase due to the vast number of sites to be searched

Engineering Contradiction:
Improvedetection efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the vast dark web landscape into manageable portions by targeting specific sites and pages that are most likely to contain compromised PII. Rather than uniformly searching all sites, the system prioritizes based on risk indicators, effectively dividing the search space into high-value and low-value targets

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by focusing computational resources on specific regions of the dark web that show higher indicators of PII compromise. Sites with known data breaches, high traffic to PII-related keywords, or patterns indicating illicit activity receive prioritized searching attention, while low-risk areas are searched less intensively

Inventive Principle:
Principle #3Local quality

3Measurement precision

If the system searches and verifies all PII data patterns, then the measurement precision of compromised information is improved, but the loss of time and processing resources increases significantly

Engineering Contradiction:
ImprovePII identification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial action by searching for and verifying only the most indicative PII data patterns and focusing on sites with highest risk indicators. Rather than exhaustively analyzing every possible data pattern across all dark web sites, the system concentrates resources on high-probability targets, achieving sufficient precision without the time cost of complete exhaustion

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20230385451A1Systems and methods of determining compromised identity information
Publication Date: 2023.11.30 EARLY WARNING SERVICES LLC
  • US20230385451A1 patent drawing
  • US20230385451A1 patent drawing
  • US20230385451A1 patent drawing

AI summary

A compromised data exchange system extracts data from websites using a crawler, detects portions within the extracted data that resemble personally identifying information (PII) data based on PII data patterns using a risk assessment module, and compares a detected portion to data within a database of disassociated compromised PII data to determine a match using the risk assessment module. A risk score may be assigned to a data item within the database in response to determining the match. In some embodiments, URL data may also be detected in the extracted data. The detected URL data represents further websites that can be automatically crawled by the system to detect further PII data.