E-mail risk detection method and device
By integrating the detection methods of email headers, texts and attachments, combined with dynamic adjustment of scoring rules and thresholds, the problem of traditional email risk detection methods being single and high false alarm rates is solved, and more efficient and accurate email risk detection is achieved.
Patent Information
- Application Number
- CN202410899385.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-05
- Publication Date
- 2025-05-27
AI Technical Summary
The traditional email risk detection method has a single detection method, which leads to a low detection accuracy rate, which is prone to false alarms or missed reports. The detection process is lengthy and consumes computing resources, so it is impossible to effectively deal with new email attacks.
Email risk detection methods that combine multiple detection methods, including the detection of email head, text and attachments. Through the comprehensive scores and thresholds of head detection, text detection and attachment detection, we will judge whether to intercept, and monitor the network environment and email traffic in real time, and dynamically adjust the scoring rules and thresholds to deal with emergencies of security threats.
It effectively reduces the false alarm rate of phishing email detection, solves the problem of high false alarm rate of traditional email gateways for phishing email detection, improves detection accuracy and efficiency, and can deal with sudden security threats in real time.
Smart Images

Figure CN120050057A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of network security and information security, and in particular, to an email risk detection method and device. Background Art
[0002] For enterprises, maintaining their own network security is extremely important. Currently, network security incidents of illegal intrusion using emails occur frequently, so the protection against email risks is particularly important.
[0003] Traditional email risk detection methods have a single detection method. Some only detect through attachments or email header information, with a low detection accuracy rate, and are prone to false positives or false negatives. False negatives will result in employees being successfully attacked by hackers, while false positives will affect normal email sending and receiving and have an impact on the business. And some methods need to check all information including header information, body information, attachment information, etc. of the email before judging the risk, and the whole process is long and consumes computing resources. Moreover, new email attacks often combine with current events information, and induce users to take the bait through the body information of a certain popular disease at that time. Therefore, enterprises urgently need a new email risk detection method. Summary of the Invention
[0004] In view of this, the present invention provides an email risk detection method and device to solve at least one of the above-mentioned problems.
[0005] To achieve the above object, the present invention adopts the following solutions:
[0006] According to a first aspect of the present invention, there is provided an email risk detection method, the method comprising: performing email header detection on the received email; updating a first comprehensive score of the email according to the email header detection result, and determining whether to intercept according to the first comprehensive score and a first preset score threshold; in response to not intercepting based on the first comprehensive score, continuing to perform email body detection on the email; updating a second comprehensive score of the email according to the email body detection result, and determining whether to intercept according to the second comprehensive score and a second preset score threshold; in response to not intercepting based on the second comprehensive score, continuing to perform email attachment detection on the email; updating a third comprehensive score of the email according to the email attachment detection result, and determining whether to intercept according to the third comprehensive score and a third preset score threshold.
[0007] As an embodiment of the present invention, the email header detection in the above method includes: detecting whether the email sender is in a trusted list or an untrusted list; detecting whether the email domain name is in a trusted domain name or an untrusted domain name; detecting whether the email domain name belongs to a forged domain name.
[0008] As an embodiment of the present invention, in the above method, detecting whether the email domain name belongs to a forged domain name includes: calculating the similarity between the email domain name and the company's own domain name, trusted domain names, and authoritative domain names; determining whether the similarity exceeds a preset threshold, and if it does, the email domain name belongs to a forged domain name.
[0009] As an embodiment of the present invention, in the above method, the email body detection includes: comparing the email body with the built-in feature library and determining the probability that the email belongs to a risky email based on the comparison result.
[0010] As an embodiment of the present invention, in the above method, the email attachment detection includes: detecting the suffix name of the email attachment; performing static analysis on the email attachment to determine its risk index; and placing the email attachment in a sandbox for execution to perform dynamic analysis of its risk index.
[0011] As an embodiment of the present invention, the above method further includes: real-time monitoring of the network environment and email traffic to detect potential security events; when a specific security event is detected, automatically adjusting the scoring rules of the first comprehensive score, the second comprehensive score, and the third comprehensive score, as well as the values of the first preset score threshold, the second preset score threshold, and the third preset score threshold to cope with sudden security threats.
[0012] As an embodiment of the present invention, the above method further includes: continuously collecting user feedback data; according to the analysis result of the user feedback data, automatically adjusting the scoring rules of the first comprehensive score, the second comprehensive score, and the third comprehensive score, as well as the values of the first preset score threshold, the second preset score threshold, and the third preset score threshold to improve the detection accuracy.
[0013] According to a second aspect of the present invention, there is provided an email risk detection device, the device includes: a header detection unit for performing email header detection on the received email; a first interception unit for updating the first comprehensive score of the email according to the email header detection result and determining whether to intercept according to the first comprehensive score and the first preset score threshold; a body detection unit for, in response to the first interception unit not intercepting based on the first comprehensive score, continuing to perform email body detection on the email; a second interception unit for updating the second comprehensive score of the email according to the email body detection result and determining whether to intercept according to the second comprehensive score and the second preset score threshold; an attachment detection unit for, in response to the second interception unit not intercepting based on the second comprehensive score, continuing to perform email attachment detection on the email; a third interception unit for updating the third comprehensive score of the email according to the email attachment detection result and determining whether to intercept according to the third comprehensive score and the third preset score threshold.
[0014] As an embodiment of the present invention, the above-mentioned header detection unit includes: a sender detection module for detecting whether the email sender is in the trusted list or the untrusted list; a domain name detection module for detecting whether the email domain name is in the trusted domain name or the untrusted domain name, and detecting whether the email domain name belongs to a forged domain name.
[0015] As an embodiment of the present invention, the above-mentioned domain name detection module detecting whether the email domain name belongs to a forged domain name includes: calculating the similarity between the email domain name and its own company domain name, trusted domain names, and authoritative domain names; determining whether the similarity exceeds a preset threshold, and if it exceeds, the email domain name belongs to a forged domain name.
[0016] As an embodiment of the present invention, the above-mentioned body detection unit performing email body detection includes: comparing the email body with the built-in feature library, and determining the probability that the email belongs to a risky email based on the comparison result.
[0017] As an embodiment of the present invention, the above-mentioned attachment detection unit includes: a suffix detection module for detecting the suffix name of the email attachment; a static analysis module for performing static analysis on the email attachment to determine its risk index; a dynamic analysis module for putting the email attachment into a sandbox for execution to perform dynamic analysis of its risk index.
[0018] As an embodiment of the present invention, the above-mentioned device further includes: a real-time monitoring unit for real-time monitoring of the network environment and email traffic to detect potential security events; a first automatic adjustment unit for automatically adjusting the scoring rules of the first comprehensive score, the second comprehensive score, and the third comprehensive score, and the values of the first preset score threshold, the second preset score threshold, and the third preset score threshold when a specific security event is detected to cope with sudden security threats.
[0019] As an embodiment of the present invention, the above-mentioned device further includes: a feedback collection unit for continuously collecting user feedback data; a second automatic adjustment unit for automatically adjusting the scoring rules of the first comprehensive score, the second comprehensive score, and the third comprehensive score, and the values of the first preset score threshold, the second preset score threshold, and the third preset score threshold according to the analysis result of the user feedback data to improve the detection accuracy.
[0020] According to the third aspect of the present invention, there is provided an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the computer program, the steps of the above-mentioned method are implemented.
[0021] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0022] As can be seen from the above technical solutions, the email risk detection method and device provided by the present invention effectively reduce the false alarm rate of phishing email detection by integrating various detection means, and solve the problem of high false alarm rate of phishing email detection by traditional email gateways. By triggering the dynamic adjustment of scoring rules and thresholds through security events and user feedback, the system can respond to sudden security threats in real time, further improving the detection accuracy and efficiency. Finally, after each detection unit completes the detection, the present application can immediately evaluate the current comprehensive score and make a preliminary decision according to the preset threshold, improving the detection efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to these drawings. In the drawings:
[0024] Figure 1 is a flowchart of an email risk detection method provided by an embodiment of the present invention;
[0025] Figure 2 is a flowchart of a mail header detection method provided by an embodiment of the present invention;
[0026] Figure 3 is a flowchart of a mail attachment detection method provided by an embodiment of the present invention;
[0027] Figure 4 is a flowchart of the dynamic adjustment of scoring rules and thresholds provided by an embodiment of the present invention;
[0028] Figure 5 is a flowchart of the dynamic adjustment of scoring rules and thresholds provided by another embodiment of the present invention;
[0029] Figure 6 is a structural diagram of an email risk detection device provided by an embodiment of the present invention;
[0030] Figure 7 is a structural diagram of a header detection unit provided by an embodiment of the present invention;
[0031] Figure 8 is a structural diagram of an attachment detection unit provided by an embodiment of the present invention;
[0032] Figure 9 It is a schematic block diagram of the system composition of the electronic device provided by the invention embodiment. Specific embodiments
[0033] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer and more understandable, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings. Herein, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but not to limit the present invention.
[0034] Since the detection methods of traditional email risk detection are single, some only detect through attachment or email header information, and the detection accuracy rate is relatively low, which is prone to false positives or false negatives. False negatives will lead to successful hacker attacks on employees, while false positives will affect normal email sending and receiving and have an impact on business. There are also some methods that need to check all information including header information, body information, attachment information, etc. of the email before judging the risk, and the whole process is long and consumes computing resources. Therefore, the purpose of this application is to provide an email risk detection method and device, which can solve the above technical problems in the prior art.
[0035] As Figure 1 shown is a schematic flowchart of an email risk detection method provided by an embodiment of the present invention. This embodiment describes this application from the perspective of the enterprise's email system side. The method includes the following steps:
[0036] Step S101: Perform email header detection on the received email.
[0037] Generally, the emails we receive can be divided into three parts: email header, email body, and email attachment. Therefore, this application also starts from these three parts to detect the risk of emails.
[0038] In this step, first perform email header detection on the received email. The email header generally includes the following parts: sender, recipient, carbon copy, blind carbon copy, subject, date, message ID, reply address, sending server, email priority, etc. These parts together constitute the information of the email header, which is used to describe the basic attributes and transmission path of the email.
[0039] Preferably, as Figure 2 shown, the above email header detection method in this embodiment can further include the following sub-steps:
[0040] Step S1011: Detect whether the email sender is in the trusted list or the untrusted list.
[0041] This step evaluates the credibility of an email by checking whether the sender is on a pre-set trusted list or untrusted list. If the sender is on the trusted list, the score of the email increases; if the sender is on the untrusted list, the score of the email decreases; if the sender is neither on the trusted list nor on the untrusted list, the score remains medium. Here, both the trusted list and the untrusted list are pre-set and can be increased or decreased as needed.
[0042] Step S1012: Detect whether the email domain name is among the trusted domain names or untrusted domain names.
[0043] The domain name of the email also appears in the sender information. The above step S1011 performs detection by checking all fields of the sender, while this step only checks the domain name part in the sender information. This step evaluates the credibility of the email by checking whether the domain name of the sending email is in a pre-set trusted domain name list or untrusted domain name list. If the domain name is in the trusted domain name list, the score of the email increases; if the domain name is in the untrusted domain name list, the score of the email decreases; if the domain name is neither in the trusted domain name nor in the untrusted domain name, the score remains medium.
[0044] Step S1013: Detect whether the email domain name belongs to a forged domain name.
[0045] This step can calculate the similarity between the email domain name and the company's own domain name, trusted domain names, and authoritative domain names, and then determine whether the similarity exceeds a preset threshold. If it exceeds, the email domain name belongs to a forged domain name.
[0046] For example, string similarity algorithms (such as Levenshtein distance, Jaccard similarity coefficient, etc.) can be used to calculate the similarity between the email domain name and the company's own domain name, trusted domain names, and authoritative domain names. Then, the calculated similarity is compared with the preset similarity threshold. If the similarity exceeds the preset threshold, it is determined that the email domain name is a forged domain name. If the email domain name is determined to be a forged domain name, the email is deducted points according to the rules. In this way, forged domain names can be effectively identified, improving the accuracy and security of high-risk email detection.
[0047] When detecting the email header, in addition to the sender detection module, sending email detection module, and email forgery identification module mentioned in this application, the following several risk detections can also be performed:
[0048] In addition to detecting the email header in the above manner, this application can also perform the following detections on the email header:
[0049] 1. Sender Policy Framework (SPF) Detection: Check whether the email has passed the SPF verification. The SPF record is part of the Domain Name System (DNS) and is used to prevent email address forgery. Emails that pass the SPF verification are more trustworthy.
[0050] 2. DomainKeys Identified Mail (DKIM) Detection: Check whether the email has passed the DKIM signature verification. DKIM uses an encrypted signature to verify the origin and integrity of the email, ensuring that the email has not been tampered with during transmission.
[0051] 3. Email Path Analysis: Analyze the Received field in the email header to check whether the email's transmission path contains suspicious or untrustworthy servers. An abnormal email path may indicate that the email has been subject to a man-in-the-middle attack or forgery.
[0052] 4. Timestamp Consistency Check: Check whether the timestamps in the email header are consistent. For example, whether the email's sending time and receiving time are reasonable and whether there are signs of tampering with the timestamps.
[0053] 5. Reverse DNS Lookup: Perform a reverse DNS lookup on the IP address of the sending server to verify whether its domain name is consistent with the sending domain name in the email header. Inconsistency may indicate that the email source is suspicious.
[0054] Through these additional risk detections and corresponding scoring of various detection results, the accuracy and security of email header detection can be further improved, effectively identifying and intercepting various high-risk emails.
[0055] Step S102: Update the first comprehensive score of the email according to the email header detection result, and determine whether to intercept according to the first comprehensive score and the first preset score threshold.
[0056] In this step, according to the preset scoring rules, the email header detection result can be scored and the first comprehensive score of the email can be updated. Then, the updated first comprehensive score is compared with the first preset score threshold. If the first comprehensive score reaches or exceeds the first preset score threshold, it is determined that the email needs to be intercepted. If the first comprehensive score does not reach the first preset score threshold, the email continues to be passed to the next detection unit for further detection. In this way, a preliminary judgment can be made on the email at an early stage, improving the detection efficiency and accuracy.
[0057] Step S103: In response to not intercepting based on the first comprehensive score, continue to perform email body detection on the email.
[0058] When the system determines not to intercept based on the first comprehensive score, it continues to perform email body detection on the said email. Email body detection analyzes the content of the email body and uses the built-in feature library and user-defined content information to identify the content of suspected risky emails. The feature library here includes the features of common risky emails and the latest factual information (such as security drills, etc.). This application can evaluate the matching degree between the email body and the features of risky emails in the feature library, and based on the matching degree, judge the probability that the email belongs to a risky email. If the email body highly matches the risky features in the feature library, then the email is determined to be a high-risk email, and corresponding points can be deducted from the email according to the corresponding rules.
[0059] Step S104: Update the second comprehensive score of the email according to the email body detection result, and determine whether to intercept based on the second comprehensive score and the second preset score threshold.
[0060] This step is the same as step S102. According to the preset scoring rules, the email body detection result can be scored, and the second comprehensive score of the email can be updated. The second comprehensive score is an update based on the above first comprehensive score, and the updated second comprehensive score is compared with the second preset score threshold. If the second comprehensive score reaches or exceeds the second preset score threshold, it is determined that the email needs to be intercepted. If the first comprehensive score does not reach the second preset score threshold, the email continues to be passed to the next detection unit for further detection. It should be noted that the second preset score threshold here can be set to the same score as the above first preset score threshold, or can be set to a different score. This application does not limit this and can be flexibly adopted according to actual needs. In this way, a preliminary judgment can be made on the email in the early stage, improving the detection efficiency and accuracy.
[0061] Step S105: In response to not intercepting based on the second comprehensive score, continue to perform email attachment detection on the said email.
[0062] When the system determines not to intercept based on the second comprehensive score, it continues to perform email attachment detection on the said email.
[0063] Preferably, as Figure 3 shown, this step can further include the following sub-steps:
[0064] Step S1051: Detect the suffix name of the email attachment.
[0065] In this step, the system first detects the file extension of the email attachment. File extensions are usually used to identify the type of a file. For example, ".exe" indicates an executable file, ".docx" indicates a Word document, ".pdf" indicates a PDF file, etc. By detecting the attachment's extension, the system can preliminarily determine the type of the attachment and take corresponding security measures according to different types of files.
[0066] The specific operation steps are as follows: First, extract the file extension from the file name of the email attachment. For example, for the file name "document.pdf", the extension ".pdf" is extracted. Then, compare the extracted file extension with the system's pre-set trusted list. If the extension is in the trusted list, it is considered that the attachment type is relatively safe, and the system can give it appropriate bonus points. Compare the extracted file extension with the system's pre-set untrusted list. If the extension is in the untrusted list, it is considered that the attachment type has a relatively high risk, and the system will deduct points for it. For example, extensions such as ".exe" and ".bat" are usually considered high-risk file types. For unknown extensions that are not in the trusted list and the untrusted list, the system will mark them as objects that need further analysis and handle them appropriately according to the rules. Through the above steps, the system can preliminarily judge the potential risks of email attachments and provide basic information for subsequent static analysis and dynamic analysis.
[0067] Step S1052: Perform static analysis on the email attachment to determine its risk index.
[0068] The system performs static analysis on the email attachment to determine its potential security risks. Static analysis refers to the process of identifying possible malicious behaviors or characteristics by examining the content and structure of a file without executing the file.
[0069] First, extract the file features of the email attachment, including but not limited to file size, file hash values (such as MD5, SHA-256), file header information, file metadata, etc. These features can help identify the type and source of the file.
[0070] Then, compare the extracted file features with a known malicious feature library. The malicious feature library contains the feature information of known malware, such as specific byte sequences, abnormal file structures, suspicious strings, etc. If the file features match some features in the malicious feature library, it is considered that the file may have risks.
[0071] Next, check whether the file contains a digital signature and verify the validity of the signature. Legitimate software usually contains a digital signature issued by a trusted certificate authority. If the digital signature of the file is invalid or missing, there may be risks.
[0072] If the attachment is a compressed package (such as ZIP, RAR, etc.), the system will decompress the file and perform static analysis on each file therein. Additionally, if there are other files nested within the file (such as embedded objects in an Office document), the system will also analyze the nested files.
[0073] Based on the results of the static analysis, the system assigns a risk index to the attachment. The risk index can be calculated comprehensively based on multiple factors, such as the quantity and severity of malicious feature matches, the validity of digital signatures, the degree of abnormality of the file structure, etc.
[0074] Through the above steps, the system can preliminarily judge the potential risks of email attachments without executing the files, and provide a reference basis for subsequent dynamic analysis. The results of the static analysis will be part of the comprehensive score.
[0075] Step S1053: Put the email attachment into a sandbox for execution to dynamically analyze its risk index.
[0076] In this step, the system executes the email attachment in a sandbox environment to observe its behavior and judge its potential security risks. Dynamic analysis refers to actually executing the file in a controlled environment to detect its runtime behavior and characteristics.
[0077] A sandbox is an isolated virtual environment used to securely execute and analyze suspicious files. The system will prepare a clean sandbox environment to ensure there are no other interfering factors. Then the email attachment is placed in the sandbox for execution. The sandbox environment will simulate the real operating system and user behavior to observe all operations of the file during execution. During the execution of the file, the sandbox system will monitor its behavior in real time, including but not limited to the following aspects:
[0078] 1. File operations: Monitor whether the file creates, modifies, or deletes other files or directories.
[0079] 2. Registry operations: Monitor whether the file reads from or writes to the system registry.
[0080] 3. Network activities: Monitor whether the file attempts to connect to an external network, send, or receive data.
[0081] 4. Processes and threads: Monitor whether the file creates new processes or threads and their behavior.
[0082] 5. System calls: Monitor whether the file calls specific system APIs or functions.
[0083] 6. Malicious behavior detection: According to preset rules and a feature library, detect whether the file exhibits malicious behavior during execution. For example, attempting to download other malware, recording keyboard input, hijacking system resources, etc.
[0084] Finally, based on the behavior of the file executed in the sandbox, the system assigns it a risk index. The risk index can be comprehensively calculated based on multiple factors, such as the quantity and severity of malicious behaviors, the suspiciousness of network activities, the scope of system modifications, etc.
[0085] Record the results of dynamic analysis, and based on the results of static and dynamic analysis, comprehensively calculate the final risk index of the email attachment.
[0086] Step S106: Update the third comprehensive score of the email according to the email attachment detection result, and determine whether to intercept according to the third comprehensive score and the third preset score threshold.
[0087] According to the result transmitted by the email attachment detection unit, update the third comprehensive score of the email. The third comprehensive score is a score calculated based on the second comprehensive score after comprehensively considering the results of static and dynamic analysis of the email attachment. Compare the third comprehensive score with the preset third score threshold. The third preset score threshold is a score set by the system or the administrator, used to determine whether the email should be intercepted. If the third comprehensive score reaches or exceeds the third preset score threshold, the system determines that the email attachment has a high risk and decides to intercept the email. If the third comprehensive score is lower than the third preset score threshold, the system determines that the risk of the email attachment is low and decides not to intercept the email. If it is decided to intercept the email, the system will prevent the email from reaching the recipient and may mark it as a high-risk email or a malicious email. If it is decided not to intercept the email, the system will allow the email to be normally delivered to the recipient. Similarly, the third preset score threshold here can be set to the same score as the above first preset score threshold and second preset score threshold, or can be set to different scores. This application does not limit this and can be flexibly adopted according to actual needs.
[0088] Preferably, in addition to the detection of the above three parts of the email header, email body, and email attachment, the email risk detection method of this embodiment can also include context correlation analysis detection, that is, by performing correlation analysis on each part of the email (such as email body, email header information, attachment content, link address, etc.) and comparing it with historical data, so as to more accurately judge the risk of the email. The following is a detailed description of this method:
[0089] 1. Correlation analysis
[0090] 1.1. Association analysis of combining email header information and body, including: Associating the sender information with the email body content. For example, if the sender is a frequent contact but the email body contains phishing characteristics, the credibility of the email needs to be further verified. Associating the sender email domain name with the email body content. For example, if the sender email domain name is inconsistent with the company information mentioned in the email body, it may be a phishing email. Associating the email subject with the email body content. For example, if the email subject does not match the body content, it may be a risky email.
[0091] 1.2. Association analysis of email body and attachments, including: Analyzing whether the attachment type mentioned in the email body is consistent with the actual attachment type. For example, if the body mentions a PDF file but the attachment is an executable file (such as.exe), there is a risk. Analyzing the attachment content and the body content. If the attachment is a text file, the attachment content can be scanned to check whether it is consistent with the body content. For example, whether the contract content mentioned in the body is consistent with the contract in the attachment.
[0092] 1.3. Association analysis of email body and link addresses, including: Checking whether the link address mentioned in the email body is consistent with the actual link address. For example, the link mentioned in the body is a well-known website, but the actual link address is an unrelated domain name. Threat intelligence analysis of the link address, performing threat intelligence analysis on the link address in the email to check whether it is on the blacklist or whether it points to a known risky website.
[0093] 2. Historical data comparison
[0094] 2.1. Historical comparison of email header information, including: Checking whether the sender has ever sent similar emails. If the sender has never sent similar content emails, it needs to be vigilant. Checking the historical record of the sender email domain name and analyzing whether the sender email domain name has ever been used to send risky emails. If the domain has a bad record, its credibility is reduced.
[0095] 2.2. Historical comparison of email body, including: Similarity analysis of the body content, that is, performing similarity analysis on the current email body and historical email bodies to identify abnormal or suspicious emails. For example, if a large number of similar email bodies suddenly appear, it may be a phishing attack. Historical comparison of keywords and phrases, that is, checking whether the email body contains common phishing keywords and phrases in history. If it does, its risk score is increased.
[0096] 2.3 Historical comparison of attachment content, including: checking the historical records of attachment types, analyzing whether the attachment types are consistent with those in historical emails. For example, if a sender usually sends PDF files but sends an executable file this time, it is necessary to be vigilant. Similarity analysis of attachment content, that is, performing similarity analysis on the attachments in the current email and those in historical emails to identify abnormal or suspicious attachment content.
[0097] 2.4 Historical comparison of link addresses, including: checking the historical records of link addresses, that is, checking whether the link addresses in the email have ever appeared in historical emails. If a link address has never appeared before, it is necessary to further analyze its risk. Checking the access records of link addresses, that is, analyzing the historical access records of users to this link address. If this link address has caused security incidents, increase its risk score.
[0098] 3. Comprehensive judgment of the risk of the email
[0099] Through the above-mentioned correlation analysis and historical data comparison, the risk of the email can be comprehensively judged. That is, according to the results of the correlation analysis and historical data comparison, a comprehensive score is given to judge the risk level of the email. According to the comprehensive score results, decide whether to intercept, mark or release the email. Through this comprehensive context correlation analysis method, phishing emails can be more accurately identified, improving the accuracy and reliability of detection.
[0100] As can be seen from the above technical solutions, the email risk detection method provided by the present invention effectively reduces the false positive rate of phishing email detection by integrating multiple detection means, and solves the problem of high false positive rate of phishing email detection by traditional email gateways. Moreover, after each detection unit completes the detection, the present application can immediately evaluate the current comprehensive score and make a preliminary decision according to the preset threshold, improving the detection efficiency.
[0101] Preferably, the above-mentioned email risk detection method of the present invention also has a mechanism for dynamically adjusting the scoring rules and thresholds, such as Figure 4 shown, the above method further includes:
[0102] Step S401: Real-time monitor the network environment and email traffic to detect potential security incidents.
[0103] Through means such as network traffic analysis and email log analysis, the system real-time monitors the running status of the email system and the network environment to detect potential security incidents. Using preset security incident detection rules, abnormal behaviors or large-scale attacks can be identified. For example, the sending of a large number of similar emails in a short period of time, a sharp increase in malicious links contained in emails, etc.
[0104] Step S402: When a specific security event is detected, automatically adjust the scoring rules for the first comprehensive score, the second comprehensive score, and the third comprehensive score, as well as the values of the first preset score threshold, the second preset score threshold, and the third preset score threshold, to cope with sudden security threats.
[0105] When a specific security event is detected, the system will automatically adjust the scoring rules of each detection unit according to the severity and characteristics of the event. For example, increase the deduction weight of senders on the untrusted list in email header detection, or increase the detection sensitivity to specific keywords. In addition, this application can also automatically adjust the scoring threshold of the comprehensive scoring control unit according to the urgency of the event. For example, during a large-scale attack, lower the interception threshold to increase the interception rate.
[0106] Through the above steps, the system can monitor the network environment and email traffic in real time, detect potential security events in a timely manner, and automatically adjust the scoring rules and thresholds according to the detected security events. This dynamic adjustment mechanism can effectively cope with sudden security threats and improve the accuracy and flexibility of risk email detection.
[0107] Further preferably, as Figure 5 shown, the above email risk detection method of the present invention also has a feedback adjustment mechanism, which includes:
[0108] Step S501: Continuously collect user feedback data.
[0109] Through the email client or the management background, the system continuously collects user feedback on the email detection results. For example, users can mark normal emails that are misreported or risk emails that are missed.
[0110] Step S502: According to the analysis results of the user feedback data, automatically adjust the scoring rules for the first comprehensive score, the second comprehensive score, and the third comprehensive score, as well as the values of the first preset score threshold, the second preset score threshold, and the third preset score threshold, to improve detection accuracy.
[0111] Statistically analyze the collected feedback data, calculate the false positive rate and the missed detection rate, and identify the detection rules and thresholds that need to be adjusted. On the one hand, according to the analysis results of the false positive rate and the missed detection rate, the scoring rules for the first comprehensive score, the second comprehensive score, and the third comprehensive score can be automatically adjusted. For example, reduce the deduction weight for some common false positive features, or increase the detection sensitivity to missed detection features. On the other hand, according to the changing trends of the false positive rate and the missed detection rate, the values of the first preset score threshold, the second preset score threshold, and the third preset score threshold can be automatically adjusted. For example, when the false positive rate is high, increase the interception threshold to reduce false positives; when the missed detection rate is high, lower the interception threshold to increase the interception rate.
[0112] Through the above feedback adjustment mechanism, the system can continuously optimize the detection rules and thresholds, further improving the accuracy and flexibility of risk email detection.
[0113] As Figure 6 shown in the structural schematic diagram of an email risk detection device provided by an embodiment of the present application, the device includes: a header detection unit 610, a first interception unit 620, a body detection unit 630, a second interception unit 640, an attachment detection unit 650, and a third interception unit 660, which are connected in sequence. Among them:
[0114] The header detection unit 610 is configured to perform email header detection on the received email.
[0115] The first interception unit 620 is configured to update the first comprehensive score of the email according to the email header detection result, and determine whether to intercept according to the first comprehensive score and the first preset score threshold.
[0116] The body detection unit 630 is configured to continue to perform email body detection on the email in response to the first interception unit not intercepting based on the first comprehensive score.
[0117] The second interception unit 640 is configured to update the second comprehensive score of the email according to the email body detection result, and determine whether to intercept according to the second comprehensive score and the second preset score threshold.
[0118] The attachment detection unit 650 is configured to continue to perform email attachment detection on the email in response to the second interception unit not intercepting based on the second comprehensive score.
[0119] The third interception unit 660 updates the third comprehensive score of the email according to the email attachment detection result, and determines whether to intercept according to the third comprehensive score and the third preset score threshold.
[0120] Preferably, as Figure 7 shown, the above header detection unit 610 includes: a sender detection module 611, configured to detect whether the email sender is in the trusted list or the untrusted list; a domain name detection module 612, configured to detect whether the email domain name is in the trusted domain name or the untrusted domain name, and detect whether the email domain name belongs to a forged domain name.
[0121] Preferably, the domain name detection module 612 detecting whether the email domain name belongs to a forged domain name includes: calculating the similarity between the email domain name and its own company domain name, the trusted domain name, and the authoritative domain name; determining whether the similarity exceeds a preset threshold, and if it exceeds, the email domain name belongs to a forged domain name.
[0122] Preferably, the email body detection unit 630 performs email body detection including: comparing the email body with a built-in feature library and judging the probability that the email belongs to a risky email based on the comparison result.
[0123] Preferably, as Figure 8 shown, the above attachment detection unit 650 includes: a suffix detection module 651 for detecting the suffix name of the email attachment; a static analysis module 652 for performing static analysis on the email attachment to judge its risk index; and a dynamic analysis module 653 for putting the email attachment into a sandbox for execution to perform dynamic analysis of its risk index.
[0124] Preferably, the above device further includes: a real-time monitoring unit for real-time monitoring of the network environment and email traffic to detect potential security events; a first automatic adjustment unit for automatically adjusting the scoring rules of the first comprehensive score, the second comprehensive score, and the third comprehensive score, and the values of the first preset score threshold, the second preset score threshold, and the third preset score threshold when a specific security event is detected to cope with sudden security threats.
[0125] Preferably, the above device further includes: a feedback collection unit for continuously collecting user feedback data; a second automatic adjustment unit for automatically adjusting the scoring rules of the first comprehensive score, the second comprehensive score, and the third comprehensive score, and the values of the first preset score threshold, the second preset score threshold, and the third preset score threshold according to the analysis result of the user feedback data to improve the detection accuracy.
[0126] As can be seen from the above technical solutions, the email risk detection device provided by the present invention effectively reduces the false alarm rate of phishing email detection through a combination of multiple detection means, and solves the problem of high false alarm rate of phishing email detection by traditional email gateways. By triggering dynamic adjustment of scoring rules and thresholds through security events and user feedback, the system can respond to sudden security threats in real time, further improving the detection accuracy and efficiency. Finally, in this application, after each detection unit completes the detection, the current comprehensive score can be immediately evaluated, and a preliminary decision can be made according to the preset threshold, improving the detection efficiency.
[0127] An embodiment of the present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, the above method is implemented.
[0128] An embodiment of the present invention further provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program for executing the above method.
[0129] As Figure 9, the electronic device 600 may further include: a communication module 110, an input unit 120, an audio processor 130, a display 160, and a power supply 170. It should be noted that the electronic device 600 does not necessarily have to include Figure 9 all the components shown; in addition, the electronic device 600 may further include Figure 9 components not shown. For those not shown, reference may be made to the prior art.
[0130] Such as Figure 9 , the central processing unit 100, sometimes also referred to as a controller or operation control, may include a microprocessor or other processor device and / or logic device. The central processing unit 100 receives inputs and controls the operations of the various components of the electronic device 600.
[0131] Among them, the memory 140, for example, may be one or more of a buffer, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory, or other suitable devices. It can store the above information related to failures, and can also store programs for executing relevant information. And the central processing unit 100 can execute the programs stored in the memory 140 to implement information storage or processing, etc.
[0132] The input unit 120 provides inputs to the central processing unit 100. The input unit 120 is, for example, a key or a touch input device. The power supply 170 is used to supply power to the electronic device 600. The display 160 is used to display display objects such as images and texts. The display may be, for example, an LCD display, but is not limited thereto.
[0133] The memory 140 may be a solid-state memory. For example, a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It can also be such a memory that stores information even when powered off, can be selectively erased and has more data stored. Examples of such a memory are sometimes referred to as EPROMs, etc. The memory 140 may also be some other type of device. The memory 140 includes a buffer memory 141 (sometimes referred to as a buffer). The memory 140 may include an application / function storage unit 142, which is used to store applications and function programs or the processes for operating the electronic device 600 through the central processing unit 100.
[0134] The memory 140 may further include a data storage unit 143, which is used to store data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 144 of the memory 140 may include various drivers of the electronic device for communication functions and / or for executing other functions of the electronic device (such as a messaging application, an address book application, etc.).
[0135] The communication module 110 is a transmitter / receiver 110 that transmits and receives signals via the antenna 111. The communication module (transmitter / receiver) 110 is coupled to the central processor 100 to provide input signals and receive output signals, which can be the same as in the case of a conventional mobile communication terminal.
[0136] Based on different communication technologies, multiple communication modules 110, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, etc., can be provided in the same electronic device. The communication module (transmitter / receiver) 110 is also coupled to the speaker 131 and the microphone 132 via the audio processor 130 to provide an audio output via the speaker 131 and receive an audio input from the microphone 132, thereby implementing the usual telecommunication functions. The audio processor 130 can include any suitable buffers, decoders, amplifiers, etc. Additionally, the audio processor 130 is also coupled to the central processor 100, so that recording can be performed on the local machine through the microphone 132, and the sound stored on the local machine can be played through the speaker 131.
[0137] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.
[0138] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0139] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1The functions specified in one or more boxes.
[0140] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the steps of the functions specified in Figure 1 one process or more processes and / or boxes Figure 1 the functions specified in one box or more boxes.
[0141] In the present invention, specific embodiments are used to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only for helping to understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. An email risk detection method, characterized in that: The method comprises: Perform mail header inspection on received emails; Updating a first comprehensive score of the email according to the email header detection result, and determining whether to intercept the email according to the first comprehensive score and a first preset score threshold; In response to not intercepting the email based on the first comprehensive score, continuing to perform email body detection on the email; Updating a second comprehensive score of the email according to the email body detection result, and determining whether to intercept the email according to the second comprehensive score and a second preset score threshold; In response to not intercepting the email based on the second comprehensive score, continuing to perform email attachment detection on the email; The third comprehensive score of the email is updated according to the email attachment detection result, and whether to intercept is determined according to the third comprehensive score and a third preset score threshold.
2. The email risk detection method according to claim 1, characterized in that: The mail header detection includes: Check whether the email sender is on the trusted list or untrusted list; Check whether the email domain name is among the trusted domain names or untrusted domain names; Check whether the email domain name is a fake domain name.
3. The email risk detection method according to claim 2, characterized in that: The detection of whether the email domain name is a forged domain name includes: Calculate the similarity between the email domain name and your company domain name, trusted domain name, and authoritative domain name; It is determined whether the similarity exceeds a preset threshold. If so, the email domain name is a forged domain name.
4. The email risk detection method according to claim 1, characterized in that: The email body detection includes: comparing the email body with a built-in feature library, and judging the probability that the email is a risky email based on the comparison result.
5. The email risk detection method according to claim 1, characterized in that: The email attachment detection includes: Detect the suffix of email attachments; Performing static analysis on the email attachment to determine its risk index; The email attachment is placed into a sandbox for execution to dynamically analyze its risk index.
6. The email risk detection method according to claim 1, characterized in that: The method further comprises: Monitor network environment and email traffic in real time to detect potential security incidents; When a specific security event is detected, the scoring rules of the first comprehensive score, the second comprehensive score, and the third comprehensive score, as well as the values of the first preset score threshold, the second preset score threshold, and the third preset score threshold are automatically adjusted to respond to sudden security threats.
7. The email risk detection method according to claim 1, characterized in that: The method further comprises: Continuously collect user feedback data; According to the analysis results of the user feedback data, the scoring rules of the first comprehensive score, the second comprehensive score, and the third comprehensive score, as well as the values of the first preset score threshold, the second preset score threshold, and the third preset score threshold are automatically determined to improve detection accuracy.
8. An email risk detection device, characterized in that: The device comprises: A header detection unit, used for performing mail header detection on received emails; A first interception unit, configured to update a first comprehensive score of the email according to the email header detection result, and determine whether to intercept according to the first comprehensive score and a first preset score threshold; a body detection unit, configured to, in response to the first interception unit not performing interception based on the first comprehensive score, continue to perform mail body detection on the email; A second interception unit, configured to update a second comprehensive score of the email according to the email body detection result, and determine whether to intercept according to the second comprehensive score and a second preset score threshold; an attachment detection unit, configured to, in response to the second interception unit not intercepting the email based on the second comprehensive score, continue to perform mail attachment detection on the email; The third interception unit updates the third comprehensive score of the email according to the email attachment detection result, and determines whether to intercept according to the third comprehensive score and a third preset score threshold.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.