User-Generated Authentication for Vishing Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for detecting and preventing vishing attacks, such as AI/ML models and blocklists, fail to provide a high level of security due to limitations in training data and human judgment, leading to insufficient accuracy in identifying vishing attacks.

Innovation Solution

The use of user-generated authentication information, where a user device receives a request for first authentication information, sends it to the call source, and receives second authentication information, which is then used to authenticate the call, leveraging machine learning models to determine the type of authentication information based on call characteristics and security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If AI/ML models are used to detect vishing attacks, then detection capability is improved, but accuracy is insufficient due to limited training data

Engineering Contradiction:
Improvevishing attack detection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSMeasurement precision

Solution Approach 1:

The system performs preliminary authentication by requesting authentication information from the user device before the telephone call is connected. This advance verification step allows the system to authenticate the source without relying solely on AI/ML detection during the call, thereby improving detection accuracy while maintaining the capability to identify vishing attacks.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If blocklists are used to prevent vishing attacks, then known malicious actors are blocked, but effectiveness is limited by incomplete blocklist data

Engineering Contradiction:
Improveprotection against known malicious actorsVSAvoidblocklist completeness
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system enables each user device to independently authenticate incoming calls by generating and verifying authentication information locally. This self-service approach eliminates reliance on centralized blocklists, allowing the system to adapt to new malicious actors automatically without requiring updates to blocklist data, thereby improving both reliability and adaptability.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If human judgment is used to recognize vishing attacks, then flexibility in assessment is improved, but accuracy is limited by human error

Engineering Contradiction:
Improvejudgment flexibilityVSAvoidauthenticity judgment accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system replaces human judgment with automated authentication mechanisms that verify call sources using cryptographic or verified identification methods. This substitution eliminates human error while maintaining the flexibility to assess various call scenarios, thereby improving detection accuracy without sacrificing adaptability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Measurement precision

If user-generated authentication information is used to authenticate call sources, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvecall source authentication accuracyVSAvoidauthentication system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The authentication process is performed as a preliminary step before the call is connected, using existing user device capabilities. By leveraging already-available authentication mechanisms in the user device rather than introducing new complex systems during the call, the solution improves accuracy while minimizing added complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12113929B2Systems and methods for detecting and/or preventing vishing attacks using user-generated authentication information
Publication Date: 2024.10.08 CAPITAL ONE SERVICES LLC
  • US12113929B2 patent drawing
  • US12113929B2 patent drawing
  • US12113929B2 patent drawing

AI summary

A computer-implemented method for authenticating a source of a telephone call to a recipient of the telephone call may include receiving, prior to receiving the telephone call, a request to input first authentication information. The first authentication information may include a passcode or a selection of a security question. The method may include receiving input of the first authentication information and sending, by the user device, the first authentication information to a computing device associated with the source of the telephone call. The method may include receiving the telephone call from the source and receiving input from the recipient of the telephone call to answer the telephone call. The method may include receiving second authentication information from the computing device, where the second authentication information may include the passcode or an answer to the security question. The method may include outputting the second authentication information.