Phishing mail detection method, device and equipment and storage medium

By using technical means such as email address blacklist, email sandbox system and feature abnormality verification in phishing email detection, the problem of low accuracy of phishing email detection in the existing technology is solved, and higher detection accuracy and lower missed rate is achieved.

CN120017305APending Publication Date: 2025-05-16INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Patent Information

Application Number
CN202411963704.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

When facing complex and changing phishing rhetoric, the existing phishing email detection model is prone to problems of high misreport and low accuracy.

Method used

Address verification is performed based on the email address blacklist. If it is passed, the email will be sent to the email sandbox system for malicious file identification. If there is no exception, feature abnormality verification will be performed. After passing, the phishing email detection system will be used for content abnormality detection to generate an email detection report.

Benefits of technology

It improves the accuracy of phishing email detection, and through multi-level and multi-dimensional detection, the missed and false alarm rates are effectively reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017305A_ABST
    Figure CN120017305A_ABST
Patent Text Reader

Abstract

The invention discloses a phishing mail detection method and device, equipment and a storage medium, and relates to the technical field of information security. The method comprises the steps of performing address verification on an email address of a to-be-detected email based on an email address blacklist; wherein the mailbox address blacklist is constructed according to mailbox addresses of historical phishing mails; the to-be-detected email refers to a newly received email; under the condition that the address verification is passed, sending the to-be-detected mail to a mail sandbox system, so that the mail sandbox system performs malicious file identification on the to-be-detected mail; under the condition that no exception instruction returned by the mail sandbox system is recognized, feature exception verification is carried out on the to-be-detected mail; and if the feature abnormality verification is passed, performing content abnormality detection on the mail content of the to-be-detected mail by adopting a phishing mail detection system to obtain a mail detection report. According to the technical scheme, the accuracy of phishing mail detection can be effectively improved through multi-level and multi-dimensional phishing mail detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of artificial intelligence technology, in particular to the field of information security technology, and specifically to a phishing email detection method, device, equipment and storage medium. Background Art

[0002] With the continuous development of the Internet, email has gradually become an indispensable part of people's work and life. At the same time, the security of email itself is constantly facing challenges.

[0003] Phishing attacks against enterprises continue to occur, which have a great impact on the normal operation of enterprises and will also cause certain economic losses. With the continuous advancement of network security technology, email phishing has become a lower-cost but more efficient means of attack. To address this problem, existing email systems generally have phishing email detection modes, but under a single traditional detection mode, complex and changeable phishing tactics are prone to problems such as high underreporting and low accuracy. Summary of the invention

[0004] The present application provides a phishing email detection method, apparatus, device and storage medium to improve the accuracy of phishing email detection.

[0005] According to one aspect of the present application, a phishing email detection method is provided, the method comprising:

[0006] Based on the email address blacklist, the email address of the email to be detected is verified; wherein the email address blacklist is constructed based on the email addresses of historical phishing emails; the email to be detected refers to a newly received email;

[0007] If the address verification passes, the mail to be detected is sent to the mail sandbox system, so that the mail sandbox system can identify malicious files on the mail to be detected;

[0008] When a normal instruction is identified to be returned by the email sandbox system, a feature abnormality check is performed on the email to be detected;

[0009] If the feature anomaly check passes, a phishing email detection system is used to perform content anomaly detection on the email content of the email to be detected to obtain an email detection report.

[0010] According to another aspect of the present application, a phishing email detection device is provided, the device comprising:

[0011] An address verification module, used to perform address verification on the email address of the email to be detected based on the email address blacklist; wherein the email address blacklist is constructed based on the email addresses of historical phishing emails; the email to be detected refers to a newly received email;

[0012] A file identification module is used to send the mail to be detected to the mail sandbox system when the address verification passes, so that the mail sandbox system can identify malicious files on the mail to be detected;

[0013] A feature verification module, configured to perform feature abnormality verification on the email to be detected when a normal instruction returned by the email sandbox system is identified;

[0014] The content detection module is used to use a phishing email detection system to perform content anomaly detection on the email content of the email to be detected if the feature anomaly check passes, and obtain an email detection report.

[0015] According to another aspect of the present application, an electronic device is provided, the electronic device comprising:

[0016] one or more processors;

[0017] A memory for storing one or more programs;

[0018] When the one or more programs are executed by the one or more processors, the one or more processors implement any one of the phishing email detection methods provided in the embodiments of the present application.

[0019] According to another aspect of the present application, a computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, any one of the phishing email detection methods provided in the embodiments of the present application is implemented.

[0020] According to another aspect of the present application, a computer program product is provided, including a computer program, which, when executed by a processor, implements any one of the phishing email detection methods provided in the embodiments of the present application.

[0021] This application verifies the address of the email address to be detected based on the email address blacklist; wherein the email address blacklist is constructed based on the email addresses of historical phishing emails; the email to be detected refers to a newly received email; if the address verification passes, the email to be detected is sent to the email sandbox system so that the email sandbox system can identify malicious files in the email to be detected; if the email sandbox system returns a normal instruction, the email to be detected is verified for feature anomalies; if the feature anomaly verification passes, the phishing email detection system is used to perform content anomaly detection on the email content of the email to be detected to obtain an email detection report. The above technical solution can effectively improve the accuracy of phishing email detection through multi-level and multi-dimensional phishing email detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 This is a flow chart of a phishing email detection method provided according to Embodiment 1 of the present application;

[0023] Figure 2 This is a flow chart of a phishing email detection method provided according to Embodiment 2 of the present application;

[0024] Figure 3 It is a structural schematic diagram of a phishing email detection device provided according to Embodiment 3 of the present application;

[0025] Figure 4 It is a structural diagram of an electronic device that implements the phishing email detection method of an embodiment of the present application. DETAILED DESCRIPTION

[0026] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.

[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0028] In addition, it should be noted that in the technical solution of this application, the collection, storage, use, processing, transmission, provision and disclosure of relevant data such as email address blacklists and emails to be detected are in compliance with the relevant laws and regulations and do not violate public order and good morals.

[0029] Embodiment 1

[0030] Figure 1 This is a flowchart of a phishing email detection method provided according to the first embodiment of the present application. This embodiment can be applied to the case of identifying whether a newly received email is a phishing email. It can be performed by a phishing email detection device. The phishing email detection device can be implemented in the form of hardware and / or software. The phishing email detection device can be configured in a computer device, such as a server. Figure 1 As shown, the method includes:

[0031] S110. Based on the email address blacklist, perform address verification on the email address of the email to be detected; wherein the email address blacklist is constructed based on the email addresses of historical phishing emails; the email to be detected refers to a newly received email.

[0032] In this embodiment, the email address blacklist refers to a list of known email addresses that have been used to send phishing emails or spam emails; the list is constructed based on the email addresses of historical phishing emails, and the purpose is to quickly identify and filter out emails from untrusted sources when receiving new emails. Emails to be detected refer to emails that have just been received and have not yet undergone the security detection process. Historical phishing emails refer to emails that have been identified as phishing emails in the past, as well as emails that are publicly available on the Internet. An email address refers to a unique identifier used to receive emails, usually consisting of a user name and a domain name; it serves as the identity of the recipient in email communications, and any email sent over the Internet needs to specify a sender address and one or more recipient addresses.

[0033] Optionally, based on the email address blacklist, corresponding filtering rules are set in the email gateway; according to the filtering rules, the address of the email to be detected is verified to filter the blacklisted email addresses.

[0034] Specifically, based on the email address blacklist, filtering rules are set in the email gateway; wherein the filtering rules refer to a consistency check between the email address of the email to be detected and the email address blacklist; when the email to be detected is received, the email address of the email to be detected is checked based on the filtering rules.

[0035] Exemplarily, an email address blacklist is constructed by accumulating email addresses of historical phishing email addresses received and crawling phishing email addresses publicly available on the Internet; the email address of the email to be detected is compared with the email address blacklist for consistency; if the email address of the email to be detected is not found in the email address blacklist, it is proved that the email address of the email to be detected is safe, that is, the address verification passes.

[0036] It is understandable that by setting rules on the email gateway, filtering of blacklisted email addresses is achieved to complete the first layer of protection; rule-based filtering detection has low latency and good stability, and can quickly filter out phishing emails with obvious characteristics, saving detection resources.

[0037] S120: If the address verification passes, the email to be detected is sent to the email sandbox system, so that the email sandbox system can identify malicious files on the email to be detected.

[0038] In this embodiment, the email sandbox system refers to a system that analyzes whether the email content contains malicious code, viruses or other potential threats by placing the email and its attachments in an isolated virtual environment; the email sandbox can simulate the actual behavior of the email, such as opening attachments, clicking links, etc., in order to detect malicious programs hidden therein.

[0039] Exemplarily, the mailbox to be detected that passes the address verification is sent to the email sandbox system for attachment detection. The email sandbox system can identify malicious files in the attachments of the mailbox to be detected; if the email sandbox system does not detect malicious files, it returns a no abnormality instruction.

[0040] S130: When a normal instruction is identified to be returned by the email sandbox system, a feature abnormality check is performed on the email to be detected.

[0041] In this embodiment, no abnormal instructions means that the email sandbox system has not detected any instructions of malicious programs from the email to be detected, which means that the email to be detected has passed the detection of the email sandbox system. Feature abnormality verification refers to determining whether the email is abnormal by analyzing various features of the email; common abnormal features include abnormal email structure, irregular format, grammatical errors, links pointing to suspicious websites, etc.

[0042] Optionally, performing feature anomaly check on the email to be detected can be: based on a machine learning model, extracting features of the email to be detected to obtain features to be detected; performing consistency check on the features to be detected and an abnormal feature set; wherein the abnormal feature set is obtained by extracting features from historical phishing emails through a multi-channel large model.

[0043] In this embodiment, the machine learning model refers to an algorithm that predicts or classifies by learning a large amount of data; in phishing email detection, the machine learning model is usually used to analyze historical email data, learn common features of phishing emails, and apply these features to the detection of new emails. The features to be detected refer to various features that can represent the content, structure, sending behavior, etc. of the email to be detected. The multi-channel large model refers to a complex model structure used in machine learning and deep learning, which is usually used to process input data with multiple features; it processes different types of data features (such as text features, structural features, network behavior features, etc.) through different "channels" and combines this information for prediction.

[0044] Exemplarily, the abnormal feature set can be determined by building a multi-channel automatic feature extraction mechanism through multiple general large models, using different large models to automatically extract features for each phishing email sample, and then taking the union of the feature extraction results of the different large models to obtain the final feature set as the abnormal features of the phishing email; these abnormal features are summarized to obtain the abnormal feature set.

[0045] In an optional implementation manner, if the mail to be detected has no attachment, then in the case where the address verification passes, an abnormality check is performed on the mail to be detected.

[0046] S140. If the feature anomaly check passes, a phishing email detection system is used to perform content anomaly detection on the email content to be detected, and an email detection report is obtained.

[0047] In this embodiment, the phishing email detection system is a security system specially designed to identify and intercept phishing emails; it uses a series of algorithms (such as machine learning models, rule engines, etc.) to analyze multiple dimensions of emails (such as content, attachments, sending mode, etc.) to determine whether the email is a phishing email. The email detection report is a detailed report generated by the phishing email detection system, which describes the results of the security detection of the email; the report usually includes whether the email is judged to be a phishing email, abnormal features in the email, possible threats, recommended treatment measures, etc.

[0048] Optionally, the phishing email detection system may include an email header detection module, an intent recognition module, a sentiment analysis module, and a link and QR code detection module; the email content includes the email header content, email body content, links, and QR codes.

[0049] In this embodiment, the email header detection module refers to an expert who identifies suspicious content in the email header of the email to be detected. The intent recognition module refers to an expert who identifies suspicious intent in the email content of the email to be detected. The sentiment analysis module refers to an expert who analyzes the sentiment characteristics of the email content in the detection module. The link and QR code detection module refers to an expert who performs content detection on the links or QR codes contained in the email content in the detection module.

[0050] In an optional embodiment, the phishing email detection system is constructed based on a fine-tuned phishing email detection model and a multi-agent system; the fine-tuned phishing email detection model is obtained by fine-tuning a general large model or a security vertical large model based on a phishing email sample data set; the phishing email sample data set is determined based on historical phishing emails.

[0051] In this embodiment, the fine-tuned phishing email detection model refers to the process of retraining or adjusting a specific task (here, phishing email detection) based on a pre-trained large-scale machine learning model (such as a large-scale language model, a vertical large model, etc.); the fine-tuned phishing email detection model is trained on a phishing email sample data set to optimize the accuracy and effect of the model in identifying phishing emails. A multi-agent system refers to a system composed of multiple autonomous agents that can complete tasks through collaboration, competition, or other forms of interaction; in phishing email detection, a multi-agent system can be used to perform complex email analysis and detection tasks through multiple agents working together. A phishing email sample data set refers to a collection of a large number of real or simulated phishing emails for training and verifying a phishing email detection system; the data set usually contains different types of phishing emails, such as emails from fake banks, payment platforms, e-commerce websites, etc.; these emails will be marked as "phishing emails" and used as training data to help the model learn to identify the characteristics of malicious emails. A general large model refers to an artificial intelligence model that can handle a variety of different tasks, usually consisting of billions or even tens of billions of parameters, and can handle multiple tasks or solve multiple problems through a single framework or platform. Vertical large models refer to large artificial intelligence models trained in specific fields (such as phishing email detection); these models are usually pre-trained using specific data related to the domain, so that the model has stronger understanding and reasoning capabilities for specific tasks.

[0052] Exemplarily, firstly, a sample set of phishing emails covering all types is constructed through an existing public phishing email dataset or a private dataset, including social engineering type, link type, image QR code type, and attachment document type, etc.; then the dataset is preprocessed, and the specific preprocessing process is as follows: for each phishing email sample, it is disassembled into {email header, email protocol, email body, email attachment}, wherein the email header contains the mail_from and from fields of the sender address and the mail_to and to fields of the recipient address; the email protocol contains the verification result of the email security protocol; the email body includes the content description of the email body, the url (Uniform Resource Locator) link and QR code contained in the email; since the large model context has a length limit, for emails with too long body content, the body content is first cropped or the email content is summarized and summarized through the large model to compress the content to the required length; after the dataset is constructed, LoRA (Low-Rank The parameters of the large model are adjusted by the low-rank adaptation (low-rank adaptation) fine-tuning technology to obtain the fine-tuned model as the large model for phishing email detection; based on the fine-tuned large model for phishing email detection, a phishing email detection system is constructed through a multi-agent approach.

[0053] The embodiment of the present application performs address verification on the email address of the email to be detected based on the email address blacklist; wherein the email address blacklist is constructed based on the email addresses of historical phishing emails; the email to be detected refers to a newly received email; if the address verification passes, the email to be detected is sent to the email sandbox system so that the email sandbox system can identify malicious files on the email to be detected; if the email sandbox system returns a normal instruction, the email to be detected is verified for feature anomalies; if the feature anomaly verification passes, the phishing email detection system is used to perform content anomaly detection on the email content of the email to be detected to obtain an email detection report. The above technical solution can effectively improve the accuracy of phishing email detection through multi-level and multi-dimensional phishing email detection.

[0054] Embodiment 2

[0055] Figure 2It is a flow chart of a phishing email detection method provided in accordance with the second embodiment of the present application. Based on the technical solutions of the above embodiments, this embodiment refines "using a phishing email detection system to perform content anomaly detection on the email content to be detected and obtain an email detection report" into "based on the thinking chain method, according to the email header detection module, the intent recognition module, the sentiment analysis module and the link and QR code detection module, construct a detection task flow of a phishing email detection system; using a phishing email detection system, according to the detection task flow, perform content anomaly detection on the email content to be detected and obtain an email detection report". It should be noted that for the parts not described in detail in the embodiments of the present application, please refer to the relevant statements of other embodiments. Figure 2 As shown, the method includes:

[0056] S210. Based on the email address blacklist, perform address verification on the email address of the email to be detected; wherein the email address blacklist is constructed based on the email addresses of historical phishing emails; the email to be detected refers to a newly received email.

[0057] S220: If the address verification passes, the email to be detected is sent to the email sandbox system, so that the email sandbox system can identify malicious files in the email to be detected.

[0058] S230: When a normal instruction is identified to be returned by the email sandbox system, a feature abnormality check is performed on the email to be detected.

[0059] S240. If the feature anomaly check passes, based on the thinking chain method, according to the email header detection module, intent recognition module, sentiment analysis module and link and QR code detection module, a detection task flow of the phishing email detection system is constructed.

[0060] In this embodiment, the thought chain method refers to a technical method in the field of artificial intelligence, especially natural language processing, which helps AI (Artificial Intelligence) models maintain a coherent reasoning process when dealing with complex problems, so as to gradually draw conclusions; the key idea of ​​the thought chain method is to allow the model to not only give the final answer when solving problems, but also to explicitly display the intermediate steps of reasoning, so as to make the model's reasoning process more transparent and explainable. The detection task flow refers to the processing of each module of the detection email according to certain processes and steps in the phishing email detection system in order to achieve effective phishing email identification; these modules work together in a certain order, and each module is responsible for different detection tasks; the task flow usually includes steps such as email header parsing, intent recognition, sentiment analysis, link and QR code detection.

[0061] Exemplarily, through the way of thinking chain, the phishing email detection task flow is constructed, that is, for each email to be detected, the following task tree is constructed: {Task 1: Detect whether the email header is suspicious; Task 2: Identify whether the email intention is suspicious; Task 3: Analyze whether the email emotion is suspicious; Task 4: Analyze whether the email contains malicious links and QR codes}.

[0062] S250: Using the phishing email detection system, according to the detection task flow, perform content anomaly detection on the email content to be detected, and obtain an email detection report.

[0063] Optionally, an email header detection module is used to verify the content of the email header of the email to be detected to obtain an email header detection result; an intention recognition module is used to identify suspicious intents in the email body of the email to be detected to obtain an intention recognition result; a sentiment analysis module is used to perform sentiment feature analysis on the email body of the email to be detected to obtain a sentiment analysis result; a link and QR code detection module is used to perform content detection on the links and QR codes in the email to be detected to obtain a link and QR code detection result; the email header detection result, intent recognition result, sentiment analysis result and link and QR code detection result are integrated to obtain an email detection report.

[0064] In this embodiment, the email header content refers to the metadata required for sending and receiving emails, which is usually not displayed in the email body; the email header includes but is not limited to the sender address, the recipient address, the subject of the email, the sending time and other information. The email header detection result refers to the result obtained after analyzing the email header content through the email header detection module, which usually includes the authenticity and security of the email header and whether it contains signs of spam or phishing emails. The email body content refers to the actual text content part contained in the email, which is usually the core of the email; the email body can include text, pictures, attachments, links, etc. The intention recognition result refers to the result obtained after analyzing the email body content through the intention recognition module; the result indicates whether the email has suspicious or malicious intentions, such as phishing, fraud, etc. The sentiment analysis result refers to the result obtained after sentiment analysis of the email body content through the sentiment analysis module; the result indicates whether there is an obvious emotional tendency (such as threat, urgency or intimidation) in the email and the intensity of the emotion. The link and QR code detection result refers to the result obtained after analyzing the links and QR codes in the email through the link and QR code detection module; the result can include whether it contains malicious links, whether it points to fraudulent websites, etc.

[0065] Furthermore, the format of the email detection report may adopt a preset report template format, or the report format may be customized by the user; the report content may include the phishing email detection conclusion and the corresponding judgment basis.

[0066] For example, to facilitate understanding of the technical solution of the present application, the phishing email detection system can be regarded as a phishing email detection team; the modules therein can be different roles defined in the team, and the specific role definitions are as follows:

[0067] Role 1: Email header detection expert (equivalent to email header detection module).

[0068] Objective: To identify suspicious content in email headers.

[0069] Description: You are an experienced email header analysis expert, and you are a member of the phishing email detection team. Your main task is to check whether the sender, recipient, and email protocol in the email header are suspicious. Suspicious situations include inconsistencies between the mail_from (actual sender) field and the from (declared sender) field, and inconsistencies between the sender address domain and the email title content. Your work is crucial, and your work results will directly affect the final detection results.

[0070] Role 2: Intent recognition expert (equivalent to intent recognition module).

[0071] Objective: To identify suspicious intent in email content.

[0072] Description: You are an experienced content intent identification expert, and you are a member of the phishing email detection team. Your main task is to identify whether the email body contains suspicious intent, such as using phishing tactics such as subsidy payment, personal tax settlement, patch update, etc. to induce recipients to click on links, reactivate accounts, etc.

[0073] Role 3: Sentiment analysis expert (equivalent to sentiment analysis module).

[0074] Objective: Analyze the sentiment characteristics of email content.

[0075] Description: You are a sentiment analysis expert with rich experience in psychology and are a member of the phishing email detection team. Your main task is to identify whether the content of the email contains suspicious emotional characteristics, such as creating a sense of urgency, threatening, tempting, impersonating relatives, friends or colleagues, and other characteristics, such as prompts for security vulnerability repairs and emergency account deactivation notifications.

[0076] Role 4: Link and QR code detection expert (equivalent to link and QR code detection module).

[0077] Objective: To detect the links or QR codes contained in the email content.

[0078] Description: You are an experienced link and QR code detection expert, and you are a member of the phishing email detection team. Your main task is to use link and QR code detection tools to identify malicious links and QR codes. Your work is crucial, and your work results will directly affect the final detection results.

[0079] Furthermore, based on the above roles, a phishing email detection task flow is constructed through the Chain of Thought (CoT) method, and the detection results of different roles are combined to determine whether the email to be detected is a phishing email, and the final phishing email detection report is generated.

[0080] The embodiment of the present application performs address verification on the email address of the email to be detected based on the email address blacklist; wherein the email address blacklist is constructed based on the email addresses of historical phishing emails; the email to be detected refers to a newly received email; if the address verification passes, the email to be detected is sent to the email sandbox system so that the email sandbox system can identify malicious files on the email to be detected; if the email sandbox system returns a normal instruction, a feature abnormality check is performed on the email to be detected; if the feature abnormality check passes, based on the thinking chain method, according to the email header detection module, the intent recognition module, the sentiment analysis module and the link and QR code detection module, a detection task flow of the phishing email detection system is constructed; the phishing email detection system is used, and according to the detection task flow, the email content of the email to be detected is detected for content abnormality to obtain an email detection report. The above technical scheme can effectively improve the accuracy of phishing email detection through multi-level and multi-dimensional phishing email detection.

[0081] Embodiment 3

[0082] Figure 3 1 is a schematic diagram of a phishing email detection device according to the third embodiment of the present application, which can be used to identify whether a newly received email is a phishing email. The phishing email detection device can be implemented in the form of hardware and / or software, and the phishing email detection device can be configured in a computer device, such as a server. Figure 3 As shown, the device comprises:

[0083] The address verification module 310 is used to perform address verification on the email address of the email to be detected based on the email address blacklist; wherein the email address blacklist is constructed based on the email addresses of historical phishing emails; the email to be detected refers to a newly received email;

[0084] The file identification module 320 is used to send the mail to be detected to the mail sandbox system when the address verification passes, so that the mail sandbox system can identify malicious files in the mail to be detected;

[0085] The feature verification module 330 is used to perform feature abnormality verification on the email to be detected when a normal instruction returned by the email sandbox system is identified;

[0086] The content detection module 340 is used to use a phishing email detection system to perform content anomaly detection on the email content of the email to be detected if the feature anomaly check passes, and obtain an email detection report.

[0087] The embodiment of the present application performs address verification on the email address of the email to be detected based on the email address blacklist; wherein the email address blacklist is constructed based on the email addresses of historical phishing emails; the email to be detected refers to a newly received email; if the address verification passes, the email to be detected is sent to the email sandbox system so that the email sandbox system can identify malicious files on the email to be detected; if the email sandbox system returns a normal instruction, the email to be detected is verified for feature anomalies; if the feature anomaly verification passes, the phishing email detection system is used to perform content anomaly detection on the email content of the email to be detected to obtain an email detection report. The above technical solution can effectively improve the accuracy of phishing email detection through multi-level and multi-dimensional phishing email detection.

[0088] Optionally, the phishing email detection system includes an email header detection module, an intent recognition module, a sentiment analysis module, and a link and QR code detection module; the email content includes the email header content, email body content, links, and QR codes.

[0089] Optionally, the content detection module 340 includes:

[0090] The task flow construction unit is used to construct the detection task flow of the phishing email detection system based on the thought chain method, according to the email header detection module, the intent recognition module, the sentiment analysis module, and the link and QR code detection module;

[0091] The content detection unit is used to use the phishing email detection system to perform content anomaly detection on the email content of the email to be detected according to the detection task flow, and obtain an email detection report.

[0092] Optionally, the content detection unit is specifically used to:

[0093] The mail header detection module is used to verify the content of the mail header of the mail to be detected and obtain the mail header detection result;

[0094] The intent recognition module is used to identify suspicious intents in the email body of the email to be detected, and the intent recognition result is obtained;

[0095] The sentiment analysis module is used to analyze the sentiment characteristics of the email body content of the email to be detected, and the sentiment analysis result is obtained;

[0096] Use the link and QR code detection module to perform content detection on the link and QR code in the email to be detected, and obtain the link and QR code detection results;

[0097] The email header detection results, intent recognition results, sentiment analysis results, and link and QR code detection results are integrated to obtain an email detection report.

[0098] Optionally, the feature verification module 330 is specifically used for:

[0099] Based on the machine learning model, feature extraction is performed on the emails to be detected to obtain the features to be detected;

[0100] The consistency of the features to be detected is checked with the abnormal feature set; wherein the abnormal feature set is obtained by extracting features from historical phishing emails through a multi-channel large model.

[0101] Optionally, the phishing email detection system is built based on a fine-tuned phishing email detection model and a multi-agent system; the fine-tuned phishing email detection model is obtained by fine-tuning a general large model or a security vertical large model based on a phishing email sample data set; the phishing email sample data set is determined based on historical phishing emails.

[0102] The phishing email detection device provided in the embodiments of the present application can execute the phishing email detection method provided in any embodiment of the present application, and has the corresponding functional modules and beneficial effects for executing each phishing email detection method.

[0103] According to an embodiment of the present application, the present application also provides an electronic device, a readable storage medium and a computer program product.

[0104] Embodiment 4

[0105] Figure 4 4 is a schematic diagram of the structure of an electronic device 410 that implements the phishing email detection method of an embodiment of the present application. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workbenches, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or required herein.

[0106] like Figure 4As shown, the electronic device 410 includes at least one processor 411, and a memory connected to the at least one processor 411 in communication, such as a read-only memory (ROM) 412, a random access memory (RAM) 413, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 411 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 412 or the computer program loaded from the storage unit 418 to the random access memory (RAM) 413. In RAM413, various programs and data required for the operation of the electronic device 410 can also be stored. The processor 411, ROM412 and RAM413 are connected to each other via a bus 414. An input / output (I / O) interface 415 is also connected to the bus 414.

[0107] Multiple components in the electronic device 410 are connected to the I / O interface 415, including: an input unit 416, such as a keyboard, a mouse, etc.; an output unit 417, such as various types of displays, speakers, etc.; a storage unit 418, such as a disk, an optical disk, etc.; and a communication unit 419, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 419 allows the electronic device 410 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0108] The processor 411 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 411 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 411 executes the various methods and processes described above, such as a phishing email detection method.

[0109] In some embodiments, the phishing email detection method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 418. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 410 via the ROM 412 and / or the communication unit 419. When the computer program is loaded into the RAM 413 and executed by the processor 411, one or more steps of the phishing email detection method described above may be performed. Alternatively, in other embodiments, the processor 411 may be configured as the phishing email detection method in any other appropriate manner (e.g., by means of firmware).

[0110] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0111] The computer programs for implementing the methods of the present application may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable phishing email detection device, so that when the computer programs are executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer programs may be executed entirely on the machine, partially on the machine, partially on the machine as a stand-alone software package and partially on a remote machine, or entirely on a remote machine or server.

[0112] In the context of the present application, a computer readable storage medium may be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, device or equipment. A computer readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer readable storage medium may be a machine readable signal medium. A more specific example of a machine readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0113] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0114] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0115] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.

[0116] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this application can be executed in parallel, sequentially or in different orders, as long as the expected results of the technical solution of this application can be achieved, and this document is not limited here.

[0117] The above specific implementations do not constitute a limitation on the protection scope of this application. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principles of this application should be included in the protection scope of this application.

Claims

1. A method for detecting phishing emails, characterized in that: include: Based on the email address blacklist, the email address of the email to be detected is verified; wherein the email address blacklist is constructed based on the email addresses of historical phishing emails; the email to be detected refers to a newly received email; If the address verification passes, the mail to be detected is sent to the mail sandbox system, so that the mail sandbox system can identify malicious files on the mail to be detected; When a normal instruction is identified to be returned by the email sandbox system, a feature abnormality check is performed on the email to be detected; If the feature anomaly check passes, a phishing email detection system is used to perform content anomaly detection on the email content of the email to be detected to obtain an email detection report.

2. The method according to claim 1, characterized in that The phishing email detection system includes an email header detection module, an intent recognition module, a sentiment analysis module, and a link and QR code detection module; the email content includes email header content, email body content, links, and QR codes.

3. The method according to claim 2, characterized in that A phishing email detection system is used to perform content anomaly detection on the email content of the email to be detected, and an email detection report is obtained, including: Based on the chain thinking method, the detection task flow of the phishing email detection system is constructed according to the email header detection module, the intention recognition module, the sentiment analysis module and the link and QR code detection module; The phishing email detection system is used to perform content anomaly detection on the email content of the email to be detected according to the detection task flow to obtain an email detection report.

4. The method according to claim 3, characterized in that The phishing email detection system is used to perform content anomaly detection on the email content of the email to be detected according to the detection task flow, and an email detection report is obtained, including: Using the mail header detection module, verify the content of the mail header of the mail to be detected to obtain the mail header detection result; Using the intention recognition module, the suspicious intention of the email body content of the email to be detected is recognized to obtain an intention recognition result; Using the sentiment analysis module, the sentiment feature analysis is performed on the email body content of the email to be detected to obtain a sentiment analysis result; Using the link and QR code detection module, the link and QR code in the email to be detected are detected to obtain link and QR code detection results; The email header detection result, the intent recognition result, the sentiment analysis result and the link and QR code detection result are integrated to obtain an email detection report.

5. The method according to claim 1, characterized in that Based on the email address blacklist, the email address to be tested is verified, including: Based on the email address blacklist, filter rules are set in the email gateway; wherein the filter rules refer to checking the consistency between the email address of the email to be detected and the email address blacklist; When the email to be detected is received, an address check is performed on the email address of the email to be detected based on the filtering rule.

6. The method according to claim 1, characterized in that Performing feature anomaly check on the email to be detected, including: Based on the machine learning model, feature extraction is performed on the email to be detected to obtain features to be detected; The features to be detected are checked for consistency with an abnormal feature set; wherein the abnormal feature set is obtained by extracting features from the historical phishing emails using a multi-channel large model.

7. The method according to claim 1, characterized in that The phishing email detection system is constructed based on a fine-tuned phishing email detection model and a multi-agent system; the fine-tuned phishing email detection model is obtained by fine-tuning a general large model or a security vertical large model based on a phishing email sample data set; The phishing email sample data set is determined based on the historical phishing emails.

8. A phishing email detection device, characterized in that: include: An address verification module, used to perform address verification on the email address of the email to be detected based on the email address blacklist; wherein the email address blacklist is constructed based on the email addresses of historical phishing emails; the email to be detected refers to a newly received email; A file identification module is used to send the mail to be detected to the mail sandbox system when the address verification passes, so that the mail sandbox system can identify malicious files on the mail to be detected; A feature verification module, configured to perform feature abnormality verification on the email to be detected when a normal instruction returned by the email sandbox system is identified; The content detection module is used to use a phishing email detection system to perform content anomaly detection on the email content of the email to be detected if the feature anomaly check passes, and obtain an email detection report.

9. An electronic device, characterized in that: include: one or more processors; A memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the phishing email detection method as described in any one of claims 1-7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the phishing email detection method as described in any one of claims 1-7 is implemented.

11. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the phishing email detection method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Phishing mail detection method and device, electronic equipment and storage medium

    CN110868378A

  • Phishing mail detection method and device, electronic equipment and storage medium

    CN115473676A

  • Phishing and threat detection and prevention

    US20160057167A1

  • Message phishing detection using machine learning characterization

    US20220210188A1

  • Incident detecting and responding method on email services

    WO2020060505A1

Cited By

  • Multi-dimensional analysis-based phishing mail detection method, apparatus and device, and medium

    CN120675792A