Mail security detection method and system based on frequency domain and semantic analysis, electronic equipment and computer readable storage medium
Through the email security detection method of frequency domain and semantic analysis, combined with DCT transformation and SMTP traffic analysis, a comprehensive risk score is generated and multi-level alarms are triggered, which solves the shortcomings of email security management in the existing technology and realizes efficient data theft protection.
Patent Information
- Application Number
- CN202510726314.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-06-03
AI Technical Summary
In the office automation system, the existing technology has problems such as weak steganography detection capability, insufficient semantic analysis of protocol layer, isolated response mechanism and high latency, and weak hardware acceleration support in the email security management. It is difficult to effectively identify frequency domain steganography data, intercept sensitive word outgoing behavior in real time and realize multi-level automated response.
The email security detection method based on frequency domain and semantic analysis is adopted, and the mail attachment image is preprocessed and DCT transformed, the entropy value of high-frequency components is calculated, combined with SMTP traffic semantic analysis, a comprehensive risk score is generated, and a multi-level alarm linkage mechanism is triggered, and a FPGA hardware acceleration is used to achieve real-time response.
It realizes data theft protection with high detection rate, low latency and strong adaptability, and provides reliable technical guarantees for enterprise-level network security.
Smart Images

Figure CN120238380A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of office automation, and particularly relates to an email security detection method and system, an electronic device, and a computer-readable storage medium based on frequency domain and semantic analysis. Background Art
[0002] In an office automation system, as a core communication tool, the security of email is directly related to the protection of enterprise business data. In the prior art, the security management of email mainly relies on content filtering, rule engines, or traditional encryption means, but there are obvious deficiencies in dealing with advanced threats (such as steganography attacks): 1. Weak steganography detection ability: Existing systems are mostly based on spatial domain analysis (such as LSB steganography detection), with low detection rates (such as only 25% verified by the UCID dataset), and it is difficult to effectively identify frequency domain steganographic data.
[0003] 2. Insufficient semantic parsing at the protocol layer: SMTP traffic analysis is mostly limited to protocol compliance checks, lacking in-depth semantic parsing of TLS encrypted traffic, and unable to intercept the behavior of sending sensitive words in real time.
[0004] 3. Isolated response mechanism and high latency: Traditional solutions rely on software processing, and there is no dynamic linkage between detection results and warning actions The interception latency is as high as 15 seconds. For example, even if an anomaly is detected, manual intervention or step-by-step processing is required for links such as alarm triggering, email blocking, and log recording, and multi-level automated response cannot be achieved. Moreover, the synchronization efficiency between alarm logs and the security event management system is low, resulting in delayed threat handling.
[0005] 4. Weak support for hardware acceleration: Existing alarm mechanisms are difficult to utilize hardware acceleration technologies such as FPGA / DPDK, and cannot meet the stringent requirements for real-time performance (such as millisecond-level response) in office automation scenarios.
[0006] Therefore, there is an urgent need for a technical solution that combines frequency domain analysis, protocol layer semantic analysis, and an efficient linkage warning mechanism to improve the email security protection ability of the office automation system and achieve integrated real-time response of detection, blocking, and log synchronization. Summary of the Invention
[0007] The object of the present invention is to provide an email security detection method and system, an electronic device, and a computer-readable storage medium based on frequency domain and semantic analysis to solve the email security problem in an automated office environment.
[0008] The present invention provides an email security detection method based on frequency domain and semantic analysis, and the method includes the following steps: Step 1: Obtain the email to be detected and perform preprocessing operations on the images in its attachments; Step 2: Perform a chunking operation on the preprocessed image, and then perform a DCT transform on each chunk to generate the corresponding DCT coefficient matrix; Step 3: Calculate the entropy value of the high-frequency component corresponding to each chunk according to the DCT coefficient matrix ; Determine the steganography suspicion detection result of the email according to the value; Step 4: Based on the steganography suspicion detection result, trigger the SMTP traffic semantic analysis of the email to obtain a comprehensive risk score ; The specific steps of Step 4 include: Step 4.1: Decrypt the TLS traffic and extract the corresponding plaintext; Step 4.2: Perform real-time matching of sensitive words to obtain a sensitive word score ; Step 4.3: Perform semantic association analysis to obtain a semantic score ; Step 4.4: Generate a comprehensive risk score based on the sensitive word score and the semantic score ; ; Step 5: Based on the comprehensive risk score , trigger the linkage mechanism of multi-level alarms; the specific judgment rule is: when ≥0.9, trigger a first-level alarm, immediately block the email, give an audible and visual alarm, and notify the central station; when 0.75 ≤ <0.9, trigger a second-level alarm, perform a secondary verification with a 500ms delay, record the log after confirmation, and prompt the administrator; when <0.75, trigger a third-level alarm, only record the log for manual review by the administrator.
[0009] The email security detection method based on frequency domain and semantic analysis as described above is further preferably that the preprocessing operation in Step 1 is specifically to perform grayscale processing on the image.
[0010] The email security detection method based on frequency domain and semantic analysis as described above is further preferably that the implementation of Step 2 specifically includes the following steps: First, perform an 8×8 chunking operation on the grayscale processed image; then, perform a two-dimensional discrete cosine transform DCT on each 8×8 chunk to generate the corresponding 8×8 DCT coefficient matrix.
[0011] The email security detection method based on frequency domain and semantic analysis as described above is further preferably that the implementation of Step 3 specifically includes the following steps: Step 3.1: Select high-frequency components: In the 8×8 DCT coefficient matrix, define the high-frequency components as the 20 coefficients located in the lower right corner of the matrix; Step 3.2: Calculate the probability distribution: Statistically calculate the normalized probability distribution of the high-frequency components of each block; Step 3.3: According to the probability distribution obtained in Step 3.2, calculate the entropy value of the high-frequency components of the block; Step 3.4: Based on the entropy value of the high-frequency components of the block, count the number of abnormal blocks, and determine whether there is a suspicion of steganography in the email based on the number of abnormal blocks.
[0012] For the email security detection method based on frequency domain and semantic analysis as described above, it is further preferably that the calculation formula for the sensitive word score in Step 4.2 is:
[0013] where, is the weight corresponding to the hit sensitive word; is the total number of hit sensitive words; the total number of shards is the total number of independent processing units obtained by splitting the complete SMTP email data into multiple units according to logic or a fixed size.
[0014] For the email security detection method based on frequency domain and semantic analysis as described above, it is further preferably that Step 4.3 specifically includes: First, use the lightweight BERT-Tiny model to perform a binary classification task on the email body, and output the probability value , representing the confidence that the email is an abnormal external send, where ; Second, perform context detection. If the body description is "regular report" but the attachment is an encrypted compressed package, perform a contradiction mark. If multiple emails containing sensitive words are received by the same recipient within a short period of time, perform an abnormality mark; Finally, perform semantic scoring. When a contradiction or abnormality mark appears, perform dynamic weighting on to obtain the semantic score , and its dynamic weighting formula is:
[0015] where, is the weighting coefficient, which can be dynamically adjusted according to the policy.
[0016] For the email security detection method based on frequency domain and semantic analysis as described above, it is further preferably that the secondary verification in Step 5 specifically includes the following steps: Step 5.1: Set a delay window and perform data caching; Step 5.2: Multimodal Deep Association Analysis: In this sub-step, two methods, i.e., frequency domain-semantic cross-validation and behavior portrait matching verification, are combined for deep association analysis; Step 5.3: Dynamic Score Correction and Decision Making: The score correction rule is:
[0017] Based on the corrected score Alarm escalation / downgrading is performed.
[0018] The present invention also discloses an email security detection system based on frequency domain and semantic analysis. This system executes the above-mentioned email security detection method based on frequency domain and semantic analysis. Specifically, the system includes: Preprocessing Module: Used to obtain the email to be detected and perform preprocessing operations on the images in its attachments; DCT Coefficient Matrix Generation Module: Used to perform block operations on the preprocessed images, and then perform DCT transformation on each block to generate the corresponding DCT coefficient matrix; Steganography Suspect Detection Module: Used to calculate the high-frequency component entropy value corresponding to each block respectively according to the DCT coefficient matrix ; According to the value, determine the steganography suspect detection result of this email; Semantic Analysis Module: Used to trigger the SMTP traffic semantic analysis of this email based on the steganography suspect detection result to obtain a comprehensive risk score ; Multi-level Alarm Linkage Mechanism: Used to trigger multi-level alarms based on the comprehensive risk score ;
[0019] The present invention also discloses an electronic device, including one or more processors; a storage device for storing one or more computer programs. When the one or more computer programs are executed by the one or more processors, the electronic device implements the above-mentioned email security detection method based on frequency domain and semantic analysis.
[0020] The present invention also discloses a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the processor of the electronic device, the electronic device executes the above-mentioned email security detection method based on frequency domain and semantic analysis.
[0021] The beneficial effects of the present invention are as follows: By obtaining the email to be detected, performing preprocessing operations on the images in its attachments; performing block operations on the preprocessed images, and then performing DCT transformation on each block to generate the corresponding DCT coefficient matrix; calculating the high-frequency component entropy value corresponding to each block respectively according to the DCT coefficient matrix ; According to The value determines the steganography suspicion detection result of the email; based on the steganography suspicion detection result, trigger the SMTP traffic semantic analysis of the email to obtain a comprehensive risk score ; based on the comprehensive risk score , trigger the linkage mechanism of multi-level alarms. Through the deep cooperation of frequency domain and semantic dual modalities, the innovation of the hardware acceleration architecture, and the design of multi-level alarm linkage, the present invention realizes the data theft protection effect with high detection rate, low latency, and strong adaptability, providing a reliable technical guarantee for enterprise-level network security. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 is a flowchart of the steps of the email security detection method based on frequency domain and semantic analysis; Figure 2 is a flowchart of the steps of the secondary verification of the email security detection method; Figure 3 is a schematic structural diagram of the email security detection system based on frequency domain and semantic analysis. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0023] The present invention will be described in detail below through embodiments.
[0024] In order to further elaborate on the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following combines the accompanying drawings and preferred embodiments to detail the specific implementation manners, structures, features, and effects of the email security detection method and system based on frequency domain and semantic analysis proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0025] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs.
[0026] The following specifically describes the specific solutions of the email security detection method and system based on frequency domain and semantic analysis provided by the present invention with reference to the accompanying drawings.
[0027] Please refer to Figure 1 , which shows a flowchart of the steps of the email security detection method based on frequency domain and semantic analysis provided by an embodiment of the present invention. As Figure 1 shown, the email security detection method based on frequency domain and semantic analysis provided by the embodiment of the present application includes the following steps 1 to 5: Step 1: Obtain the email to be detected and perform preprocessing operations on the images in its attachments; It should be noted that the image format in the email attachment can be JPEG, PNG, etc. In the preprocessing operation, the image in the attachment needs to be grayscale processed and uniformly converted into 8-bit grayscale images to simplify subsequent operations.
[0028] Step 2: Perform block operation on the preprocessed image, and then perform DCT transformation on each block to generate the corresponding DCT coefficient matrix; It should be noted that for the grayscale image, 8×8 block processing is performed. For example, an image with a resolution of 1024×1024 will be divided into 16384 blocks, each of which is a non-overlapping 8×8 pixel block. The reason for choosing 8×8 block size is: the consideration of computational efficiency and high-frequency component positioning; the complexity of DCT transformation is exponentially related to the block size, 8×8 is a general standard for balancing computational efficiency and frequency domain resolution, and the lower right area of the 8×8 matrix concentrates on representing the high-frequency information of the image, which is suitable for detecting subtle disturbances introduced by steganography.
[0029] Perform a two-dimensional discrete cosine transform (DCT) on each 8×8 block to generate the corresponding 8×8 DCT coefficient matrix. The DCT formula is as follows:
[0030] Among them, C(u), C(v) are normalization coefficients, (when u,v=0), otherwise 1; It is the gray value of the pixel in the mth row and nth column in the block; u and v represent the frequency components of the image block in the horizontal and vertical directions respectively.
[0031] Step 3: According to the DCT coefficient matrix, calculate the high-frequency component entropy value corresponding to each block ;according to The value determines the result of the steganography suspicion detection of the email; It should be noted that: First, high-frequency components are selected: in the 8×8 DCT coefficient matrix, the high-frequency components are defined as the 20 coefficients located in the lower right corner of the matrix, and their positions satisfy This area is more sensitive to the noise introduced by the steganographic operation and has a naturally low energy characteristic, which makes it easier to detect abnormal entropy fluctuations; Secondly, calculate the probability distribution: Calculate the normalized probability distribution of the high-frequency components of each block. Assume that the 20 high-frequency coefficients are , the specific method is: Take the absolute value of the 20 high-frequency coefficients of each block and get , , , ; Calculate the probability of each coefficient:
[0032] This calculation process is to convert the energy distribution of high-frequency components into a probability distribution, eliminating the influence of the energy difference of the image content itself.
[0033] Calculate the entropy value: Calculate the entropy value of the high-frequency components based on the probability distribution obtained from the above calculation process:
[0034] It should be noted here that using the logarithm with base 2 makes the unit of the entropy value bit (bit), which is convenient for unified quantization; for the threshold setting, through experiments on the UCID dataset, the average value of normal images is about 5.1, while for stego images, the probability distribution is homogenized due to the introduction of random noise, and the entropy value increases significantly.
[0035] The process of judging the steganography suspicion based on the calculated block entropy value is as follows: If the entropy value of a certain block satisfies , then mark this block as an abnormal block; When the proportion of the number of abnormal blocks in a single image exceeds the preset threshold (default setting is ), it is determined that there is a suspicion of steganography in this image.
[0036]
[0037] Step 4: Based on the steganography suspicion detection result, trigger the semantic analysis of the SMTP traffic of this email to obtain a comprehensive risk score ; It should be noted that when this email is determined to be suspected of steganography, the semantic analysis of the SMTP traffic of this email is triggered, and the specific steps are as follows: Step 4.1: Decrypt the TLS traffic and extract the corresponding plaintext; First, intercept the SMTP traffic of this email at the enterprise egress gateway and identify the TLS encrypted session (port 465 or 587); then, use the pre-deployed TLS man-in-the-middle agent (MitM Proxy) to complete the traffic decryption and extract the application layer plaintext data, such as the email body and attachment metadata; finally, temporarily store the decrypted data in the cache area (based on the DPDK memory pool, with a read / write latency of 1ms) for subsequent calls by the semantic analysis module.
[0038] Step 4.2: Real-time matching of sensitive words to obtain a sensitive word score ; First, load the keyword library: Synchronize the top 500 sensitive word libraries from the cloud to the on-chip memory of the local FPGA, with an update cycle of 5 minutes, and the word library format is a hash table (SHA-256 index); then, the parallel matching engine: Use FPGA hardware acceleration to implement multi-threaded keyword scanning, and each thread independently processes a mail shard; Matching logic: Perform regular expression matching on the mail body, attachment name, and metadata, and mark it as abnormal if a hit occurs. Here, a mail shard refers to: Divide the complete SMTP mail data (including the decrypted body, attachment metadata, etc.) into multiple independent processing units according to logic or a fixed size, so as to achieve efficient parallel processing through multi-threading and hardware acceleration. Its core design goal is to improve the throughput of semantic analysis while ensuring the accuracy and low latency of keyword matching.
[0039] At the same time, in order to take into account subsequent multi-level linkage alarms, it is necessary to define and assign weights to sensitive words here.
[0040] Specifically, the method for defining and assigning weights to sensitive words is as follows: Weight classification: Static weight: Based on the enterprise security policy, preset a fixed weight for each sensitive word to reflect its risk level, as shown in the following table:
[0041] Dynamic weight: Dynamically adjust in combination with context and historical data: (1) Word frequency weighting: Increase the weight of sensitive words that appear frequently recently, such as weight × 1.2; (2) Combination enhancement: Combine sensitive words, such as "patent number + amount", and perform weight superposition, such as .
[0042] Weight storage and update: The sensitive word library is stored in the on-chip BRAM of the FPGA, and the format is a hash table (key: sensitive word SHA-256 digest, value: weight); The cloud synchronizes and updates the policy to the local every 3 minutes to ensure real-time performance.
[0043] Based on the weights corresponding to the hit sensitive words above, calculate the sensitive word score. The specific calculation formula is:
[0044] It should be noted that: The sensitive word score is normalized according to the number of shards to avoid weight skew in long emails, resulting in distortion; For example, if the weight range of sensitive words is large (such as high-risk words , low-risk words ), multiple hits of low-risk words in a long email may lead to an inflated total score, interfering with risk determination. Of course, in the above calculation formula, due to the different total weights of sensitive words in different emails, directly dividing by the total number of shards may not be able to eliminate the influence of the absolute value difference in weights. Here, the "total weight sum" method can be introduced on the basis of the above calculation formula to perform "normalization" processing.
[0045] Step 4.3: Semantic association analysis; NLP model selection Model architecture: Adopt the lightweight BERT-Tiny model (4 layers of Transformer, with 4.3M parameters) and adapt it to hardware acceleration; this lightweight BERT-Tiny model performs a binary classification task on the email body and outputs a probability value between 0 and 1 ( ), representing the confidence that the email is an abnormal external send.
[0046] For example:
[0047] Input processing: (1) After tokenizing the email body, truncate it to 512 words to generate a Token sequence; (2) Append metadata features, such as sender credibility, attachment type, etc.; Output logic: The model generates a probability value through the Softmax or Sigmoid function, reflecting the matching degree between the email content and the abnormal samples in the training data.
[0048] Semantic risk identification Intention classification: Output the email intention probability, normal / abnormal external send; Context detection: (1) If the body description is "routine report", but the attachment is an encrypted compressed package, then mark it as contradictory; (2) If the same recipient receives multiple emails containing sensitive words within a short period of time, then mark it as abnormal.
[0049] Semantic scoring
[0050] (1) The model output is a probability between 0 and 1, representing the risk of abnormal external send; (2) When there is a contradictory or abnormal mark, the score is weighted and increased, and its weighted increase rule is: When detecting context contradiction (such as conflict between body description and attachment type) or frequency anomaly (such as the same recipient receiving multiple emails containing sensitive words within a short period of time), dynamically weight the original score:
[0051] Among them, is the weighting coefficient (such as 1.5), which can be dynamically adjusted according to the strategy, and the min function ensures that the score does not exceed 1.0.
[0052] Step 4.4: Generate a comprehensive risk score based on the sensitive word score and the semantic score Generate a comprehensive risk score ; Based on the sensitive word score obtained from the above calculations and the semantic score Generate a comprehensive risk score , and its specific calculation formula is:
[0053] where The initial value is 0.7, representing the coefficient corresponding to the sensitive word score. At the same time, its value can be dynamically adjusted according to enterprise policies, such as increasing it to 0.8 during high-risk periods.
[0054] Step 5: Trigger the linkage mechanism for multi-level alarms based on the comprehensive risk score , trigger the linkage mechanism for multi-level alarms.
[0055] Based on the obtained comprehensive risk score , make a determination in combination with the predetermined multi-level thresholds. The specific determination rules are:
[0056] Furthermore, another embodiment of the present invention provides a method for dynamically adjusting the alarm priority. The specific process is as follows: When the frequency domain is abnormal ( ) and the semantic score , upgrade to a first-level alarm; When only the frequency domain is abnormal but the semantic score is low ( ), downgrade to a third-level alarm.
[0057] Please refer to Figure 2 , which shows the flowchart of the steps of secondary verification provided by another embodiment of the present invention. As Figure 2 shown, the method flow of the secondary verification provided by the embodiments of the present application includes the following steps 1 to step 3: Step 1: Set a delay window and perform data caching Delay time: Set a time window of 500 ms, suspend the execution of the blocking action, and cache the email data in high-speed memory (such as the DPDK memory pool) during this period; Cached content: Includes the decrypted email body, attachment metadata, and preliminary detection results (sensitive word hit records, frequency domain entropy values, etc.).
[0058] Step 2: Multi-modal deep correlation analysis In this step, a combination of two methods is used for in-depth correlation analysis, namely: frequency domain-semantic cross-validation and behavioral portrait matching. The specific operations are as follows: Frequency domain-semantic cross-validation, the steps are as follows: (1) If the frequency domain detection is abnormal , force the deep parsing of the attachment: use OCR to extract the hidden text in the image; check whether the attachment hash value matches the known malicious file library. (2) If the semantic score is abnormal , upgrade the NLP model (such as switching from BERT-Tiny to BERT-Base), and re-analyze the potential contradictions in the email body (such as the conflict between "regular report" and the attached encryption behavior).
[0059] Behavioral portrait matching, the steps are as follows: Real-time query the sender's historical behavior database and evaluate the following indicators: (1) Sending frequency: the number of similar emails in the past 1 hour; (2) Recipient reputation: whether the target email is a high-risk external domain name (such as personal Gmail, unknown enterprise domain name); (3) Permission verification: whether the sender has the permission to send sensitive data externally.
[0060] Step 3: Dynamically correct the score and decision Score correction rules:
[0061] Among them, multimodal contradictions include the following situations, described as: (1) High-risk frequency domain detection ( ): There is a suspicion of steganography in the image attachment; Low-risk semantic detection ( ): The email body does not hit sensitive words, and the intention classification is normal. Contradiction manifestation: There are obvious signs of tampering with the carrier (attachment), but the external sending intention is not abnormal, which may be that the attacker deliberately disguises the body to cover up the steganography behavior. (2) High-risk semantic detection ( ): The body contains high-risk sensitive words (such as "patent number"), and the intention classification is abnormal external sending; Normal frequency domain detection ( ): The attachment has no steganography features. Contradiction manifestation: The email content clearly points to data leakage, but no tampering is found in the carrier, which may be that sensitive information is sent in plain text or a new steganography method is used to avoid detection.
[0062] Alarm upgrade / downgrade (1) If , then upgrade to a level 1 alarm and execute immediate blocking; (2) If , then maintain a level 2 alarm, record the log and prompt the administrator; (3) If , downgrade to a level 3 alarm and only record the log.
[0063] The actual application scenarios are as follows: Scenario: A situation where sensitive words are frequently hit but the semantics are ambiguous Initial detection: Sensitive word score: 0.7 (the medium-risk word "internal document" is hit 5 times); Semantic score: 0.6 (the body text describes "department shared materials"); Comprehensive risk score: If , then , at this time, the secondary alarm threshold is not reached, but if the secondary verification is triggered due to abnormal sending frequency.
[0064] Secondary verification: 1. The behavior profile shows that the sender has sent 10 similar emails to an external domain in the past 1 hour; 2. Upgrading the NLP model finds that "shared materials" in the body text conflicts with the attachment type (encrypted compressed package); 3. The corrected score , then the secondary alarm is triggered, the log is recorded and the administrator is prompted.
[0065] Please refer to Figure 3 , which shows a schematic structural diagram of an email security detection system based on frequency domain and semantic analysis provided by another embodiment of the present invention. As Figure 3 shown, the email security detection system based on frequency domain and semantic analysis provided by the embodiment of the present application includes: a preprocessing module, a DCT coefficient matrix generation module, a steganography suspicion detection module, a semantic analysis module, and a multi-level alarm linkage mechanism, where: Preprocessing module: used to obtain the email to be detected and perform preprocessing operations on the images in its attachments; It should be noted that: the image format in the email attachment can be JPEG, PNG format, etc. In the preprocessing operation, the images in the attachments need to be grayscale processed and uniformly converted into 8-bit grayscale images to simplify subsequent operations.
[0066] DCT coefficient matrix generation module: used to perform block operations on the preprocessed images, and then perform DCT transforms on each block to generate corresponding DCT coefficient matrices; It should be noted that: its specific implementation process is basically the same as step 2 in the above detection method, and will not be elaborated here.
[0067] Steganography suspicion detection module: used to calculate the high-frequency component entropy value corresponding to each block according to the DCT coefficient matrix ; Determine the steganography suspicion detection result of the email according to the value; It should be noted that: its specific implementation process is basically the same as step 3 in the above detection method, and will not be elaborated here.
[0068] Semantic analysis module: used to trigger the SMTP traffic semantic analysis of the email based on the steganography suspicion detection result, and obtain a comprehensive risk score ; It should be noted that: its specific implementation process is basically the same as step 4 in the above detection method, and will not be elaborated here.
[0069] Multi-level alarm linkage mechanism: used to trigger multi-level alarms based on the comprehensive risk score , triggering multi-level alarms.
[0070] It should be noted that: its specific implementation process is basically the same as step 5 in the above detection method, and will not be elaborated here.
[0071] The email security detection method and system based on frequency domain and semantic analysis provided by the present invention achieve the following technical effects: through the deep cooperation of frequency domain and semantic dual modalities, the innovation of the hardware acceleration architecture, and the design of multi-level alarm linkage, the data stealing protection effect with high detection rate, low latency, and strong adaptability is realized, providing a reliable technical guarantee for enterprise-level network security.
[0072] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center in a wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that the computer can access, or a data storage device such as a server or data center that includes one or more integrated available media. The available media can be magnetic media (for example, floppy disks, hard disks, magnetic tapes), optical media (for example, DVDs), or semiconductor media (for example, solid-state drives), etc.
[0073] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention without departing from the principles and purposes of the present invention.
Claims
1. A mail security detection method based on frequency domain and semantic analysis, characterized in that The method includes the following steps: Step 1: Obtain the email to be detected and perform preprocessing operations on the images in its attachments; Step 2: Perform a blocking operation on the preprocessed images, and then perform DCT transformation on each block to generate the corresponding DCT coefficient matrix; Step 3: Calculate the entropy value of the high-frequency component corresponding to each block respectively according to the DCT coefficient matrix ; Determine the steganography suspicion detection result of the email according to the value Step 4: Based on the steganography suspicion detection result, trigger the semantic analysis of the SMTP traffic of this email to obtain a comprehensive risk score ; The specific steps of Step 4 include: Step 4.1: Decrypt the TLS traffic and extract the corresponding plaintext; Step 4.2: Real-time matching of sensitive words to obtain sensitive word scores ; Step 4.3: Semantic association analysis to obtain a semantic score ; Step 4.4: Based on the sensitive word score and the semantic score generate a comprehensive risk score ; Step 5: Based on the comprehensive risk score , trigger the linkage mechanism for multi-level alarms; the specific judgment rule is: when ≥0.9, trigger a first-level alarm, immediately block emails, sound and light alarms, and notify the central station; when 0.75 ≤ <0.9, trigger a second-level alarm, conduct secondary verification, record the log after confirmation, and prompt the administrator; when <0.75, trigger a third-level alarm, only record the log for manual review by the administrator.
2. The email security detection method based on frequency domain and semantic analysis according to claim 1, characterized in that, The preprocessing operation in Step 1 is specifically to perform grayscale processing on the images.
3. The method for detecting email security based on frequency domain and semantic analysis according to claim 2, wherein The implementation of Step 2 specifically includes the following steps: First, perform an 8×8 blocking operation on the grayscale processed image; then, perform a two-dimensional discrete cosine transform DCT on each 8×8 block to generate the corresponding 8×8 DCT coefficient matrix.
4. The email security detection method based on frequency domain and semantic analysis according to claim 3, characterized in that, The implementation of Step 3 specifically includes the following steps: Step 3.1: Select high-frequency components: In the 8×8 DCT coefficient matrix, define the high-frequency components as the 20 coefficients located in the lower right corner of the matrix; Step 3.2: Calculate the probability distribution: Statistically calculate the normalized probability distribution of the high-frequency components of each block; Step 3.3: According to the probability distribution obtained in Step 3.2, calculate the entropy value of the high-frequency components of the block; Step 3.4: Based on the entropy value of the high-frequency components of the block, count the number of abnormal blocks, and based on the number of abnormal blocks, determine whether there is a suspicion of steganography in the email.
5. The email security detection method based on frequency domain and semantic analysis according to claim 4, wherein The calculation formula for the sensitive word score in Step 4.2 is: Among them, is the weight corresponding to the sensitive word hit; is the total number of sensitive words hit; the total number of shards is the total number of independent processing units obtained by logically or fixedly splitting the complete SMTP email data.
6. According to the method for detecting email security based on frequency domain and semantic analysis as described in claim 5, It is characterized in that Step 4.3 specifically includes: First, use the lightweight BERT-Tiny model to perform a binary classification task on the email body and output a probability value , representing the confidence that the email is abnormally sent externally, where ; Second, perform context detection. If the body description is "routine report", but the attachment is an encrypted compressed package, then perform a contradiction mark. If multiple emails containing sensitive words are received by the same recipient within a short period of time, then perform an anomaly mark; Finally, perform semantic scoring. When a contradiction or anomaly mark appears, perform dynamic weighting on to obtain a semantic score , and its dynamic weighting formula is: Among them, is a weighting coefficient and can be dynamically adjusted according to the strategy.
7. The method for email security detection based on frequency domain and semantic analysis according to claim 6, characterized in that The secondary verification in Step 5 specifically includes the following steps: Step 5.1: Set a delay window and perform data caching; Step 5.2: Multi-modal deep correlation analysis: In this sub-step, two methods of frequency domain-semantic cross-verification and behavior portrait matching verification are combined to perform deep correlation analysis; Step 5.3: Dynamically correct the score and decision: The score correction rule is: Based on the revised score Perform alarm escalation / downgrading.
8. A mail security detection system based on frequency domain and semantic analysis, the system executes the mail security detection method based on frequency domain and semantic analysis according to any one of claims 1-7 above, characterized in that, The system specifically includes: A preprocessing module: used to obtain the email to be detected and perform preprocessing operations on the images in its attachments; A DCT coefficient matrix generation module: used to perform a blocking operation on the preprocessed images, and then perform DCT transformation on each block to generate the corresponding DCT coefficient matrix; Steganography suspicion detection module: used to calculate the entropy value of the high-frequency component corresponding to each block respectively according to the DCT coefficient matrix ; According to the value to determine the steganography suspicion detection result of this email; Semantic analysis module: Used to trigger semantic analysis of the SMTP traffic of this email based on the steganography suspicion detection result, and obtain a comprehensive risk score ; Multi-level alarm linkage mechanism: used to trigger multi-level alarms based on the comprehensive risk score , triggering multi-level alarms.
9. An electronic device, characterized in that, It includes one or more processors; a storage device for storing one or more computer programs, and when the one or more computer programs are executed by the one or more processors, the electronic device implements the method for detecting email security based on frequency domain and semantic analysis as described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor of the electronic device, the electronic device executes the method for detecting email security based on frequency domain and semantic analysis as described in any one of claims 1-7.
Citation Information
Patent Citations
Image steganalysis method and system based on frequency domain analysis
CN106327413A
Image semantic segmentation method and device based on discrete cosine transform
CN110738666A
Image processing method and device, equipment, storage medium and program product
CN118018658A
Application of Z-Webs and Z-factors to Analytics, Search Engine, Learning, Recognition, Natural Language, and Other Utilities
US20140079297A1
Cited By
Multi-dimensional analysis-based phishing mail detection method, apparatus and device, and medium
CN120675792A