Website Security Module Detecting Phishing via Communication Anomalies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current website security technologies are ineffective in detecting and preventing security breach attempts, such as keylogging, phishing, man-in-the-browser, and pharming attacks, due to their reliance on user awareness and skill, and the ability of malicious programs to hide and mimic legitimate functions.

Innovation Solution

A website security system comprising anti-trojan, anti-phishing, anti-mib, and anti-pharming software modules embedded in website code, which monitor communications, detect anomalies, and alert servers to modify user permissions or report suspicious activity, including scanning for unauthorized instances and intercepting data breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current website security technologies rely on user awareness and skill to detect security breaches, then user responsibility is maintained, but detection effectiveness deteriorates due to user limitations

Engineering Contradiction:
Improvedetection effectivenessVSAvoiduser skill requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security module operates autonomously on the user's computer without requiring user intervention. It automatically monitors communications, detects anomalies, and responds to security threats, allowing the system to protect itself and the user without relying on user expertise

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

An intermediary security module is introduced between the user and the website communications. This module intercepts and analyzes communications, detecting security breaches automatically and responding without requiring user awareness or action

Inventive Principle:
Principle #24Intermediary (Mediator)

2Duration of action of stationary object

If malicious programs hide themselves in the system with rootkit functionality, then program persistence is improved, but detection difficulty increases

Engineering Contradiction:
Improveprogram persistenceVSAvoiddetection difficulty
Core Design Contradiction:
Duration of action of stationary objectVSDifficulty of detecting and measuring

Solution Approach 1:

Instead of trying to detect hidden rootkits directly, the security module inverts the approach by monitoring for anomalies in communications that indicate the presence of malicious programs. It detects the effects of rootkits rather than the rootkits themselves, making detection possible even when programs hide their presence

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The security module continuously monitors communications and provides feedback about detected anomalies. This ongoing feedback mechanism allows it to detect persistent malicious programs that attempt to hide, as their communications will eventually exhibit detectable patterns or anomalies

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If legitimate keylogging programs are used for monitoring employee activity, then administrative control is improved, but security risk increases due to potential misuse

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The security module changes the 'color' or characteristics of communications by analyzing them for anomalies. It identifies legitimate monitoring versus malicious keylogging by detecting unusual patterns in communications, effectively distinguishing between authorized administrative control and unauthorized security risks

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The security module monitors changes in communication parameters to detect malicious activity. By analyzing parameters such as communication frequency, data volume, and timing patterns, it can distinguish between legitimate monitoring programs and malicious keyloggers, reducing security risks while maintaining administrative control capabilities

Inventive Principle:
Principle #35Parameter changes

4Productivity

If phishing websites use identical look and feel to legitimate sites, then phishing effectiveness is improved, but technical detection capability deteriorates

Engineering Contradiction:
Improvephishing effectivenessVSAvoidtechnical detection capability
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The security module acts as an intermediary that intercepts communications between the user and the website. It analyzes the communication parameters and metadata to detect phishing attempts, providing technical detection capability that goes beyond visual inspection and can identify fraudulent sites even when they replicate legitimate appearances

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10157280B2System and method for identifying security breach attempts of a website
Publication Date: 2018.12.18 F5 NETWORKS INC
  • US10157280B2 patent drawing
  • US10157280B2 patent drawing
  • US10157280B2 patent drawing

AI summary

The present invention is a method, circuit and system for detecting, reporting and preventing an attempted security breach of a commercial website (for example a banking website), such as identity theft, website duplication (mirroring/Phishing), MITB (man in the browser) attacks, MITM (man in the middle) attacks and so on.