Spoofed Domain Identification and User Training System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Domain spoofing poses a significant risk to organizations as users may inadvertently access spoofed domains, leading to information collection, malware injection, and damage to brand reputation, with existing technologies failing to effectively identify and mitigate these risks.

Innovation Solution

A security awareness system that identifies potential harmful domains by analyzing associated, spoofed, and look-alike domains, determines their registration status, and generates electronic training campaigns to educate users in distinguishing between legitimate and spoofed domains, incorporating risk assessments and user-specific training based on their role and history.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users access domains without verification, then ease of operation is improved, but security risk increases due to spoofed domains

Engineering Contradiction:
Improveease of domain accessVSAvoidsecurity risk from spoofed domains
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary identification of spoofed domains by analyzing domain similarity, registration status, and web server activity before users access domains. Risk indicators are calculated in advance and communicated to users, allowing them to make informed decisions without compromising ease of access to legitimate domains.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If the system tracks all third-party registered spoofed domains, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improveaccuracy of spoofed domain identificationVSAvoidsystem complexity for tracking domains
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies different tracking approaches based on domain characteristics. It specifically tracks privately registered spoofed domains with active web servers as these pose the highest risk, while using less resource-intensive methods for other domains. This selective approach maintains measurement precision for high-risk domains while reducing overall system complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If the system provides comprehensive training to all users, then reliability is improved, but loss of time increases due to training requirements

Engineering Contradiction:
Improveuser awareness of spoofed domainsVSAvoidtime spent on training
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system provides training selectively based on user risk indicators rather than uniformly to all users. Users with higher risk profiles or those who interact with domains showing risk indicators receive targeted training, while low-risk users receive minimal or no training. This approach maintains reliability by training those who need it most while reducing overall time loss.

Inventive Principle:
Principle #16Partial or excessive action

4Difficulty of detecting and measuring

If the system monitors all domain variations, then detection capability is improved, but loss of information increases due to privacy registration

Engineering Contradiction:
Improvedetection capability of spoofed domainsVSAvoidinformation about domain ownership
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The system converts the obstacle of privacy registration into a beneficial detection mechanism. Rather than being blocked by hidden ownership information, the system uses the presence of privacy registration itself as a risk indicator, combined with analysis of domain similarity, active web servers, and other observable characteristics to identify spoofed domains effectively.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS11902324B2System and methods for spoofed domain identification and user training
Publication Date: 2024.02.13 KNOWBE4 INC
  • US11902324B2 patent drawing
  • US11902324B2 patent drawing
  • US11902324B2 patent drawing

AI summary

Systems and methods are disclosed that minimize ongoing risk to an organization from user behaviors which magnify the severity of a spoofed domain. Systems and method are provided which enable an entity and users of an entity to identify potential harmful domains, combining search, discovery, reporting, the generation of risk indicators, end-user risk assessments, and training into a security awareness system.