Website Tattler for Phishing Detection and Hindrance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional anti-phishing methods lack the tools to provide organizations with insight and visibility into who, when, and how individuals in an organization are phished, as they rely on human recognition and training, which is insufficient in preventing credential compromise.
Innovation Solution
A method that modifies a target website by adding a tattler, which collects and analyzes website monitoring data to identify and hinder phishing activity, including detecting and classifying potential attack websites and restricting associated activity through takedown operations or authentication services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional anti-phishing approaches are used, then human training and recognition are employed, but they lack visibility and insight into phishing attacks, resulting in insufficient protection
Solution Approach 1:
The patent implements preliminary action by modifying the target website in advance with a tattler component that proactively collects monitoring data. This allows the system to gather intelligence about phishing attempts before they fully execute, enabling early detection and response. The tattler is embedded in the legitimate website code, so it travels with the site and automatically monitors for copies being used in phishing attacks.
Solution Approach 2:
The patent uses an intermediary approach by introducing a tattler component as a mediator between the target website and the monitoring system. The tattler collects data from the website environment and transmits it to a server for analysis, acting as an intermediary that bridges the gap between the website and the security monitoring infrastructure. This allows indirect observation of phishing activities without directly interfering with normal website operations.
2Ease of operation
If human training is used to recognize phishing, then user awareness is improved, but it requires user action and is insufficient without automated detection
Solution Approach 1:
The patent implements self-service by enabling the website itself to perform monitoring and detection functions through the embedded tattler. The website automatically collects data about its environment, identifies potential phishing copies, and transmits this information to the monitoring server without requiring user intervention. This automates the detection process while the website serves its own security monitoring needs.
Solution Approach 2:
The patent uses feedback mechanisms by having the tattler continuously monitor the website environment and transmit data back to the server for analysis. The system receives feedback about website copies, traffic patterns, and potential phishing activities, which is then processed to identify phishing attempts. This closed-loop feedback system enables automated detection and response to phishing threats.
3Measurement precision
If a tattler is added to the target website, then phishing detection capability is improved, but the website modification process becomes more complex
Solution Approach 1:
The patent applies universality by designing the tattler as a multi-functional component that performs multiple security tasks through a single implementation. The tattler simultaneously collects monitoring data, identifies website copies, detects phishing attempts, and transmits information to the server. This consolidates multiple security functions into one component, reducing the overall complexity of the modification process while maintaining comprehensive detection capabilities.
Data Source
AI summary
Systems and methods for hindering cyber-attacks include: modifying a target website of a remote service provider, wherein modifying the target website includes: reconfiguring a structure of the target website to include a tattler, wherein when the tattler is executed at a non-authorized copy of the target website, the tattler is configured to transmit to a cyber-attack mitigation platform tattler data associated with the non-authorized copy of the target website; receiving the tattler data, wherein the tattler data includes website monitoring data, wherein the website monitoring data comprises a URL of the non-authorized copy of the target website; using the website monitoring data to evaluate the non-authorized copy of the target website, wherein the evaluating includes identifying whether the non-authorized copy of the target website comprises an attack website; and implementing one or more attack mitigation protocols when the non-authorized copy of the target website comprises the attack website.


