Phishing mail processing method, device, equipment and medium

By acquiring email information in real time and using intelligent agents to detect phishing emails, combined with multi-stage response processing, the shortcomings of existing technologies in phishing email detection and handling are solved, achieving efficient identification and risk containment of phishing emails.

CN121077796APending Publication Date: 2025-12-05PING AN TECH (SHENZHEN) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511392681.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2025-12-05

AI Technical Summary

Technical Problem

Existing phishing email detection technologies are ill-equipped to handle complex attack methods and lack comprehensive countermeasures, making it difficult to contain phishing email risks in a timely and effective manner.

Method used

By acquiring email information in real time, extracting key fields for security filtering, using intelligent agents to detect email types, and implementing multi-stage response processing after confirming that it is a phishing email, the attack path is blocked.

Benefits of technology

It improves the reliability of phishing email detection and the comprehensiveness of handling, ensuring timely and effective containment of the risks posed by phishing emails and preventing information leakage and system paralysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121077796A_ABST
    Figure CN121077796A_ABST
Patent Text Reader

Abstract

The invention relates to the field of artificial intelligence, can be applied to business system platforms of finance, medical health and the like, and discloses a phishing mail processing method, device, equipment and medium, and the method comprises the following steps: obtaining mail information of an original mail in real time and extracting key fields in the mail information; according to key fields in the mail information, performing security filtering on all the original mails according to a preset filtering strategy to obtain to-be-detected mails after security filtering; obtaining an original sample of a to-be-detected mail, performing mail type detection on the original sample of the to-be-detected mail through a pre-constructed intelligent agent, and determining whether the to-be-detected mail is a phishing mail; and if yes, performing multi-stage response processing on the phishing mail according to the mail information of the phishing mail and a preset response strategy, and blocking and eliminating an attack path of the phishing mail. The phishing mails are processed through multi-stage response processing after the phishing mails are reliably identified through the intelligent agent, so that the processing completeness is ensured, and the risk caused by the phishing mails is effectively restrained in time.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of artificial intelligence, and in particular to a phishing email processing method, device, equipment and medium. BACKGROUND

[0002] Phishing email is a network attack method based on social engineering, which usually disguises as a credible source of email to induce users to click malicious links, download malicious attachments or leak sensitive information, so as to achieve information theft or malicious program implantation. For example, in the financial field, an attacker may send a mail disguised as a bank customer service to a customer, claiming that there is an abnormal transaction in the customer's account, and the customer needs to click the link in the email and input the account information to verify the identity. If the customer operates according to the instructions in the email, the account information may be stolen by the attacker, thereby affecting the safety of the account funds. For another example, in the medical and health field, an attacker may send an email pretending to be from a cooperative pharmaceutical company to a hospital employee, with a file containing malicious code attached, claiming to be a clinical trial report of a new drug. Once the hospital employee opens the file, the malicious code will spread in the hospital's computer system, which may cause the hospital information system to malfunction.

[0003] In recent years, with the rapid development of Internet technology, the attack means of phishing emails has become more covert, such as AI-generated phishing emails with more realistic professional language and format to bypass traditional protection mechanisms, resulting in a continuous increase in the number of phishing emails, so it is particularly important to protect against phishing emails. However, existing phishing email detection techniques mainly rely on feature matching and rule engines, which are difficult to cope with increasingly complex attack methods, and lack of perfect disposal for detected phishing emails, resulting in difficulty in timely and effective containment of the risks brought by phishing emails when facing phishing attacks. SUMMARY

[0004] In view of the deficiencies of the prior art described above, the purpose of the present application is to provide a phishing email processing method, device, equipment and medium applicable to the financial field, medical field or other related fields, the main purpose of which is to improve the detection reliability of phishing emails and the disposal perfection of phishing emails, to ensure timely and effective containment of the risks brought by phishing emails.

[0005] The technical solutions of the present application are as follows: The present application provides a phishing email processing method in a first aspect, comprising: real-time acquisition of email information of an original email, and extraction of key fields in the email information; According to the key fields in the email information, all original emails are subjected to security filtering according to a preset filtering strategy, to obtain a security-filtered email to be detected; An original sample of the to-be-detected email is acquired, an agent is used to detect the type of the original sample of the to-be-detected email, and it is determined whether the to-be-detected email is a phishing email. If the to-be-detected email is determined to be a phishing email, a multi-stage response process is performed on the phishing email according to the email information of the phishing email and a preset response strategy, and the attack path of the phishing email is blocked and eliminated.

[0006] The second aspect of the present application provides a phishing email processing device, comprising: An information acquisition module is configured to acquire email information of an original email in real time and extract a key field in the email information. A security filtering module is configured to perform security filtering on all original emails according to the key field in the email information and a preset filtering strategy, and obtain to-be-detected emails after security filtering. An agent detection module is configured to acquire an original sample of the to-be-detected email, and use an agent to detect the type of the original sample of the to-be-detected email, and determine whether the to-be-detected email is a phishing email. A multi-stage response module is configured to perform a multi-stage response process on the phishing email according to the email information of the phishing email and a preset response strategy if the to-be-detected email is determined to be a phishing email, and block and eliminate the attack path of the phishing email.

[0007] The third aspect of the present application provides a computer device, comprising at least one processor, and A memory connected in communication with the at least one processor; wherein The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the phishing email processing method.

[0008] The fourth aspect of the present application provides a non-volatile computer readable storage medium, which stores computer executable instructions, and the computer executable instructions are executed by one or more processors to enable the one or more processors to perform the phishing email processing method.

[0009] Beneficial effects: The application discloses a phishing email processing method, device, equipment and medium, compared with the prior art, the embodiment of the application acquires the email information of the original email in real time, and extracts the key field in the email information; according to the key field in the email information, all original emails are safely filtered according to a preset filtering strategy, and the detected email after safety filtering is obtained; the original sample of the detected email is acquired, the original sample of the detected email is detected by the intelligent agent constructed in advance, whether the detected email is a phishing email is confirmed; if it is confirmed that it is a phishing email, the phishing email is processed by a multi-stage response according to the email information of the phishing email according to a preset response strategy, and the attack path of the phishing email is blocked and eliminated. Through the safety filtering of the real-time acquired email, the semantic understanding ability of the intelligent agent is used for accurate email type detection of the detected email, the phishing email is reliably identified, and the phishing email is processed through multi-stage response processing, so that the perfection of the disposal is ensured, and the risk caused by the phishing email is effectively curbed in time. BRIEF DESCRIPTION OF DRAWINGS

[0010] In order to more clearly illustrate the scheme in the application, the drawings needed in the description of the embodiments of the application will be briefly introduced below. Obviously, the drawings in the following description are some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0011] Figure 1 An application environment schematic diagram of the phishing email processing method provided by the embodiment of the application is shown in the figure. Figure 2 A flowchart of the phishing email processing method provided by the embodiment of the application is shown in the figure. Figure 3 A functional module schematic diagram of the phishing email processing device provided by the embodiment of the application is shown in the figure. Figure 4 A hardware structure schematic diagram of the computer equipment provided by the embodiment of the application is shown in the figure. DETAILED DESCRIPTION

[0012] In order to make the purpose, technical scheme and effect of the application more clear and definite, the application will be further described in detail below. It should be understood that the specific embodiments described herein are only used to explain the application, and are not used to limit the application. The embodiments of the application are introduced below with reference to the drawings.

[0013] The phishing email processing method provided by the embodiment of the application can be applied to, for example Figure 1The application environment of the present application includes a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 is a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 can include various connection types, such as wired and / or wireless communication links, etc.

[0014] A user can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as knowledge reading applications, web browser applications, search applications, instant messaging tools, email clients, and / or social platform software, etc. (only as an example).

[0015] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with a display screen and supporting web browsing, including but not limited to smartphones, tablet computers, laptop computers, desktop computers, etc.

[0016] The server 105 can be a server providing various services, such as a background server providing support for content browsed by a user using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (only as an example). The background server can analyze and process received user requests and other data, and feed back the processing results (such as web pages, information, or data, etc. obtained or generated according to user requests) to the terminal device. The server 105 can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of large management difficulty and weak business scalability in traditional physical hosts and VPS services (Virtual Private Server, or simply VPS). The server 105 can also be a server of a distributed system, or a server combined with a blockchain.

[0017] It should be noted that the phishing email processing method provided by the embodiments of the present application can generally be executed by the first terminal device 101, the second terminal device 102, or the third terminal device 103. Correspondingly, the phishing email processing device provided by the embodiments of the present application can also be arranged in the first terminal device 101, the second terminal device 102, or the third terminal device 103. Alternatively, the phishing email processing method provided by the embodiments of the present application can generally be executed by the server 105. Correspondingly, the phishing email processing device provided by the embodiments of the present application can generally be arranged in the server 105.

[0018] It should be understood that the number of terminal devices, networks and servers above is only illustrative. Any number of terminal devices, networks and servers can be provided according to implementation needs.

[0019] As shown in Figure 2 The phishing email processing method provided by the embodiment of the present application specifically includes the following steps: S201, real-time acquisition of mail information of the original mail, and extraction of key fields in the mail information.

[0020] In this embodiment, the mail information of the original mail is acquired in real time from the mail gateway system through an automated orchestration tool, for example, using mail gateway devices or services. These devices or services can monitor mail traffic in real time and perform preprocessing and analysis before the mail arrives at the mail server. Alternatively, a connection is established with the mail server using a mail protocol (such as IMAP, POP3, SMTP), and the mail inbox is monitored in real time. When a new mail arrives, the mail information of the mail is acquired through the mail protocol, including the mail header and the mail body, etc.

[0021] The key fields of the original mail are extracted from the mail information, for example, the mail content can be parsed through a mail parsing library (such as the email library of Python, etc.), and the key fields including the receiving time, the sender, the subject, the attachment, the URL, the body, etc. are extracted. By acquiring the mail information in real time, it is ensured that potential phishing emails can be discovered in time, and the key fields therein are extracted, providing necessary data basis for subsequent filtering and detection For example, in the financial field, the customer service department of a bank monitors customer inquiry mails in real time, extracts key information to quickly respond to customer needs, and prevents phishing email attacks. In the medical and health field, the information system of a hospital acquires the communication mails between doctors and patients in real time, extracts key information to timely handle medical consultations, and prevents phishing email attacks from causing patient information leakage.

[0022] S202, according to the key fields in the mail information, performing security filtering on all original mails according to a preset filtering strategy, to obtain the security filtered mail to be detected.

[0023] In this embodiment, before performing the phishing email detection and disposal, all original emails are subjected to security filtering. A filtering strategy is preset, such as a whitelist mechanism, keyword filtering, email format checking, etc. All original emails are subjected to security filtering according to the preset filtering strategy. Emails meeting the security standards are marked as secure emails and enter a normal processing flow, i.e. no subsequent phishing email detection is needed to save data processing amount. Emails not meeting the security standards are marked as emails to be detected and enter the next step of detection. By quickly filtering out a large number of known secure emails, the load of subsequent detection is reduced to improve detection efficiency and reduce false positive rate.

[0024] For example, in the financial field, the internal email system of a financial institution can use a whitelist mechanism to ensure the safety of email communication between employees and trusted business partners, while also strictly filtering emails from the outside to prevent phishing email attacks. In the medical and health field, the email system of a hospital uses a whitelist, email content features, etc. to perform security filtering on real-time received original emails, filters out secure emails between hospital employees and secure emails not containing potential risks (such as pure text emails), and improves the detection and processing efficiency of phishing emails.

[0025] S203, acquire the original sample of the email to be detected, and perform email type detection on the original sample of the email to be detected by the pre-constructed agent to confirm whether the email to be detected is a phishing email.

[0026] In this embodiment, for the remaining emails to be detected after security filtering, the complete original sample of the email to be detected is downloaded from the email server, including the email header, body, attachment, etc. The original sample is stored in a secure temporary storage area for further analysis. When performing email detection, the original sample is input into the pre-constructed agent, which is a detection model constructed based on artificial intelligence technology and can automatically learn and identify the features of phishing emails. By analyzing and analyzing the original sample, the email content including URL, attachment MD5, X-Mailer, subject, body, etc. is subjected to semantic analysis and feature extraction, and then matched with the features of known phishing emails, thereby comprehensively and accurately confirming whether the email to be detected is a phishing email or other suspicious emails, etc.

[0027] Further, if the detection result is a normal email, the original sample can be deleted to avoid occupying storage space, and the email is normally delivered to the recipient address to ensure the normal flow of the email. If the detection result is a phishing email or other suspicious email, etc. non-normal email, the email is subjected to subsequent processing to prevent the spread of security threats. Through the automatic detection of the agent, phishing emails can be quickly and accurately identified to improve the detection accuracy of phishing emails.

[0028] For example, in the financial field, various external marketing emails are often received, but among them may be phishing emails, which induce users to open by attaching a marketing brochure file with malicious code in the attachment. The mail system of the financial institution uses an agent to detect all emails to be detected to detect whether there is a phishing email, ensuring the security of financial information.

[0029] In the medical health field, hospital employees receive a large number of emails from external mailboxes related to medical device procurement, academic exchanges, etc., but among them may contain phishing emails that induce employees to click malicious links, etc., resulting in attacks on medical device systems or patient information leaks. By using an agent to detect phishing emails, malicious emails disguised as medical device suppliers or partner hospitals can be accurately identified to prevent patient information leaks.

[0030] S204, if the phishing email is confirmed, a multi-stage response process is performed on the phishing email according to the email information of the phishing email according to a pre-set response strategy, and the attack path of the phishing email is blocked and eliminated.

[0031] In this embodiment, for the phishing email detected and confirmed by the agent, an automatic emergency response process for phishing emails is started, i.e. an automatic response process is started according to the email information of the phishing email, and a pre-set response strategy is executed. The pre-set response strategy includes a multi-stage response processing method, including blocking malicious links, deleting phishing emails, optimizing email filtering rules, isolating affected users, tracing attack sources, continuous monitoring, etc. Through multi-stage response processing, the attack path of the phishing email is completely blocked and eliminated to prevent secondary attacks and effectively contain the risks brought by phishing emails.

[0032] For example, in the financial field, after detecting a phishing email, the financial institution can perform multi-stage response processing, such as automatically blocking malicious links, deleting phishing emails, and optimizing email filtering rules to prevent similar attacks from occurring again, while isolating and further checking affected users to block and eliminate the attack path of the phishing email and ensure customer fund security.

[0033] In the medical health field, after detecting a phishing email, the hospital mail system can perform multi-stage response processing such as automatically deleting the email, blocking malicious links, and isolating and checking affected medical devices and systems to block and eliminate the attack path of the phishing email and prevent patient information leaks and malicious control of medical devices.

[0034] In the above embodiment, the application discloses a phishing email processing method, which comprises the following steps: acquiring email information of an original email in real time, and extracting key fields in the email information; performing security filtering on all original emails according to the key fields in the email information according to a preset filtering strategy, to obtain a to-be-detected email after security filtering; acquiring an original sample of the to-be-detected email, performing email type detection on the original sample of the to-be-detected email by an agent constructed in advance, and confirming whether the to-be-detected email is a phishing email; if the to-be-detected email is confirmed to be a phishing email, performing multi-stage response processing on the phishing email according to the email information of the phishing email according to a preset response strategy, and blocking and eliminating an attack path of the phishing email. After security filtering on the email acquired in real time, accurate email type detection is performed on the to-be-detected email based on the semantic understanding ability of the agent, the phishing email is reliably identified, and the phishing email is processed through multi-stage response processing, so that the perfection of the processing is ensured, and the risk caused by the phishing email is effectively curbed in a timely and effective manner.

[0035] In one embodiment, after step S202, the method further comprises: performing hash calculation according to the email information of the to-be-detected email; confirming a duplicate email in the to-be-detected email according to the hash calculation result, and performing deduplication processing on the duplicate email to obtain a deduplicated to-be-detected email; if the deduplicated to-be-detected email is confirmed to be a phishing email, the method further comprises: confirming an email identical to the phishing email in the deduplicated email according to historical data of the deduplication processing; marking the deduplicated email identical to the phishing email as a phishing email, and performing multi-stage response processing according to a preset response strategy.

[0036] In this embodiment, before all original emails are transmitted to the agent for email detection after security filtering, the to-be-detected email is also subjected to deduplication processing, so as to reduce the data amount of email detection and improve the detection efficiency. Specifically, hash calculation is performed on the email information of the to-be-detected email, including the email subject, the content of the email body, the name of the attachment, and the like, for example, the hash calculation is performed on these information by using a hash algorithm (such as SHA-256), to generate a unique hash value stored in a database for subsequent deduplication processing, that is, the output result of the hash algorithm has uniqueness and can be used to identify the uniqueness of the email, and the unique identification of the email can be quickly generated through hash calculation, thereby providing a basis for subsequent deduplication processing.

[0037] According to the hash calculation result, the duplicate mails in the to-be-detected mails are confirmed, that is, the hash values of the to-be-detected mails are compared with each other, if the same hash value is found, the duplicate mail is confirmed, the duplicate mail is de-duplicated, only one copy is kept for subsequent detection, thereby effectively reducing the detection of duplicate mails, improving the detection efficiency, reducing the system load, saving the storage space and computing resources.

[0038] Further, in the subsequent detection step, if the de-duplicated to-be-detected mail is confirmed as a phishing mail, the database is queried based on the de-duplicated historical data to find the mail record with the same hash value as the phishing mail, the same mail as the phishing mail is confirmed in the de-duplicated mail through the hash value comparison, and the mail is marked as a phishing mail, so that the phishing mail in the de-duplicated mail is subjected to the multi-stage response processing according to the budget response strategy. According to the detection result of the phishing mail after de-duplication, the hash value of the de-duplicated mail is matched, so that all phishing mails with the same content are marked and processed, the omission is avoided, the detection efficiency is improved, and the comprehensiveness of detection and subsequent response processing is ensured, and the phishing attack is minimized.

[0039] In one embodiment, step S202 includes: According to the key field in the mail information, the sender mailbox of all original mails and the existence state of the specified mail content are confirmed; A preset sender white list is obtained, the sender mailbox of the original mail is matched with the sender white list, the original mail with a successful match is subjected to initial security filtering, and initial filtered mails are obtained; According to the existence state of the specified mail content in the initial filtered mail, the initial filtered mail without the specified mail content is subjected to secondary security filtering, and the to-be-detected mail after security filtering is obtained.

[0040] In this embodiment, when all original mails are subjected to security filtering, first, according to the key field in the mail information, the existence state of the sender mailbox and the specified mail content is confirmed. Specifically, the original mail can be parsed by a mail parsing library, the sender mailbox address in the mail header is extracted, and it is checked whether the specified mail content exists in the mail. The specified mail content refers to specific content that may be contained in the mail, such as attachments, URLs, etc. These mail contents are contents that are easy to hide phishing codes, and if these contents exist, it may indicate that the mail has security risks.

[0041] Load preset sender whitelist from database or configuration file, the whitelist contains known safe sender mailbox address, match the original mail sender mailbox with the whitelist, check if it is in the whitelist, if the sender mailbox is in the whitelist, mark the mail as a safe mail, if the sender mailbox is not in the whitelist, it is classified as an initial filtering mail for subsequent detection. By whitelist screening, known safe mails can be quickly screened out, reducing the load of subsequent detection.

[0042] Further check the initial filtering mail to confirm whether there is specified mail content (such as malicious link, attachment, etc.) in the mail, if there is no specified mail content in the initial filtering mail, mark the mail as a safe mail and enter the normal delivery process; if there is specified mail content in the initial filtering mail, mark the mail as a to-be-detected mail and enter the subsequent detection process. By checking the existence of specified mail content through secondary security filtering, safe mails are further screened out to improve phishing mail detection efficiency and accuracy, and false positives are reduced.

[0043] In one embodiment, step S203 includes: Obtain the original sample of the to-be-detected mail and analyze and feature engineer the original sample through the pre-constructed agent, and extract multiple key mail features of the original sample; Calculate the similarity of the multiple key mail features with the features of known phishing mails in the preset label library to obtain the similarity of each key mail feature; According to the similarity of each key mail feature, weighted sum is performed to obtain the total similarity; If the total similarity is greater than or equal to the similarity threshold, the preset label library is hit, and it is confirmed that the to-be-detected mail is a phishing mail; If the total similarity is less than the similarity threshold, continue to identify the to-be-detected mail as an advertising marketing mail or a suspicious mail.

[0044] In this embodiment, the original sample of the to-be-detected mail is obtained and the agent analyzes and features the mail sample in depth. Specifically, the key content of the mail such as the sender mailbox, the mail subject, the text content, the attachment name, the URL link, etc. can be analyzed. The text content is preprocessed, including word segmentation, stop word removal, stem extraction, etc. Then the text content is converted into numerical features, and the subject features and text features of the original sample are obtained. The MD5 of the attachment is calculated to obtain the attachment features of the original sample. The technical information in the mail header such as X-Mailer is extracted to obtain the X-Mailer features of the original sample, and so on. Thus, multiple key features of the mail can be extracted, providing rich data for subsequent similarity calculation.

[0045] In the detection of whether it is a phishing email, a preset label library containing features of known phishing emails is loaded from the database. For each key email feature, the similarity between it and the corresponding feature in the label library is calculated. Specifically, cosine similarity, edit distance, Hamming distance, etc. can be used to calculate the similarity between each key email feature and the corresponding known feature in the label library. At the same time, according to the importance of each key email feature, different weights are assigned, for example, the weight of the email subject is 0.3, the weight of the attachment hash value is 0.4, and the weight of the text content is 0.3, etc. The specific weight can be adjusted according to the number and importance of the features. Based on the similarity of each key email feature and its weight, a comprehensive similarity score, i.e. the total similarity, is obtained. Through the similarity calculation of multiple features, the features of the email to be detected and the features of the known phishing email can be compared comprehensively and accurately, and the similarity of multiple features is considered comprehensively through weighted summation to obtain a more comprehensive evaluation result, thereby effectively identifying emails similar to known phishing emails and improving the accuracy of detection.

[0046] According to actual needs and experience, a similarity threshold is set, for example, 0.8, etc. If the total similarity is greater than or equal to the similarity threshold, it is confirmed that the email is a phishing email that hits the label library, the email is marked as a phishing email, and subsequent response processing is started in time to prevent the spread of security threats. If it is less than the similarity threshold, it means that the email does not hit the label library and is not a phishing email, but may be other types of emails, such as advertising marketing or other suspicious emails, etc. Therefore, the classification of the email to be detected is continued to identify it as an advertising marketing email or a suspicious email for targeted processing to improve the refinement of email processing.

[0047] In one embodiment, the continuing to identify the email to be detected as an advertising marketing email or a suspicious email includes: identifying whether the email to be detected is an advertising marketing email through a pre-trained classifier for advertising marketing email identification; detecting the credibility of the sender and URL of the email to be detected and analyzing the intent of the email text to obtain a corresponding credibility score and intent score; identifying whether the email to be detected is a suspicious email according to the credibility score and the intent score.

[0048] In this embodiment, when further classification detection is performed on the remaining to-be-detected emails that do not hit the tag library, the extracted key email features (such as email subject, body content, attachment type, etc.) are input into a pre-trained classifier (such as a Naive Bayes classifier, a random forest classifier, a deep learning model, etc.) for advertising marketing email identification. That is, the classifier learns and trains the features of the advertising marketing email by using a large number of advertising marketing email templates as training data. For unknown email features input, the classifier can calculate the probability that the email content belongs to an advertising marketing email according to the input features. If the probability is higher than a certain threshold (such as 0.9), the email is considered to be an advertising marketing email. Through the pre-trained classifier, advertising marketing emails can be quickly and accurately identified.

[0049] For the remaining to-be-detected emails that are not advertising marketing, the sender and URL are subjected to credibility detection. Specifically, SPF (Sender Policy Framework) verification can be used to detect whether the sender of the email is fake. That is, the IP address of the sender and the domain name of the sender's mailbox are obtained. The SPF record is a record set by the domain name owner in the DNS, which specifies which IP addresses can send emails of the domain name. Based on the matching verification between the IP address of the sender and the domain name of the sender's mailbox and the SPF record, it is determined whether the sender is credible. At the same time, the URL in the email is detected by a URL reputation evaluation system (such as Google Safe Browsing API) to determine whether the URL points to a known malicious website. Based on the credibility results of the sender and the URL, a quantitative credibility score is converted.

[0050] In addition, the email body is subjected to intent analysis, that is, the natural language processing (NLP) technology is used to analyze the intent of the email body to determine whether the intent of the email is malicious (such as inducing users to click links, providing personal information, etc.), so as to obtain a quantitative intent score.

[0051] The credibility score and the intent score are used to comprehensively determine whether the to-be-detected email is a suspicious email. For example, according to actual needs, a sender credibility score threshold and an intent score threshold are set. If the credibility score of the sender is lower than the set threshold and the intent score of the email body is higher than the set threshold, the email is determined to be a suspicious email. The suspicious email is marked as a email that needs to be further processed, and enters the subsequent multi-stage response processing. Through classifier identification, credibility detection, and intent analysis, advertising marketing emails and suspicious emails can be accurately distinguished, and the degree of refinement and security of email processing can be improved.

[0052] In one embodiment, step S204 includes: If the phishing email is confirmed, a response process in a containment stage is performed according to the mail information of the phishing email to block the attack path of the phishing email; A response process in a tracing stage is performed on the phishing email that has undergone the containment process to obtain the source information and predicted attack path of the phishing email; A response process in a tracking stage is performed on the phishing email that has undergone the tracing process, and continuous attack monitoring is performed according to the source information and predicted attack path to eliminate the attack path of the phishing email in a future time period.

[0053] In this embodiment, after the phishing email is confirmed, an automatic emergency response process for the phishing email is started to perform multi-stage response processing on the phishing email, specifically including a containment stage, a tracing stage, and a tracking stage. Targeted processing is performed in each stage to block and eliminate the attack path of the phishing email and eliminate the attack impact. Among them, the response process in the containment stage is performed according to the mail information of the phishing email to block the attack path of the phishing email, that is, the response process in the containment stage includes blocking malicious links (shielding malicious links in the phishing email on the Internet gateway), deleting the phishing email (batch deleting the delivered phishing email in the mail system), optimizing the mail filtering rule (optimizing the filtering rule of the mail sandbox to prevent similar emails from being delivered again), and operating user isolation (office account ban, user server isolation, further investigation) nodes to ensure containment of the successfully delivered emails.

[0054] Then, the response process in the tracing stage is performed on the phishing email that has undergone the containment process to obtain the source information and predicted attack path of the phishing email, that is, the response process in the tracing stage includes sender IP tracking (analyzing mail header information, tracking the IP address and source of the sender), phishing website tracing (tracking the website pointed by the phishing link and the operator information thereof), and sample analysis (analyzing the delivery mode of the phishing email and the possible attack path in the future) nodes to effectively trace and prevent further attacks.

[0055] After the phishing email that has undergone the traceability processing, the response processing in the tracking stage is performed, the attack monitoring is continuously performed according to the source information and the predicted attack path, and the attack path of the phishing email in the future time period is eliminated. That is, the response processing in the tracking stage includes the system monitoring (continuously monitoring the mail system to ensure that the phishing email does not appear again), the user feedback collection (collecting user feedback to confirm that the influence of the phishing email is completely eliminated), the user reporting channel promotion (promoting a one-key reporting channel to speed up the emergency disposal timeliness), the security promotion and the phishing drill (periodically carrying out user security education to improve the awareness of preventing phishing emails; arranging a planned phishing drill to strengthen the user's prevention ability) nodes, so as to continuously perform the attack monitoring and the user feedback collection, investigate the influence range, and well promote the phishing, eliminate the attack path of the phishing email in the future time period, and ensure that the influence of the phishing attack is eliminated.

[0056] In one embodiment, before the response processing in the containment stage according to the mail information of the phishing email to block the attack path of the phishing email, the method further includes: generating an artificial review request according to the mail information of the phishing email and sending the artificial review request to a specified security user; obtaining a review result of the artificial review of the phishing email by the specified security user, and filtering out the mail with a normal review result.

[0057] In this embodiment, to ensure the accuracy of the phishing email disposal, an artificial review process is added before the multi-stage response processing to avoid false detection. Specifically, an artificial analysis node can be added, an artificial review request is generated according to the key information (such as the mail subject, the content of the body, the attachment, the sender mailbox, etc.) of the phishing email, and the artificial review request is sent to a specified security user, for example, a security expert with corresponding authority and ability is selected from a security team as the specified security user, so that the security expert with the review authority and the ability artificially reviews the mail. In specific implementation, the review request is sent to the specified security user using a secure communication channel (such as an internal security management system, an encrypted mail, etc.), to ensure that the transmission process of the review request is safe and reliable, and to prevent information leakage.

[0058] After the specified security user completes the artificial review, the review result is fed back to the system through the secure communication channel. If the review result is "normal", the mail is removed from the phishing email list to avoid false processing. If the review result is "phishing email", the subsequent response processing in the containment stage is continued. Through the artificial review process, only the real phishing email enters the subsequent processing flow, false positives are reduced, and the efficiency and reliability of the entire response process are improved.

[0059] It should be noted that the above steps do not necessarily have a certain order, and those skilled in the art can understand from the description of the embodiments of the present application that the above steps can have different execution orders in different embodiments, that is, they can be executed in parallel, or they can be executed in exchange, etc.

[0060] Further referring to Figure 3 , as an implementation of the method shown above Figure 2 , the present application provides an embodiment of a phishing email processing device, which corresponds to the method embodiment shown in Figure 2 , and the device can be applied to various electronic devices.

[0061] As shown in Figure 3 , the phishing email processing device 30 described in the embodiment comprises: an information acquisition module 301, configured to acquire email information of original emails in real time, and extract key fields in the email information; a security filtering module 302, configured to perform security filtering on all original emails according to the key fields in the email information according to a preset filtering strategy, to obtain detected emails after security filtering; an agent detection module 303, configured to acquire original samples of the detected emails, perform email type detection on the original samples of the detected emails through a pre-constructed agent, and confirm whether the detected emails are phishing emails; a multi-stage response module 304, configured to, if the detected emails are confirmed to be phishing emails, perform multi-stage response processing on the phishing emails according to a preset response strategy according to the email information of the phishing emails, to block and eliminate the attack path of the phishing emails.

[0062] The module referred to in the present application refers to a series of computer program instruction segments capable of completing a specific function, and is more suitable for describing the phishing email processing execution process than the program. The specific implementation of each module is described in the above method embodiment, which will not be described here.

[0063] In one embodiment, the device further comprises: a hash calculation module, configured to perform hash calculation according to the email information of the detected emails; a deduplication module, configured to confirm repeated emails in the detected emails according to the hash calculation result, and perform deduplication processing on the repeated emails to obtain deduplicated detected emails; a repeated email confirmation module, configured to confirm emails identical to the phishing emails in the deduplicated emails according to historical data of the deduplication processing; a marking module, configured to mark the deduplicated emails identical to the phishing emails as phishing emails, and perform multi-stage response processing according to a preset response strategy.

[0064] In one embodiment, the security filtering module 302 comprises: An information confirmation unit is configured to confirm the existence of the sender mailbox of all original emails and the specified email content according to the key field in the email information; A whitelist filtering unit is configured to obtain a preset sender whitelist, match the sender mailbox of the original email with the sender whitelist, and perform initial security filtering on the original email with a successful match to obtain an initial filtering email; A content filtering unit is configured to perform secondary security filtering on the initial filtering email without the specified email content according to the existence of the specified email content in the initial filtering email to obtain a security filtered email to be detected.

[0065] In one embodiment, the intelligent agent detection module 303 comprises: An analysis and feature extraction unit is configured to obtain an original sample of the email to be detected and perform analysis and feature engineering processing on the original sample through a pre-constructed intelligent agent to extract multiple key email features of the original sample; A label matching unit is configured to perform similarity calculation on the multiple key email features and the features of known phishing emails in a preset label library to obtain the similarity of each key email feature; A summation unit is configured to perform weighted summation on the similarity of each key email feature to obtain a total similarity; A label hit determination unit is configured to hit the preset label library if the total similarity is greater than or equal to a similarity threshold, confirming that the email to be detected is a phishing email, and continue to identify the email to be detected as an advertising marketing email or a suspicious email if the total similarity is less than the similarity threshold.

[0066] In one embodiment, the intelligent agent detection module 303 further comprises: A marketing classification unit is configured to perform advertising marketing email identification on the key email features through a pre-trained classifier to confirm whether the email to be detected is an advertising marketing email; A credibility and intent analysis unit is configured to perform credibility detection on the sender and URL of the email to be detected and intent analysis on the email body to obtain a corresponding credibility score and intent score; A suspicious email detection unit is configured to confirm whether the email to be detected is a suspicious email according to the credibility score and intent score.

[0067] In one embodiment, the multi-stage response module 304 comprises: The containment response unit is configured to, if the phishing email is confirmed, perform response processing in a containment stage according to mail information of the phishing email, and block an attack path of the phishing email. The tracing response unit is configured to, for the phishing email that has undergone the tracing processing, perform response processing in a tracing stage, and perform continuous attack monitoring according to the source information and the predicted attack path, so as to eliminate the attack path of the phishing email in a future time period. The tracing response unit is configured to, for the phishing email that has undergone the tracing processing, perform response processing in a tracing stage, and perform continuous attack monitoring according to the source information and the predicted attack path, so as to eliminate the attack path of the phishing email in a future time period.

[0068] In one embodiment, the multi-stage response module 304 further includes: The review request unit is configured to generate an artificial review request according to the mail information of the phishing email, and send the artificial review request to a designated security user. The review filtering unit is configured to obtain a review result of the phishing email after the artificial review by the designated security user, and filter out a mail with a normal review result.

[0069] In the above embodiment, the application discloses a phishing email processing device, which acquires mail information of an original email in real time, extracts key fields in the mail information, performs security filtering on all original emails according to the key fields in the mail information according to a preset filtering strategy, obtains an original sample of a to-be-detected email, performs mail type detection on the original sample of the to-be-detected email by an agent constructed in advance, confirms whether the to-be-detected email is a phishing email, performs multi-stage response processing on the phishing email according to a preset response strategy if the to-be-detected email is confirmed to be a phishing email, and blocks and eliminates an attack path of the phishing email. The to-be-detected email is accurately detected by the semantic understanding ability of the agent based on the security filtering of the real-time acquired mail, the phishing email is reliably identified, and the phishing email is processed by the multi-stage response processing, so that the perfection of the disposal is ensured, and the risk caused by the phishing email is timely and effectively contained.

[0070] Another embodiment of the application provides a computer device, as shown in the accompanying drawings. Figure 4 As shown in the accompanying drawings, the computer device 40 includes: One or more processors 401 and a memory 402, Figure 4 In an embodiment, the processor 401 and the memory 402 are connected through a bus or other means, Figure 4 In an embodiment, the connection is through a bus.

[0071] The processor 401 is configured to implement various control logic of the computer device 40, and can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), a single-chip computer, an ARM (Acorn RISC Machine), or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination of these components. In addition, the processor 401 can also be any conventional processor, microprocessor, or state machine. The processor 401 can also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, and / or any other such configuration.

[0072] The memory 402 is a non-volatile computer-readable storage medium configured to store non-volatile software programs, non-volatile computer-executable instructions, and modules, such as program instructions corresponding to the phishing email processing method in the embodiments of the present application. The processor 401 executes various functional applications and data processing of the computer device 40 by running the non-volatile software programs, instructions, and units stored in the memory 402, i.e., implements the phishing email processing method in the above method embodiments.

[0073] The memory 402 can include a program storage area and a data storage area, wherein the program storage area can store an operating system and at least one application required by a function; and the data storage area can store data created by the computer device 40, etc. In addition, the memory 402 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state memory device. In some embodiments, the memory 402 can optionally include a memory remotely disposed relative to the processor 401, and these remote memories can be connected to the computer device 40 through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof. One or more units are stored in the memory 402, and when executed by the one or more processors 401, perform the steps of the phishing email processing method in any of the above method embodiments.

[0074] In the above embodiment, the application discloses a computer device, by acquiring the mail information of the original mail in real time, and extracting the key field in the mail information; according to the key field in the mail information, all original mails are filtered according to the preset filtering strategy, and the detected mail after safety filtering is obtained; the original sample of the detected mail is obtained, the original sample of the detected mail is detected by the agent constructed in advance, and whether the detected mail is a phishing mail is confirmed; if it is confirmed that it is a phishing mail, the phishing mail is processed according to the preset response strategy according to the mail information of the phishing mail, and the attack path of the phishing mail is blocked and eliminated. Through the safety filtering of the real-time acquired mail, the semantic understanding ability of the agent is used for accurate mail type detection of the detected mail, the phishing mail is reliably identified, and the phishing mail is processed through multi-stage response processing, so that the perfection of disposal is ensured, and the risk brought by the phishing mail is effectively curbed in time.

[0075] The embodiment of the application provides a nonvolatile computer readable storage medium, and the computer readable storage medium stores computer executable instructions, and when the computer executable instructions are executed by one or more processors, the steps of the phishing mail processing method in any method embodiment are executed.

[0076] In the above embodiment, the application discloses a nonvolatile computer readable storage medium, by acquiring the mail information of the original mail in real time, and extracting the key field in the mail information; according to the key field in the mail information, all original mails are filtered according to the preset filtering strategy, and the detected mail after safety filtering is obtained; the original sample of the detected mail is obtained, the original sample of the detected mail is detected by the agent constructed in advance, and whether the detected mail is a phishing mail is confirmed; if it is confirmed that it is a phishing mail, the phishing mail is processed according to the preset response strategy according to the mail information of the phishing mail, and the attack path of the phishing mail is blocked and eliminated. Through the safety filtering of the real-time acquired mail, the semantic understanding ability of the agent is used for accurate mail type detection of the detected mail, the phishing mail is reliably identified, and the phishing mail is processed through multi-stage response processing, so that the perfection of disposal is ensured, and the risk brought by the phishing mail is effectively curbed in time.

[0077] Those skilled in the art can clearly understand from the description of the above embodiments that the above-mentioned example method can be realized by means of software and a necessary general hardware platform, and of course, it can also be realized by hardware, but in many cases, the former is a better implementation. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a plurality of instructions for causing an end device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the method described in each embodiment of the present application.

[0078] The application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld devices or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. The application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The application can also be practiced in a distributed computing environment, in which tasks are performed by remote processing devices connected by a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.

[0079] In summary, the fishing email processing method, device, equipment and medium disclosed by the application, the method comprises: acquiring the email information of the original email in real time, and extracting the key field in the email information; according to the key field in the email information, all original emails are filtered according to the preset filtering strategy, and the detected email after safety filtering is obtained; the original sample of the detected email is obtained, the original sample of the detected email is detected by the intelligent agent constructed in advance, and it is confirmed whether the detected email is a phishing email; if it is confirmed as a phishing email, the phishing email is processed according to the preset response strategy according to the email information of the phishing email, the attack path of the phishing email is blocked and eliminated. Through the safety filtering of the real-time acquired email, the semantic understanding ability of the intelligent agent is used for accurate email type detection of the detected email, the phishing email is reliably identified, and the phishing email is processed through multi-stage response processing, so that the perfection of the disposal is ensured, and the risk brought by the phishing email is effectively curbed in time.

[0080] Of course, those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing relevant hardware (such as a processor, a controller, etc.) through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and the computer program can include the processes of the above-mentioned method embodiments when executed. The storage medium can be a memory, a disk, a floppy disk, a flash memory, an optical storage, etc.

[0081] It should be noted that if a software tool or component of a company other than the company appears in the embodiments of the present application, it is only used for example introduction and does not represent actual use. It should be understood that the application of the present application is not limited to the above examples, and those skilled in the art can improve or transform according to the above description, and all these improvements and transformations should belong to the protection scope of the claims of the present application.

Claims

1. A method of processing a phishing email, characterized by, The method comprises the following steps: real-time acquisition of mail information of original mails, and extraction of key fields in the mail information; safety filtering of all original mails according to the key fields in the mail information according to a preset filtering strategy, to obtain detected mails after safety filtering; acquisition of original samples of the detected mails, mail type detection of the original samples of the detected mails by an agent constructed in advance, and confirmation of whether the detected mails are phishing mails; if the detected mails are confirmed to be phishing mails, multi-stage response processing of the phishing mails according to a preset response strategy according to mail information of the phishing mails, to block and eliminate attack paths of the phishing mails.

2. The phishing email processing method of claim 1, wherein, After the safety filtering of all original mails according to the key fields in the mail information according to the preset filtering strategy, to obtain the detected mails after safety filtering, the method further comprises the following steps: hash calculation according to mail information of the detected mails; confirmation of repeated mails in the detected mails according to the hash calculation result, and de-duplication processing of the repeated mails, to obtain the detected mails after de-duplication; if the detected mails after de-duplication are confirmed to be phishing mails, the method further comprises the following steps: confirmation of mails identical to the phishing mails in the mails after de-duplication according to historical data of the de-duplication processing; labeling of the mails identical to the phishing mails as phishing mails, and multi-stage response processing according to a preset response strategy.

3. The phishing email processing method of claim 1, wherein, The safety filtering of all original mails according to the key fields in the mail information according to the preset filtering strategy, to obtain the detected mails after safety filtering, comprises the following steps: confirmation of existence states of sender mailboxes and specified mail contents of all original mails according to the key fields in the mail information; acquisition of a preset sender whitelist, matching of the sender mailboxes of the original mails with the sender whitelist, initial safety filtering of the original mails matched successfully, to obtain initial filtering mails; secondary safety filtering of the initial filtering mails without the specified mail contents according to the existence states of the specified mail contents in the initial filtering mails, to obtain the detected mails after safety filtering.

4. The phishing email processing method of claim 1, wherein, The acquisition of the original samples of the detected mails, the mail type detection of the original samples of the detected mails by the agent constructed in advance, and the confirmation of whether the detected mails are phishing mails, comprises the following steps: acquisition of the original samples of the detected mails and analysis and feature engineering processing of the original samples by the agent constructed in advance, to extract multiple key mail features of the original samples; similarity calculation of the multiple key mail features with features of known phishing mails in a preset label library, to obtain a similarity of each key mail feature; weighted summation according to the similarity of each key mail feature, to obtain a total similarity; if the total similarity is greater than or equal to a similarity threshold, the preset label library is hit, and it is confirmed that the detected mails are phishing mails; if the total similarity is less than the similarity threshold, the detected mails are continuously identified as advertising marketing mails or suspicious mails.

5. The phishing email processing method of claim 4, wherein, The continuous identification of the detected mails as advertising marketing mails or suspicious mails comprises the following steps: The key mail features are identified as advertising marketing mails by a pre-trained classifier, and it is determined whether the mail to be detected is an advertising marketing mail; The sender and URL of the mail to be detected are subjected to credibility detection, and the mail body is subjected to intent analysis, to obtain a corresponding credibility score and intent score; It is determined whether the mail to be detected is a suspicious mail according to the credibility score and the intent score.

6. The phishing email processing method of claim 1, wherein, If it is determined that the mail is a phishing mail, a multi-stage response process is performed on the phishing mail according to the mail information of the phishing mail, the attack path of the phishing mail is blocked and eliminated, including: If it is determined that the mail is a phishing mail, a suppression stage response process is performed on the phishing mail according to the mail information of the phishing mail, and the attack path of the phishing mail is blocked; A tracing stage response process is performed on the phishing mail that has been subjected to the tracing process, the source information and the predicted attack path of the phishing mail are obtained; A tracking stage response process is performed on the phishing mail that has been subjected to the tracing process, the source information and the predicted attack path are used for continuous attack monitoring, and the attack path of the phishing mail in the future time period is eliminated.

7. The phishing email processing method of claim 6, wherein, Before the suppression stage response process is performed on the phishing mail according to the mail information of the phishing mail, the method further includes: An artificial review request is generated according to the mail information of the phishing mail and sent to a designated security user; The review result of the phishing mail after the artificial review by the designated security user is obtained, and the mail with a normal review result is filtered out.

8. A spam mail processing apparatus characterized by comprising: The method includes: An information acquisition module is configured to acquire mail information of an original mail in real time, and extract key fields in the mail information; A security filtering module is configured to perform security filtering on all original mails according to the key fields in the mail information according to a preset filtering strategy, to obtain a mail to be detected after security filtering; An intelligent agent detection module is configured to acquire an original sample of the mail to be detected, and perform mail type detection on the original sample of the mail to be detected by a pre-constructed intelligent agent, to determine whether the mail to be detected is a phishing mail; A multi-stage response module is configured to perform a multi-stage response process on the phishing mail according to the mail information of the phishing mail according to a preset response strategy if it is determined that the mail is a phishing mail, to block and eliminate the attack path of the phishing mail.

9. A computer device, comprising: The method includes at least one processor; and The memory is in communication connection with the at least one processor; wherein The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the phishing mail processing method of any one of claims 1-7.

10. A non-transitory computer readable storage medium, comprising: The non-volatile computer readable storage medium stores computer executable instructions, and the computer executable instructions are executed by one or more processors to enable the one or more processors to perform the phishing mail processing method of any one of claims 1-7.

Citation Information

Cited By

  • Mail processing method, device and system related to off-site derivatives

    CN121304107A