Website Tattler for Phishing Detection and Hindrance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional anti-phishing methods lack the tools to provide organizations with insight and visibility into who, when, and how individuals in an organization are phished, as they rely on human recognition and training, which is insufficient in preventing credential compromise.

Innovation Solution

A method that modifies a target website by adding a tattler, which collects and analyzes website monitoring data to identify and hinder phishing activity, including detecting and classifying potential attack websites and restricting associated activity through takedown operations or authentication services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-phishing approaches are used, then human training and recognition are employed, but they lack visibility and insight into phishing attacks, resulting in insufficient protection

Engineering Contradiction:
Improveprotection effectivenessVSAvoidvisibility into phishing attacks
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements preliminary action by modifying the target website in advance with a tattler component that proactively collects monitoring data. This allows the system to gather intelligence about phishing attempts before they fully execute, enabling early detection and response. The tattler is embedded in the legitimate website code, so it travels with the site and automatically monitors for copies being used in phishing attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a tattler component as a mediator between the target website and the monitoring system. The tattler collects data from the website environment and transmits it to a server for analysis, acting as an intermediary that bridges the gap between the website and the security monitoring infrastructure. This allows indirect observation of phishing activities without directly interfering with normal website operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If human training is used to recognize phishing, then user awareness is improved, but it requires user action and is insufficient without automated detection

Engineering Contradiction:
Improveuser recognition capabilityVSAvoidautomated phishing detection
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The patent implements self-service by enabling the website itself to perform monitoring and detection functions through the embedded tattler. The website automatically collects data about its environment, identifies potential phishing copies, and transmits this information to the monitoring server without requiring user intervention. This automates the detection process while the website serves its own security monitoring needs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses feedback mechanisms by having the tattler continuously monitor the website environment and transmit data back to the server for analysis. The system receives feedback about website copies, traffic patterns, and potential phishing activities, which is then processed to identify phishing attempts. This closed-loop feedback system enables automated detection and response to phishing threats.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If a tattler is added to the target website, then phishing detection capability is improved, but the website modification process becomes more complex

Engineering Contradiction:
Improvephishing detection accuracyVSAvoidwebsite modification process
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the tattler as a multi-functional component that performs multiple security tasks through a single implementation. The tattler simultaneously collects monitoring data, identifies website copies, detects phishing attempts, and transmits information to the server. This consolidates multiple security functions into one component, reducing the overall complexity of the modification process while maintaining comprehensive detection capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11057427B2Method for identifying phishing websites and hindering associated activity
Publication Date: 2021.07.06 CISCO TECHNOLOGY INC
  • US11057427B2 patent drawing
  • US11057427B2 patent drawing
  • US11057427B2 patent drawing

AI summary

Systems and methods for hindering cyber-attacks include: modifying a target website of a remote service provider, wherein modifying the target website includes: reconfiguring a structure of the target website to include a tattler, wherein when the tattler is executed at a non-authorized copy of the target website, the tattler is configured to transmit to a cyber-attack mitigation platform tattler data associated with the non-authorized copy of the target website; receiving the tattler data, wherein the tattler data includes website monitoring data, wherein the website monitoring data comprises a URL of the non-authorized copy of the target website; using the website monitoring data to evaluate the non-authorized copy of the target website, wherein the evaluating includes identifying whether the non-authorized copy of the target website comprises an attack website; and implementing one or more attack mitigation protocols when the non-authorized copy of the target website comprises the attack website.