Email Detection Method and Device

By identifying the identification items of the email and selecting the appropriate display method for email detection, the problem of privacy leakage during the email detection process is solved, and the balance between security detection and privacy protection is achieved.

CN116132138BActive Publication Date: 2025-07-04QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211729162.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2025-07-04
Estimated Expiration
2042-12-30

AI Technical Summary

Technical Problem

During the existing email detection process, user privacy and company secrets are easily leaked, resulting in a higher risk of privacy leakage.

Method used

By obtaining the identification items of the target email, identifying the identification results, and selecting the corresponding display method from the preset display strategy. If the display method is to hide some or all of the email information, security detection will be performed.

Benefits of technology

While ensuring security inspection, it reduces the risk of privacy leakage and achieves flexible privacy control and detection adjustments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116132138B_ABST
    Figure CN116132138B_ABST
Patent Text Reader

Abstract

The present application discloses an email detection method and apparatus, relating to the field of computer technologies. The method of the present application includes: obtaining a target email to be detected, and identifying identification items of the target email to obtain an identification result; determining a first display mode corresponding to the identification result from preset display policies, wherein the preset display policies include display modes respectively corresponding to multiple identification results; if the first display mode is to hide at least part of the email information of the target email, performing a security detection on the target email displayed by using the first display mode.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a method and device for email detection. Background Art

[0002] With the popularization of paperless office, more and more enterprises use emails for communication. However, during the use of emails, the behavior of attacking with emails has gradually increased. To avoid the impact of spam emails such as phishing emails and Trojan emails on users in the enterprise, a detection engine is usually set up or a specific detection email box is used to detect emails.

[0003] Currently, during the process of email detection, the email is directly sent to a specified detection engine or detection email box to detect the email security. However, during this process, since many emails of users may involve privacy or company secrets, when sending the email to the specified detection email box or detection engine, especially the detection engine on the network side, there will be a risk of email privacy leakage, resulting in a relatively high risk of privacy leakage in the current email security detection process. Summary of the Invention

[0004] An embodiment of this application provides a method and device for email detection. The main purpose is to implement a method for email detection to solve the problem that personal or company privacy is easily leaked during the current process of email security detection and reduce the risk of privacy leakage.

[0005] To solve the above technical problems, the embodiment of this application provides the following technical solutions:

[0006] In a first aspect, this application provides a method for email detection. The method includes:

[0007] Obtain a target email to be detected, and identify the identification items of the target email to obtain an identification result;

[0008] Determine a first display method corresponding to the identification result from a preset display strategy, where the preset display strategy includes display methods corresponding to multiple identification results;

[0009] If the first display method is to hide at least part of the email information of the target email, perform a security detection on the target email displayed using the first display method.

[0010] Optionally, the method further includes:

[0011] When it is determined that the identification result matches any one of the identification results in the preset display strategy, add the display method corresponding to the matching identification result to the target email.

[0012] Optionally, the method further includes:

[0013] When it is determined that the recognition result does not match any of the recognition results in the preset display strategy, a second display method is added to the recognition result, and the second display method corresponding to the recognition result is added to the preset display strategy;

[0014] Wherein, the second display method includes any one of full display and partial display;

[0015] The full display is used to indicate that when outputting the target email, all the information of the target email is displayed;

[0016] The partial display is used to indicate that when outputting the target email, the partial information corresponding to the user instruction in the target email is displayed.

[0017] Optionally, the recognition items include at least one of sender information, recipient information, security threat level, and threat label;

[0018] If it is determined that there are multiple recognition results, and each recognition result corresponds to a recognition item, before determining the first display method corresponding to the recognition result from the preset display strategy, the method further includes:

[0019] Based on the user instruction, at least one of the multiple recognition items is determined as a rule recognition item, and the target recognition result corresponding to the rule recognition item and the display method corresponding to the target recognition result are determined;

[0020] The target recognition result and display method corresponding to each rule recognition item are determined as the matching rule corresponding to the rule recognition item, and the preset display strategy is constructed according to the matching rules corresponding to the multiple rule recognition items respectively.

[0021] Optionally, the determining the first display method corresponding to the recognition result from the preset display strategy includes:

[0022] Based on the recognition result of the target email, the corresponding recognition item is determined;

[0023] In the preset display strategy, based on the rule recognition item of the matching rule and the recognition item of the target email, the matching rule adapted to the target email is determined, wherein the adapted matching rule is the matching rule in which the rule recognition item is adapted to the recognition item of the target email;

[0024] Match the target recognition result in the adapted matching rule with the recognition result corresponding to the target email, and when the target recognition result in the adapted matching rule is the same as the recognition result corresponding to the target email, determine the display mode of the adapted matching rule as the first display mode corresponding to the recognition result.

[0025] Optionally, the method further includes:

[0026] If it is determined that there are multiple adapted matching rules for the target email, then reorganize the multiple adapted matching rules to obtain the reorganized matching rules; wherein, each reorganized matching rule includes at least two rule recognition items of the adapted matching rules, and the target recognition result corresponding to each rule recognition item, and the display modes corresponding to the target recognition results corresponding to different rule recognition items in the same reorganized matching rule are the same;

[0027] The matching the target recognition result in the adapted matching rule with the recognition result corresponding to the target email, and when the target recognition result in the adapted matching rule is the same as the recognition result corresponding to the target email, determining the display mode of the adapted matching rule as the first display mode corresponding to the recognition result includes:

[0028] Match the target recognition result corresponding to each rule recognition item in the reorganized matching rule with the recognition result corresponding to the target email respectively, and when the recognition result in the target email matches any target recognition result in the reorganized matching rule, determine the display mode of the reorganized matching rule as the first display mode corresponding to the recognition result.

[0029] Optionally, before obtaining the target email to be detected, the method further includes:

[0030] Determine the target delivery mode of the target email from the preset delivery modes, where the preset delivery modes include automatic delivery and manual delivery;

[0031] If it is determined that the target delivery mode is the automatic delivery, then proceed to execute the step of obtaining the target email to be detected.

[0032] Optionally, after determining the delivery mode of the target email, the method further includes:

[0033] If it is determined that the target delivery mode is the manual delivery, then determine the display mode of the target email as full display, where the full display is used to indicate that all the content of the target email is displayed when outputting the target email.

[0034] Optionally, the first display mode includes at least one of a first mode, a second mode, a third mode, and a fourth mode;

[0035] Among them, the first mode is used to indicate hiding all information of the target email when performing the security detection;

[0036] The second mode is used to indicate hiding the body and attachments of the target email when performing the security detection;

[0037] The third mode is used to indicate hiding the threat label of the target email when performing the security detection;

[0038] The fourth mode is used to indicate hiding the body, attachments, and threat label of the target email when performing the security detection.

[0039] In a second aspect, the present application further provides an email detection device, including:

[0040] An acquisition unit, configured to acquire a target email to be detected, and identify the identification items of the target email to obtain an identification result;

[0041] A first determination unit, configured to determine a first display mode corresponding to the identification result from a preset display strategy, where the preset display strategy includes display modes corresponding to multiple identification results;

[0042] A first execution unit, configured to perform a security detection on the target email displayed in the first display mode if the first display mode is to hide at least part of the email information of the target email.

[0043] Optionally, the device further includes:

[0044] A second determination unit, configured to add a display mode corresponding to the matching identification result to the target email when it is determined that the identification result matches any one of the identification results in the preset display strategy.

[0045] Optionally, the device further includes:

[0046] An addition unit, configured to add a second display mode to the identification result and add the second display mode corresponding to the identification result to the preset display strategy when it is determined that the identification result does not match any one of the identification results in the preset display strategy;

[0047] Among them, the second display mode includes any one of full display and partial display;

[0048] The full display is used to indicate that all information of the target email is displayed when outputting the target email;

[0049] The partial display is used to indicate that when outputting the target email, a part of the information corresponding to the user instruction in the target email is displayed.

[0050] Optionally, the recognition item includes at least one of sender information, recipient information, security threat level, and threat label;

[0051] If it is determined that there are multiple recognition results, and each recognition result corresponds to a recognition item, the device further includes:

[0052] A third determination unit, configured to determine at least one of the multiple recognition items as a rule recognition item based on the user instruction, and determine the target recognition result corresponding to the rule recognition item and the display manner corresponding to the target recognition result;

[0053] A fourth determination unit, configured to determine the target recognition result and display manner corresponding to each rule recognition item as a matching rule corresponding to the rule recognition item, and construct the preset display strategy according to the matching rules corresponding to the multiple rule recognition items respectively.

[0054] Optionally, the first determination unit includes:

[0055] A first determination module, configured to determine the corresponding recognition item based on the recognition result of the target email;

[0056] A second determination module, configured to determine, in the preset display strategy, a matching rule adapted to the target email based on the rule recognition item of the matching rule and the recognition item of the target email, where the adapted matching rule is a matching rule in which the rule recognition item in the matching rule is adapted to the recognition item of the target email;

[0057] A third determination module, configured to match the target recognition result in the adapted matching rule with the recognition result corresponding to the target email, and when the target recognition result in the adapted matching rule is the same as the recognition result corresponding to the target email, determine the display manner of the adapted matching rule as the first display manner corresponding to the recognition result.

[0058] Optionally, the device further includes:

[0059] A recombination unit, which is used to recombine multiple matching rules that are adapted to the target email if it is determined that there are multiple such matching rules, to obtain a recombined matching rule; wherein, each recombined matching rule includes at least two rule identification items of the adapted matching rules, and the target identification results corresponding to each rule identification item, and the display modes corresponding to the target identification results corresponding to different rule identification items in the same recombined matching rule are the same;

[0060] The third determination module is specifically configured to respectively match the target identification result corresponding to each rule identification item in the recombined matching rule with the identification result corresponding to the target email, and when the identification result in the target email matches any target identification result in the recombined matching rule, determine the display mode of the recombined matching rule as the first display mode corresponding to the identification result.

[0061] Optionally, the device further includes:

[0062] A delivery determination unit, which is used to determine the target delivery mode of the target email from preset delivery modes, where the preset delivery modes include automatic delivery and manual delivery;

[0063] A second execution unit, which is used to transfer to the step of obtaining the target email to be detected if it is determined that the target delivery mode is the automatic delivery.

[0064] Optionally, the device further includes:

[0065] A fifth determination unit, which is used to determine that the display mode of the target email is full display if it is determined that the target delivery mode is the manual delivery, where the full display is used to indicate that all the content of the target email is displayed when outputting the target email.

[0066] Optionally, the first display mode includes at least one of a first mode, a second mode, a third mode, and a fourth mode;

[0067] Wherein, the first mode is used to indicate hiding all the information of the target email when performing the security detection;

[0068] The second mode is used to indicate hiding the body and attachments of the target email when performing the security detection;

[0069] The third mode is used to indicate hiding the threat label of the target email when performing the security detection;

[0070] The fourth mode is used to indicate hiding the body, the attachments, and the threat label of the target email when performing the security detection.

[0071] In a third aspect, an embodiment of the present application provides a storage medium, which includes a stored program. When the program runs, it controls the device where the storage medium is located to execute the mail detection method of the terminal device described in the first aspect.

[0072] In a fourth aspect, an embodiment of the present application provides a mail detection device, which includes a storage medium; and one or more processors. The storage medium is coupled to the processors, and the processors are configured to execute program instructions stored in the storage medium; when the program instructions run, they execute the mail detection method of the terminal device described in the first aspect.

[0073] By means of the above technical solutions, the technical solutions provided by the present application have at least the following advantages:

[0074] The present application provides a mail detection method and device. The present application can first obtain a target mail to be detected, identify the identification items of the target mail to obtain an identification result, and then determine a first display method corresponding to the identification result from a preset display strategy, where the preset display strategy includes display methods corresponding to multiple identification results. Finally, if the first display method is to hide at least part of the mail information of the target mail, security detection is performed on the target mail displayed by using the first display method, so as to realize the mail detection function. Compared with the prior art, since in the process of security detection, the first display method adapted to the identification result of the target mail can be displayed based on the preset display strategy, and when the first display is to hide at least part of the mail information of the target mail, security detection is performed on the target mail according to the first display method, thus ensuring the effect of hiding the mail content during security detection when the target mail is confidential or privacy needs to be protected, and reducing the risk of privacy leakage. At the same time, the preset display strategy includes display methods corresponding to multiple identification results respectively, which can ensure that different display methods can be set based on different identification results based on the preset display strategy, and then in the subsequent process of analyzing and performing security detection, different display methods can be used to detect different target mails based on the differences in the display methods, which ensures the effect of flexibly adjusting the privacy control of different mails based on the preset display strategy during the process of detecting mails.

[0075] The above description is only an overview of the technical solutions of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0076] By reading the following detailed description with reference to the accompanying drawings, the above and other objects, features, and advantages of the exemplary embodiments of the present application will become readily understandable. In the drawings, several embodiments of the present application are shown in an exemplary rather than restrictive manner, and the same or corresponding reference numerals represent the same or corresponding parts, wherein:

[0077] Figure 1 A flowchart of a mail detection method provided by an embodiment of the present application is shown;

[0078] Figure 2 A flowchart of another mail detection method provided by an embodiment of the present application is shown;

[0079] Figure 3 A block diagram of the composition of a mail detection device provided by an embodiment of the present application is shown;

[0080] Figure 4 A block diagram of the composition of another mail detection device provided by an embodiment of the present application is shown. Detailed implementation manners

[0081] The exemplary embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present application can be more thoroughly understood and the scope of the present application can be fully communicated to those skilled in the art.

[0082] It should be noted that unless otherwise specified, the technical terms or scientific terms used in the present application should have the ordinary meaning understood by those skilled in the art to which the present application belongs.

[0083] An embodiment of the present application provides a mail detection method, specifically as Figure 1 shown, the method includes:

[0084] 101. Obtain a target mail to be detected, and identify the identification items of the target mail to obtain an identification result.

[0085] In this embodiment, the identification items include any one of the sender information, recipient information, security threat level, and threat label. And the identification result can be understood as the specific parameters corresponding to different identification items. For example, when the identification item is the sender information, then the corresponding identification result is that the sender is specifically A.

[0086] In this embodiment, the process of identifying the identification items of the target email to obtain the identification result can be understood as a preliminary detection of the target email. In this process, mainly several main parameters in the target email are determined, as well as whether there is a security threat. The main several parameters include where the email comes from or where the email is to be sent, that is, the sender information and the recipient information in the identification items. At the same time, a preliminary security detection is performed on the target email. In this process, the malicious situation of the target email can be identified, that is, the security threat level. For example, it can include several levels such as no risk, low risk, and high risk. Of course, in the application process of the method in this embodiment, the types, quantities, and methods of setting the security threat levels are not limited here. The above methods are only exemplary, and specifically can be selected based on the actual situation of the actual detection engine or detection device when the user performs this step of operation. In addition, the threat tag in this embodiment can be understood as the result obtained by further detecting the threat type when the security threat level of the target email is detected to be relatively high. For example, when the threat tag can include: network worm, Trojan program, botnet, etc.

[0087] In addition, in actual applications, when the method in this step is executed, the content detected for the target email can also be further added based on actual needs. For example, the specific form of identifying the target email according to the identification items and obtaining the identification result when this step is executed can be:

[0088] DetectResult = {from, to, sendCheck, maliciousLevel, maliciousTags};

[0089] Among them, DetectResult is the identification result corresponding to different identification items. Among them, the identification item from is the sender information, the identification item to is the recipient information; the identification item sendCheck is the email to be inspected; the identification item maliciousLevel is the security threat level, and the identification result of this identification item can specifically include three types: normal, suspicious, and dangerous; the identification item maliciousTags = <name, score> is the threat tag, where name represents the specific type of the threat tag, that is, the identification result includes worm (network worm), trojan (Trojan program), botnet (botnet), etc., and the identification item score is the degree of danger, and the corresponding identification result includes several types such as ordinary, dangerous, and especially dangerous.

[0090] 102. Determine the first display method corresponding to the identification result from the preset display strategy.

[0091] Among them, the preset display strategy includes display methods corresponding to multiple identification results.

[0092] After the recognition result is determined in the foregoing step, the recognition results corresponding to some recognition items of the current target email are actually known. For example, who the sender is, who the recipient is, whether there is a security threat, etc. Thus, in this step, the target email can be detected based on a preset display policy. Since the preset display policy includes display methods corresponding to different recognition results, the first display method matching the target email can be determined through the recognition result of the target email. It should be noted that, in this embodiment, the preset display policy can be set in advance based on a user instruction, or can be selected by the user separately issuing an instruction during each email display method confirmation process. Here, the setting method of the preset display policy is not limited, and can be selected based on actual needs.

[0093] For example, when the preset display policy preset by the user is that "when the sender is mailbox A, the corresponding display method is the first display method", at this time, the recognition result of the corresponding recognition item "sender" of the target email can be matched with the preset display policy to determine whether the target email is suitable. If it is determined that the recognition result of the target email is the same as the recognition result of the corresponding recognition item in the preset display policy, then the first display method can be assigned to the target email.

[0094] 103. If the first display method is to hide at least part of the email information of the target email, then perform a security detection on the target email displayed by using the first display method.

[0095] When it is determined in step 102 that the display method corresponding to the target email is the first display method, if the first display method is to hide at least part of the email information of the target email, then it means that in the subsequent security detection process, the target email needs to be controlled according to the first display method for the part of the email information to be hidden. For example, when it is determined that the actual hidden content of the first display method is the email body content, then based on the method of this step, when performing a security detection on the target email, it is necessary to hide its email body based on the first display method. In this way, it is ensured that during the security check process, at least part of the email information of the target email can be hidden based on the first display method, so as to ensure that when the target email involves privacy or confidentiality, the content can be hidden based on the user's needs, avoiding the problem of privacy content leakage when certain privacy-related emails are output, thereby protecting the user's privacy security and reducing the risk of privacy leakage.

[0096] The present application provides a method for email detection. In the embodiments of the present application, the target email to be detected can be obtained first, and the identification items of the target email are identified to obtain an identification result. Then, the first display method corresponding to the identification result is determined from the preset display strategies, where the preset display strategies include the display methods corresponding to multiple identification results respectively. Finally, if the first display method is to hide at least part of the email information of the target email, a security detection is performed on the target email displayed using the first display method, thereby implementing the email detection function. Compared with the prior art, since during the security detection process, the first display method adapted to the identification result of the target email can be displayed based on the preset display strategy, and when the first display is to hide at least part of the email information of the target email, the security detection is performed on the target email according to the first display method, thus ensuring the effect of hiding the email content during the security detection in the case where the target email is confidential or privacy needs to be protected, and reducing the risk of privacy leakage. At the same time, the preset display strategies include the display methods corresponding to multiple identification results respectively, which can ensure that different display methods can be set based on different identification results according to the preset display strategy. Subsequently, during the subsequent analysis and security detection process, different display methods can be adjusted for different target emails based on the differences in the display methods, which ensures the effect of flexible adjustment of the privacy control of different emails based on the preset display strategy during the email detection process.

[0097] For a more detailed description below, the embodiments of the present application provide another method for email detection, specifically as Figure 2 shown. This method includes:

[0098] 201. Determine the target delivery method of the target email from the preset delivery methods.

[0099] Among them, the delivery methods include automatic delivery and manual delivery.

[0100] In this embodiment, during the detection of the target email, there may be two different submission methods. One is that the detection system automatically delivers the emails accumulated in the preset email set to the execution device of the method described in this embodiment for detection at regular intervals, and the other is that the user specifically selects one or some emails for picking and then performs detection. The latter are often emails with security problems, which are likely to be spam emails or emails that need to be focused on during the security detection process.

[0101] Therefore, different delivery methods during the above-mentioned submission for inspection also reflect different inclinations towards protecting the privacy or maintaining the security of the target email. Thus, during the execution of the email detection process described in this embodiment, it is necessary to first determine based on the delivery method of the target email to be detected currently.

[0102] Based on the detection results, there are two cases. One is that the delivery method is determined to be manual delivery, and then step 202 is executed; the other is that the delivery method is determined to be automatic delivery, and then it transfers to execute the step of obtaining the target email to be detected, that is, step 203.

[0103] 202. If the delivery method is determined to be manual delivery, then determine the display method of the target email as full display.

[0104] Among them, the full display label is used to fully display the content of the target email when outputting the target email.

[0105] Based on the detection in the foregoing steps, when the delivery method is determined to be manual delivery, it indicates that the target email needs to focus on security during detection, so there is no need to protect its privacy. Thus, the display method of the target email can be directly set as full display. In this way, during the security detection process, there is no need to worry about privacy issues, and all the content in the target email can be directly displayed. The types and methods of the displayed content can be selected based on the types of the parameters of the target email preset by the user, that is, determined based on the types of the recognition results.

[0106] 203. Obtain the target email to be detected, and identify the identification items of the target email to obtain the identification result.

[0107] Among them, the identification items include at least one of the sender information, recipient information, security threat level, and threat label.

[0108] When the delivery method is determined to be automatic delivery, it indicates that the target email is not a specific email that the user needs to focus on screening for security. Therefore, the issue of privacy needs to be considered in this target email. Thus, in this embodiment, it is necessary to identify and detect the identification items in the target email based on the method of this step. The specific identification items can include sender information, recipient information, security threat level, and threat label, etc. for detection. For the specific meanings of the above identification items and the detection methods, they are the same as those described in step 101 of the foregoing embodiment, and will not be elaborated here.

[0109] 204. Based on the user instruction, determine at least one of the multiple identification items as the rule identification item, and determine the target identification result corresponding to the rule identification item and the display method corresponding to the target identification result.

[0110] In practical applications, the preset display strategy can be composed of different recognition results and display methods selected based on user needs. That is to say, it is possible to determine which one or several, namely the rule recognition items, from multiple recognition items. Then, determine the target recognition result of the rule recognition item and the corresponding display method. For example, the user instruction can select "sender information, recipient information, security threat level, and threat label" as the recognition items, and select "sender information" and "security threat level" as the rule recognition items. At the same time, based on this user instruction, determine the target recognition results corresponding to these two rule recognition items. The sender information is A, and the security threat level is medium. And based on the user instruction, determine the corresponding display method a when the sender information is A, and the display method b when the security threat level of the email is medium.

[0111] 205. Determine the target recognition result and display method corresponding to each rule recognition item as the matching rule for the corresponding rule recognition item, and construct a preset display strategy according to the matching rules corresponding to multiple rule recognition items respectively.

[0112] Based on the example of the foregoing steps, based on the rule recognition item "sender information", the recognition result "sender A", and the corresponding display method a, it can be set as matching rule 1, and based on the rule recognition item "security threat level", the recognition result "medium", and the corresponding display method b, it can be set as matching rule b, and determine these two matching rules as the preset display strategy. That is to say, under the control of the current user instruction, the generated preset display strategy includes the above-mentioned matching rule 1 and matching rule 2.

[0113] 206. Determine the first display method corresponding to the recognition result from the preset display strategy.

[0114] Among them, the preset display strategy contains the display methods corresponding to multiple recognition results respectively.

[0115] Specifically, when this step is executed, it can be:

[0116] Step 1. Based on the recognition result of the target email, determine the corresponding recognition item;

[0117] Step 2. In the preset display strategy, based on the rule recognition item of the matching rule and the recognition item of the target email, determine the matching rule that is compatible with the target email. Among them, the compatible matching rule is the matching rule in which the rule recognition item is compatible with the recognition item of the target email;

[0118] Step 3: Match the target recognition result in the adapted matching rule with the recognition result corresponding to the target email. When the target recognition result in the adapted matching rule is the same as the recognition result corresponding to the target email, determine the display mode of the adapted matching rule as the first display mode corresponding to the recognition result.

[0119] Since the recognition result of the target email can include multiple ones, and each matching rule in the preset display policy set by the user based on the instruction has a rule recognition item, then in the process of determining the first display mode of the recognition result corresponding to the target email based on the preset display policy, it is possible to first determine the recognition item of the recognition result based on Step 1 through the recognition result, and then match the rule recognition item of the matching rule in the preset display policy with the recognition item of the target email based on Step 2 to determine the adapted matching rule. Finally, based on Step 3, the display mode included in the adapted matching rule can be determined for the target email as the first display mode of the target email.

[0120] Since there may be a situation where the target email matches multiple adapted matching rules in practical applications, in order to avoid the problem of the same target email being matched multiple times, the matching rules can also be optimized. Based on this, the optimization process can be carried out in the following manner:

[0121] If it is determined that there are multiple adapted matching rules for the target email, then reorganize the multiple adapted matching rules to obtain the reorganized matching rules; where each reorganized matching rule includes at least 2 rule recognition items of the adapted matching rules, and the target recognition results corresponding to each rule recognition item, and the display modes corresponding to the target recognition results corresponding to different rule recognition items in the same reorganized matching rule are the same.

[0122] Based on this, Step 3 of this step can be executed as follows: Match the target recognition result corresponding to each rule recognition item in the reorganized matching rule with the recognition result corresponding to the target email respectively. When the recognition result in the target email matches any target recognition result in the reorganized matching rule, determine the display mode of the reorganized matching rule as the first display mode corresponding to the recognition result.

[0123] Since users need to perform security detection on multiple different emails in the same display manner based on the recognition results corresponding to different recognition items in actual applications, there will be a situation where individual emails meet multiple matching rules during this process. To avoid the problem of such emails being matched multiple times, in this step, the matching rules can be reorganized based on the above method to obtain new reorganized matching rules, so as to ensure that during the subsequent process of matching the matching rules with the target emails, as long as any one of the reorganized target recognition results can be matched, the first display manner of the target email can be directly determined.

[0124] For example, when the matching rules determined from the user instructions are respectively "hide the email body and attachments when the sender email is mailbox A" and "hide the email body and attachments when the security threat level is low risk". In this case, there will be a situation where the sender of a certain email is mailbox A and the security threat level of this email is low risk. At this time, if directly matching according to the above two matching rules, there may be a process of performing two matching operations on this mailbox, that is, after the first matching according to the matching rule "hide the email body and attachments when the sender email is mailbox A", there will also be a match based on the matching rule "hide the email body and attachments when the security threat level is low risk", which consumes unnecessary matching time. Especially in the case of facing a large number of such emails, it will greatly affect the detection efficiency and occupy the system resources during detection. Therefore, in this step, these two matching rules need to be reorganized to obtain the reorganized matching rule, that is, "when the sender mailbox is mailbox A, or the security threat level is low risk, hide the email body and attachments". Using this reorganized matching rule for detection can avoid the process of performing two matches on emails with the sender mailbox being mailbox A and the security threat level being low risk.

[0125] Furthermore, since the matching rules provided for users are generally set based on different recognition items, and the recognition items include various parameters such as "sender information", "recipient information", "security threat level", and "threat label", there will be an intersection situation during the matching process according to these parameters, that is, an email is covered by different recognition items of multiple matching rules. To avoid the situation of repeated detection of an email, in this embodiment, these matching rules can also be reorganized in advance. Of course, during the reorganization process, the method further includes:

[0126] First, based on the preset configuration information, determine all the rule recognition items, and split the rule recognition items according to the target parameters to obtain matching sub-items, where the target parameters include sender information and recipient information;

[0127] Then, all the rule recognition items are combined according to the exhaustive method to obtain rule recognition item combinations, and sub-item combinations are determined based on the matching sub-items corresponding to each rule recognition item.

[0128] After that, in each sub-item combination, the matching sub-items with the same detection content are merged to obtain the merged sub-item combination.

[0129] Finally, the matching item combination is determined as the first matching condition, and based on the relationship between each merged sub-item combination and the corresponding matching item combination, a mapping relationship is established between the first matching condition and the merged sub-item combination to obtain the preset item merging relationship. Here, the first matching condition can be understood as the condition for matching the recognition result of the reorganized matching rule with the target email.

[0130] Specifically, the method of this step can be as follows in the execution. For example, when it is determined to detect emails related to mailbox A, and the matching rules are: ① Hide the email body and attachments for emails with the sender being mailbox A; ② Hide the email body and attachments for emails with the recipient being mailbox A; ③ For emails with a low-risk security threat level, hide the email body and attachments; ④ For emails with a normal security threat level, hide the email body and attachments, a total of 4. Then, based on the method of this step, it can be split based on the target parameters, that is, the two types of sending and receiving emails. Since matching rules ① and ② themselves are rule recognition items set for sending and receiving emails and cannot be further split, the matching sub-items can be directly obtained as M1 Hide the email body and attachments for emails with the sender being mailbox A, and M2 Hide the email body and attachments for emails with the recipient being mailbox A. At the same time, matching rule ③ is split into: M3 For emails with the sender being mailbox A and a low-risk security threat level, hide the email body and attachments; M4 For emails with the recipient being mailbox A and a low-risk security threat level, hide the email body and attachments. Similarly, matching rule ④ is split into: M5 For emails with the sender being mailbox A and a normal security threat level, hide the email body and attachments; M6 For emails with the recipient being mailbox A and a normal security threat level, hide the email body and attachments. Among them, M1 to M6 are the matching sub-items. Then, based on the exhaustive method, M1 to M6 are combined among the matching sub-items to obtain sub-item combinations. The combination method is based on the combination of matching items, as shown in Table 1 below:

[0131] Table 1

[0132]

[0133] After obtaining the matching item combinations and sub-item combinations shown in Table 1 above, it can be seen that there are overlapping cases among the above combinations. Then, in order to ensure that the same email is not repeatedly detected according to two matching sub-items during the detection process, it is necessary to merge the above combinations.

[0134] For example, for the two selected matching rules, when selecting matching rules ① and ③, based on the foregoing analysis, it can be known that the matching sub-items M1, M3, and M4 are involved. Among them, M3 is an email with the sender being mailbox A and the security threat level being low-risk, hiding the email body and attachments. This matching sub-item is exactly a subset of M1. That is to say, during the detection process, it is not necessary to detect based on M3. Only detecting based on M1 includes the emails corresponding to M3. Therefore, the overlapping parts of the detection content can be merged, and getting M1 + M4 is equivalent to matching items ① and ③. Based on the same principle, the content in Table 1 can be merged to obtain the merged sub-item combinations as shown in Table 2 below:

[0135] Table 2

[0136]

[0137] Finally, determine the matching item combination as the first matching condition, and based on the relationship between each merged sub-item combination and the corresponding matching item combination, establish a mapping relationship between the first matching condition and the merged sub-item combination to obtain the preset item merging relationship. Specifically, this preset item merging relationship can be an item merging table, as shown in Table 3 below:

[0138] Table 3

[0139]

[0140]

[0141] In this embodiment, as shown in Table 3, the first matching condition includes 1 - 12, where 1 to 12 are the identifiers of the first matching condition respectively, used to distinguish different first matching conditions.

[0142] In addition, it should be noted that during the process of detecting the target email based on the preset item merging relationship, sometimes the user may select multiple different matching rules, and it is determined based on the method in the foregoing steps that matching needs to be performed based on multiple first matching conditions. Then, during this process, in order to ensure the efficiency of the matching process, different priorities can also be set for the above-mentioned multiple different first matching conditions. Then, during the process of matching the target email with multiple first matching conditions, the priority order between multiple first matching conditions can also be determined simultaneously in the preset item merging relationship, and this can be used as the detection order during detection, so as to ensure the orderly and fast progress of the detection process. For example, on the basis of the above 12 first matching conditions, there is also a 13th first matching condition, that is, the first matching condition 13, and the matching rule corresponding to the first matching condition 13 is that if both the sender and recipient of the email involve mailbox A, all content will be hidden during the email security detection process, and it is determined that the priority of this first matching condition is the highest. Then, during the detection process of this step, it is necessary to first determine whether the current target email matches the first matching condition 13. If it does not match, then execute the first matching conditions corresponding to other detection options selected by the user among the first matching conditions 1-12.

[0143] 207. If the first display method is to hide at least part of the email information of the target email, then perform a security check on the target email displayed using the first display method.

[0144] Among them, at least one of the recognition results and the display method corresponding to the recognition result are included in the preset display strategy, and the display method includes hiding the email content of the target email.

[0145] Specifically, in this embodiment, the first display method includes at least one of a first method, a second method, a third method, and a fourth method;

[0146] Among them, the first method is used to indicate hiding all the information of the target email when performing the security check;

[0147] The second method is used to indicate hiding the body and attachments of the target email when performing the security check;

[0148] The third method is used to indicate hiding the threat label of the target email when performing the security check;

[0149] The fourth method is used to indicate hiding the body, attachments, and threat label of the target email when performing the security check.

[0150] When it is determined that the target email matches any one of the target recognition results in the reorganized matching rules in the preset display strategy, that is, when the first matching condition is met, it indicates that a certain parameter in the target email is consistent with the target recognition result of the corresponding recognition item in the first matching condition, and the display method needs to be determined according to the matching rule selected by the user. For example, taking the example of the foregoing steps, when the matching rules selected by the user are ①③④, the corresponding first matching condition 4 is determined, and the sender of the target email is mailbox A. Therefore, it is determined that the target email matches it, and then the execution tags corresponding to hiding the email body and attachments corresponding to the user-selected matching items ①③④ can be added to the target email. Based on the description of this step, the corresponding display method can be added to the target email. Of course, in the process of determining the display method in this embodiment, execution tags corresponding to each display method can also be added to the target email, that is, in the subsequent security detection process, the display method to be adopted can be determined based on this execution tag.

[0151] Based on this, during subsequent security detection, the detection can be performed according to the display method corresponding to the execution tag.

[0152] After adding the execution tags of the corresponding first matching condition to the target email based on the foregoing steps, the target email can be subjected to security detection based on this execution tag. For example, when the tag of the target email is the second tag, and the display method characterized by the second tag is the second method, that is, the body and attachments of the email need to be hidden during security detection, then the above content should be hidden during the security detection process, which avoids the problem of leakage of the email body and attachments during the security detection process and can improve privacy security.

[0153] 208. When it is determined that the recognition result matches any one of the recognition results in the preset display strategy, add the display method corresponding to the matching recognition result to the target email.

[0154] Specifically, since there are two situations in the process of matching the recognition result with the preset display strategy, one is that it matches any ten recognition results, that is, the target email conforms to the recognition result of the preset display strategy, then the corresponding display method can be determined based on the method of this step.

[0155] 209. When it is determined that the recognition result does not match any one of the recognition results in the preset display strategy, add a second display method to the recognition result and add the second display method corresponding to the recognition result to the preset display strategy.

[0156] Among them, the second display method includes any one of full display and partial display;

[0157] The full display is used to indicate that when the target email is output, all information of the target email is displayed;

[0158] The partial display is used to indicate that when the target email is output, partial information corresponding to the user instruction in the target email is displayed.

[0159] Based on the description of the foregoing steps, it can be seen that in some cases, although the user has pre-selected different matching rules to generate corresponding preset display strategies, in actual applications, there may still be a situation where the target email does not match all the matching rules of the preset display strategy. At this time, the second display method can be determined. The second display method includes two types: one is the full display, which indicates that this target email may not be the email that the user is concerned about and needs to protect privacy. Therefore, all contents of this email can be fully displayed when the target email is output subsequently. On the other hand, it is the partial display, which is to ensure that privacy is not leaked when the target email is output subsequently. Of course, which part is displayed and which part is not displayed can be preset based on the user instruction. In this way, during the process of email detection, once it is found that the target email fails to match the detection conditions in the preset display strategy configured in advance, it can be flexibly adjusted based on the second display method, that is, it can be set to partial display based on privacy needs, or all contents can be displayed regardless of privacy, realizing the flexible display function of such emails that do not match the detection conditions of the preset display strategy when output. At the same time, by adding the second display method and the recognition result to the preset display strategy, it can be ensured that in some cases where no matching rule of the preset display strategy is matched, the relationship between the display result and the recognition result of this type of email can be added to the preset display strategy, thereby achieving the effect of continuously optimizing the display strategy.

[0160] Further, as an implementation of the above Figure 1 and Figure 2 shown method, another embodiment of the present application further provides an email detection device. The embodiment of this email detection device corresponds to the foregoing method embodiment. For the convenience of reading, the details of the foregoing method embodiment will not be described one by one in this embodiment of the email detection device, but it should be clear that the device in this embodiment can correspondingly implement all the contents of the foregoing method embodiment. Specifically as Figure 3 shown, the email detection device includes:

[0161] An obtaining unit 31, which can be used to obtain a target email to be detected, identify the identification items of the target email, and obtain an identification result;

[0162] The first determination unit 32 can be used to determine a first display mode corresponding to the recognition result from a preset display policy, where the preset display policy includes display modes corresponding to multiple recognition results;

[0163] The first execution unit 33 can be used to perform a security detection on a target email that is displayed in the first display mode if the first display mode is to hide at least part of the email information of the target email.

[0164] Further, as Figure 4 shown, the device further includes:

[0165] The second determination unit 34 can be used to add a display mode corresponding to the matching recognition result to the target email when it is determined that the recognition result matches any one of the recognition results in the preset display policy.

[0166] Further, as Figure 4 shown, the device further includes:

[0167] The adding unit 35 can be used to add a second display mode to the recognition result and add the second display mode corresponding to the recognition result to the preset display policy when it is determined that the recognition result does not match any one of the recognition results in the preset display policy;

[0168] wherein, the second display mode includes any one of full display and partial display;

[0169] The full display can be used to indicate that when outputting the target email, all the information of the target email is displayed;

[0170] The partial display can be used to indicate that when outputting the target email, part of the information corresponding to the user instruction in the target email is displayed.

[0171] Further, as Figure 4 shown, the recognition items include at least one of sender information, recipient information, security threat level, and threat label;

[0172] If it is determined that there are multiple recognition results and each recognition result corresponds to an identification item, the device further includes:

[0173] The third determination unit 36 can be used to determine at least one of the multiple identification items as a rule identification item based on a user instruction, and determine a target recognition result corresponding to the rule identification item and a display mode corresponding to the target recognition result;

[0174] The fourth determination unit 37 can be used to determine the target recognition result and display method corresponding to each of the rule recognition items as the matching rule corresponding to the rule recognition item, and construct the preset display policy according to the matching rules corresponding to the multiple rule recognition items.

[0175] Further, as Figure 4 shown, the first determination unit 32 includes:

[0176] The first determination module 321 can be used to determine the corresponding recognition item based on the recognition result of the target email.

[0177] The second determination module 322 can be used to determine, in the preset display policy, the matching rule adapted to the target email based on the rule recognition item of the matching rule and the recognition item of the target email, where the adapted matching rule is the matching rule in which the rule recognition item matches the recognition item of the target email.

[0178] The third determination module 323 can be used to match the target recognition result in the adapted matching rule with the recognition result corresponding to the target email, and when the target recognition result in the adapted matching rule is the same as the recognition result corresponding to the target email, determine the display method of the adapted matching rule as the first display method corresponding to the recognition result.

[0179] Further, as Figure 4 shown, the device further includes:

[0180] The recombination unit 38 can be used to, if it is determined that there are multiple adapted matching rules for the target email, recombine the multiple adapted matching rules to obtain the recombined matching rules; where each of the recombined matching rules includes at least two rule recognition items of the adapted matching rules, and the target recognition result corresponding to each rule recognition item, and the display methods corresponding to the target recognition results corresponding to different rule recognition items in the same recombined matching rule are the same.

[0181] The third determination module 323 can specifically be used to match the target recognition result corresponding to each rule recognition item in the recombined matching rule with the recognition result corresponding to the target email respectively, and when the recognition result in the target email matches any target recognition result in the recombined matching rule, determine the display method of the recombined matching rule as the first display method corresponding to the recognition result.

[0182] Further, as Figure 4 shown, the device further includes:

[0183] The delivery determination unit 39 can be used to determine the target delivery method of the target mail from preset delivery methods, where the preset delivery methods include automatic delivery and manual delivery;

[0184] The second execution unit 40 can be used to, if it is determined that the target delivery method is the automatic delivery, transfer to execute the step of obtaining the target mail to be detected.

[0185] Further, as Figure 4 shown, the device further includes:

[0186] The fifth determination unit 41 can be used to, if it is determined that the target delivery method is the manual delivery, determine that the display mode of the target mail is full display, where the full display can be used to indicate that all the content of the target mail is displayed when outputting the target mail.

[0187] Further, as Figure 4 shown, the first display mode includes at least one of a first mode, a second mode, a third mode, and a fourth mode;

[0188] Among them, the first mode can be used to indicate hiding all the information of the target mail when performing the security detection;

[0189] The second mode can be used to indicate hiding the body and attachments of the target mail when performing the security detection;

[0190] The third mode can be used to indicate hiding the threat label of the target mail when performing the security detection;

[0191] The fourth mode can be used to indicate hiding the body, attachments, and threat label of the target mail when performing the security detection.

[0192] An embodiment of the present application provides a method and apparatus for email detection. In the embodiment of the present application, a target email to be detected can be first obtained, and the identification items of the target email are identified to obtain an identification result. Then, a first display mode corresponding to the identification result is determined from a preset display strategy, where the preset display strategy includes display modes corresponding to multiple identification results respectively. Finally, if the first display mode is to hide at least part of the email information of the target email, a security detection is performed on the target email displayed using the first display mode, thereby implementing the email detection function. Compared with the prior art, since during the security detection process, the first display mode adapted to the identification result of the target email can be displayed based on the preset display strategy, and when the first display is to hide at least part of the email information of the target email, the security detection is performed on the target email according to the first display mode, thus ensuring that when the target email is confidential or privacy needs to be protected, the email content is hidden during the security detection, reducing the risk of privacy leakage. At the same time, the preset display strategy includes display modes corresponding to multiple identification results respectively, which can ensure that different display modes can be set based on different identification results according to the preset display strategy. Subsequently, during the subsequent analysis and security detection process, different display modes can be used to detect different target emails based on the different display modes, which ensures the effect of flexible adjustment of privacy control for different emails based on the preset display strategy during the email detection process.

[0193] An embodiment of the present application provides a storage medium, which includes a stored program. When the program runs, it controls the device where the storage medium is located to execute the above-mentioned email detection method.

[0194] The storage medium may include non-permanent memory in a computer-readable medium, forms such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.

[0195] An embodiment of the present application further provides an email detection device, which includes a storage medium; and one or more processors. The storage medium is coupled to the processor, and the processor is configured to execute program instructions stored in the storage medium; when the program instructions run, they execute the above-mentioned email detection method.

[0196] An embodiment of the present application provides a device, which includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, the following steps are implemented: obtaining a target email to be detected, and identifying the identification items of the target email to obtain an identification result; determining a first display mode corresponding to the identification result from a preset display policy, where the preset display policy includes display modes corresponding to multiple identification results respectively; if the first display mode is to hide at least part of the email information of the target email, performing a security detection on the target email displayed in the first display mode.

[0197] Further, the method further includes:

[0198] When it is determined that the identification result matches any one of the identification results in the preset display policy, adding the display mode corresponding to the matching identification result to the target email.

[0199] Further, the method further includes:

[0200] When it is determined that the identification result does not match any one of the identification results in the preset display policy, adding a second display mode to the identification result, and adding the second display mode corresponding to the identification result to the preset display policy;

[0201] Wherein, the second display mode includes any one of full display and partial display;

[0202] The full display is used to indicate that when outputting the target email, all the information of the target email is displayed;

[0203] The partial display is used to indicate that when outputting the target email, part of the information corresponding to the user instruction in the target email is displayed.

[0204] Further, the identification items include at least one of sender information, recipient information, security threat level, and threat label;

[0205] If it is determined that there are multiple identification results, and each identification result corresponds to an identification item, before determining the first display mode corresponding to the identification result from the preset display policy, the method further includes:

[0206] Based on the user instruction, determining at least one of the multiple identification items as a rule identification item, and determining the target identification result corresponding to the rule identification item and the display mode corresponding to the target identification result;

[0207] Determine the target recognition result and display method corresponding to each of the rule recognition items as the matching rule corresponding to the rule recognition item, and construct the preset display strategy according to the matching rules corresponding to multiple rule recognition items.

[0208] Further, the determining the first display method corresponding to the recognition result from the preset display strategy includes:

[0209] Based on the recognition result of the target email, determine the corresponding recognition item;

[0210] In the preset display strategy, based on the rule recognition item of the matching rule and the recognition item of the target email, determine the matching rule adapted to the target email, where the adapted matching rule is the matching rule in which the rule recognition item matches the recognition item of the target email;

[0211] Match the target recognition result in the adapted matching rule with the recognition result corresponding to the target email, and when the target recognition result in the adapted matching rule is the same as the recognition result corresponding to the target email, determine the display method of the adapted matching rule as the first display method corresponding to the recognition result.

[0212] Further, the method further includes:

[0213] If it is determined that there are multiple adapted matching rules for the target email, then reorganize the multiple adapted matching rules to obtain the reorganized matching rules; where each reorganized matching rule includes at least 2 rule recognition items of the adapted matching rules, and the target recognition result corresponding to each rule recognition item, and the display methods corresponding to the target recognition results corresponding to different rule recognition items in the same reorganized matching rule are the same;

[0214] The matching the target recognition result in the adapted matching rule with the recognition result corresponding to the target email, and when the target recognition result in the adapted matching rule is the same as the recognition result corresponding to the target email, determining the display method of the adapted matching rule as the first display method corresponding to the recognition result includes:

[0215] Match the target recognition result corresponding to each rule recognition item in the reorganized matching rule with the recognition result corresponding to the target email, and when the recognition result in the target email matches any target recognition result in the reorganized matching rule, determine the display method of the reorganized matching rule as the first display method corresponding to the recognition result.

[0216] Further, before obtaining the target email to be detected, the method further includes:

[0217] Determine the target delivery method of the target email from a preset delivery method, where the preset delivery method includes automatic delivery and manual delivery;

[0218] If it is determined that the target delivery method is the automatic delivery, then proceed to execute the step of obtaining the target email to be detected.

[0219] Further, after determining the delivery method of the target email, the method further includes:

[0220] If it is determined that the target delivery method is the manual delivery, then determine the display method of the target email as full display, where the full display is used to indicate that all the content of the target email is displayed when outputting the target email.

[0221] Further, the first display method includes at least one of a first method, a second method, a third method, and a fourth method;

[0222] Wherein, the first method is used to indicate hiding all the information of the target email when performing the security detection;

[0223] The second method is used to indicate hiding the body and attachments of the target email when performing the security detection;

[0224] The third method is used to indicate hiding the threat label of the target email when performing the security detection;

[0225] The fourth method is used to indicate hiding the body, attachments, and threat label of the target email when performing the security detection.

[0226] The present application also provides a computer program product, which when executed on a data processing device, is adapted to execute program code initialized with the following method steps: obtaining a target email to be detected, and identifying the identification items of the target email to obtain an identification result; determining a first display method corresponding to the identification result from a preset display policy, where the preset display policy contains display methods corresponding to multiple identification results; if the first display method is to hide at least part of the email information of the target email, then perform a security detection on the target email displayed using the first display method.

[0227] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.

[0228] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0229] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0230] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are performed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0231] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0232] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.

[0233] A computer-readable medium includes both permanent and non-permanent, removable and non-removable media and can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, tape magnetic disks storage or other magnetic storage devices, or any other non-transitory media that can be used to store information that can be accessed by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media, such as modulated data signals and carrier waves.

[0234] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or apparatus comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or apparatus. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or apparatus comprising the element.

[0235] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0236] The above are only the embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A mail detection method, characterized in that, Including: Obtain a target email to be detected, and identify the identification items of the target email to obtain an identification result; wherein, the identification of the identification items of the target email is specifically used for performing a preliminary security detection on the target email; Determine a first display method corresponding to the identification result from a preset display strategy, wherein the preset display strategy includes display methods corresponding to multiple identification results respectively; If the first display method is to hide at least part of the email information of the target email, perform a security detection on the target email displayed using the first display method; Wherein, the identification result is determined when the identification item of the target email matches the rule identification item of the matching rule; the matching rule is obtained based on a recombination operation; Wherein, the recombination operation specifically includes: determining all the rule identification items based on preset configuration information, and splitting the rule identification items according to target parameters to obtain matching sub-items, the target parameters including sender information and recipient information; Combine all the rule identification items according to the exhaustive method to obtain a rule identification item combination, and determine a sub-item combination based on the matching sub-items corresponding to each rule identification item; In each sub-item combination, merge the matching sub-items with the same detection content to obtain a merged sub-item combination; Determine the matching item combination as the first matching condition, and establish a mapping relationship between the first matching condition and the merged sub-item combination based on the relationship between each merged sub-item combination and the corresponding matching item combination to obtain a preset item merging relationship; the first matching condition is the condition for matching the identification result of the target email with the matching rule after recombination.

2. The method according to claim 1, characterized in that, The method further includes: When it is determined that the identification result matches any one of the identification results in the preset display strategy, add the display method corresponding to the matching identification result to the target email.

3. The method according to claim 2, wherein The method further includes: When it is determined that the identification result does not match any one of the identification results in the preset display strategy, add a second display method to the identification result, and add the second display method corresponding to the identification result to the preset display strategy; Wherein, the second display method includes any one of full display and partial display; The full display is used to indicate that when outputting the target email, all the information of the target email is displayed; The partial display is used to indicate that when outputting the target email, display the partial information corresponding to the user instruction in the target email.

4. The method according to claim 1, wherein The identification items include at least one of sender information, recipient information, security threat level, and threat label; If it is determined that there are multiple identification results, and each identification result corresponds to an identification item, before determining the first display method corresponding to the identification result from the preset display strategy, the method further includes: Based on the user instruction, determine at least one of the multiple identification items as a rule identification item, and determine the target identification result corresponding to the rule identification item and the display method corresponding to the target identification result; Determine the target recognition result and display method corresponding to each of the rule recognition items as the matching rule corresponding to the rule recognition item, and construct the preset display strategy according to the matching rules corresponding to multiple rule recognition items respectively.

5. The method according to claim 4, characterized in that, The determining the first display method corresponding to the recognition result from the preset display strategy includes: Determine the corresponding recognition item based on the recognition result of the target email. In the preset display strategy, based on the rule recognition item of the matching rule and the recognition item of the target email, determine the matching rule adapted to the target email, where the adapted matching rule is the matching rule in which the rule recognition item is adapted to the recognition item of the target email. Match the target recognition result in the adapted matching rule with the recognition result corresponding to the target email, and when the target recognition result in the adapted matching rule is the same as the recognition result corresponding to the target email, determine the display method of the adapted matching rule as the first display method corresponding to the recognition result.

6. The method according to claim 5, characterized in that The method further includes: If it is determined that there are multiple adapted matching rules for the target email, then reorganize the multiple adapted matching rules to obtain the reorganized matching rules; where each reorganized matching rule includes at least 2 rule recognition items of the adapted matching rules, and the target recognition results corresponding to each rule recognition item, and the display methods corresponding to the target recognition results corresponding to different rule recognition items in the same reorganized matching rule are the same. The matching the target recognition result in the adapted matching rule with the recognition result corresponding to the target email, and when the target recognition result in the adapted matching rule is the same as the recognition result corresponding to the target email, determining the display method of the adapted matching rule as the first display method corresponding to the recognition result includes: Match the target recognition result corresponding to each rule recognition item in the reorganized matching rule with the recognition result corresponding to the target email respectively, and when the recognition result in the target email matches any target recognition result in the reorganized matching rule, determine the display method of the reorganized matching rule as the first display method corresponding to the recognition result.

7. The method according to any one of claims 1-6, characterized in that, Before obtaining the target email to be detected, the method further includes: Determine the target delivery method of the target email from the preset delivery methods, where the preset delivery methods include automatic delivery and manual delivery. If it is determined that the target delivery method is the automatic delivery, then proceed to execute the step of obtaining the target email to be detected.

8. The method according to claim 7, wherein After determining the delivery method of the target email, the method further includes: If it is determined that the target delivery method is the manual delivery, then determine the display method of the target email as full display, where the full display is used to indicate that all the content of the target email is displayed when outputting the target email.

9. The method according to any one of claims 1-6, characterized in that, The first display method includes at least one of the first method, the second method, the third method, and the fourth method. Among them, the first method is used to indicate hiding all information of the target email when performing the security detection; The second method is used to indicate hiding the body and attachments of the target email when performing the security detection; The third method is used to indicate hiding the threat label of the target email when performing the security detection; The fourth method is used to indicate hiding the body, attachments and threat label of the target email when performing the security detection.

10. A mail detection device, characterized in that, It includes: An acquisition unit, configured to acquire a target email to be detected, and identify the identification items of the target email to obtain an identification result; among them, the identification of the identification items of the target email is specifically used to perform a preliminary security detection on the target email; A first determination unit, configured to determine a first display method corresponding to the identification result from a preset display strategy, where the preset display strategy includes display methods corresponding to multiple identification results; A first execution unit, configured to perform a security detection on the target email displayed by using the first display method if the first display method is to hide at least part of the email information of the target email; Among them, the identification result is determined when the identification item of the target email matches the rule identification item of the matching rule; the matching rule is obtained based on the recombination operation; where the recombination operation specifically includes: based on the preset configuration information, determining all the rule identification items, and splitting the rule identification items according to the target parameters to obtain matching sub-items, the target parameters including sender information and recipient information; and, combining all the rule identification items by the exhaustive method to obtain a rule identification item combination, and determining a sub-item combination based on the matching sub-items corresponding to each rule identification item; and, in each sub-item combination, merging the matching sub-items with the same detection content to obtain a merged sub-item combination; and, determining the matching item combination as the first matching condition, and establishing a mapping relationship between the first matching condition and the merged sub-item combination based on the relationship between each merged sub-item combination and the corresponding matching item combination to obtain a preset item merging relationship; the first matching condition is the condition for matching the identification result of the target email with the matching rule after recombination.

11. A storage medium, characterized in that, The storage medium includes a stored program, where when the program runs, it controls the device where the storage medium is located to execute the email detection method according to any one of claims 1 to 9.

12. A mail detection device, characterized in that, The device includes a storage medium; and one or more processors, the storage medium is coupled to the processor, and the processor is configured to execute the program instructions stored in the storage medium; when the program instructions run, they execute the email detection method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Mail receiving method and device, computer device and computer readable storage medium

    CN108153567A

  • E-mail processing method and device, computer readable medium and electronic equipment

    CN112785240A