Device and method for identifying phishing mail, and computer equipment

By combining data collection, feature extraction, and model training, and utilizing technologies such as Bayesian algorithms and advanced text context understanding, phishing emails can be automatically identified, solving the problem of low accuracy in existing technologies and achieving efficient phishing email detection and risk warning.

CN121864337APending Publication Date: 2026-04-14HUADI COMP GROUP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-10-11
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

In existing technologies, the identification of phishing emails relies on human experience or rule-based judgment, which has low accuracy and consumes a lot of manpower and resources. It is difficult to efficiently and quickly alert users to suspicious emails and improve enterprise network security.

Method used

It employs a data collection module, a feature extraction module, a model training module, and a risk warning and control module, combined with Bayesian algorithms, advanced text context understanding, intelligent image processing, and feature selection training units, to automatically identify phishing emails through in-depth analysis of email content and behavioral patterns.

Benefits of technology

It improves the efficiency and accuracy of phishing email detection, enhances the risk management capabilities of enterprise email systems, automatically labels and alerts users to suspicious emails, and reduces false positives and false negatives.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864337A_ABST
    Figure CN121864337A_ABST
Patent Text Reader

Abstract

The invention discloses a device and method for identifying phishing mails and computer equipment. The device comprises a data collection module, a feature extraction module, a model training module and a risk early warning and control module. The data collection module collects phishing mail samples, normal mail samples and user behavior data; the feature extraction module is used for extracting content features, structural features, behavior features and system features of mails; the model training module adopts a Bayesian algorithm to carry out model training, evaluates the performance of the model through methods such as cross validation, and carries out adjustment and optimization according to needs; and the risk early warning and management and control module is used for deeply analyzing the mail content and carrying out three-step identification and judgment of list analysis, link and attachment detection and behavior pattern analysis and judgment on the mail content, so that the detection efficiency and the detection accuracy of phishing mails are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of email identification technology, and more specifically, to an apparatus and method for identifying phishing emails. Background Technology

[0002] Phishing emails refer to emails that use deceptive tactics to trick recipients into replying with account information, passwords, or other details to a designated recipient; or they may redirect recipients to specially crafted web pages, often disguised as legitimate websites such as bank or financial websites, leading users to believe they are legitimate and enter their credit card or bank card numbers, account names, and passwords, resulting in theft. Attackers frequently use phishing emails as a starting point for infiltrating computer systems, leading to cybersecurity incidents. These phishing emails mainly fall into two categories: one is phishing emails based on malicious links, which trick recipients into clicking on malicious links, short links with malicious intent, or by forging similar domain names; the other is phishing emails based on malicious attachments, which trick recipients into opening malicious / encrypted attachments or cloud attachments to achieve the attacker's goal.

[0003] Phishing emails can be disguised in many ways and are quite sophisticated. Traditional methods of identifying phishing emails rely heavily on human experience or rule-based judgment, resulting in low accuracy and high resource consumption. Therefore, it is crucial to find a way to quickly and efficiently alert users to suspicious emails, mitigate the risks posed by phishing emails, and improve internal network security within enterprises. Summary of the Invention

[0004] To address the aforementioned problems, this invention provides an apparatus and method for identifying phishing emails, thereby improving the efficiency and accuracy of phishing email detection.

[0005] To achieve the objective of this invention, the technical solution adopted is a device for identifying phishing emails, which includes a data collection module, a feature extraction module, a model training module, and a risk warning and control module.

[0006] The data collection module collects data including, but not limited to, phishing email samples, normal email samples, and user behavior data.

[0007] The feature extraction module extracts the content features, structural features, behavioral features, and system features of the email;

[0008] The model training module uses the Bayesian algorithm to train the model and evaluates the model's performance through methods such as cross-validation, making adjustments and optimizations as needed.

[0009] The risk warning and control module performs in-depth analysis of email content, and identifies and judges the content through three steps: list analysis, link and attachment detection, and behavioral pattern analysis.

[0010] Preferably, the model training module includes an advanced text context understanding training unit, an intelligent image processing training unit, and a feature selection training unit;

[0011] Optionally, the content feature extraction of the email includes the extraction of the email subject, body, sender, recipient, links, and attachments;

[0012] The email structure feature extraction includes the email's HTML structure, font, and color, in order to identify and extract abnormal formats;

[0013] The email behavior feature extraction includes the extraction of features related to the user's email contacts and email processing habits, which are used for behavior pattern analysis.

[0014] The email system features include collecting information on system resource usage and network traffic characteristics to detect abnormal activity.

[0015] Preferably, the risk warning and control module performs in-depth analysis of email content, and sets appropriate thresholds for each of the three steps of identification and judgment: list analysis, link and attachment detection, and behavior pattern analysis, in order to determine the conditions for marking an email as a suspected phishing email.

[0016] On the other hand, embodiments of this application also provide a method for identifying phishing emails, characterized in that the method includes:

[0017] S1: Collect email data including but not limited to phishing email samples, normal email samples, and user behavior data;

[0018] S2: Extract content features, structural features, behavioral features, and system features from the email;

[0019] S3: Train the model based on the collected and extracted data, evaluate the model's performance through methods such as cross-validation, and adjust and optimize it as needed;

[0020] S4: Perform in-depth analysis of email content, including three steps of identification and judgment: list analysis, link and attachment detection, and behavioral pattern analysis.

[0021] Optionally, the content features of the emails can be extracted, including the email subject, body, sender, recipient, links, and attachments; the structural features of the emails can be extracted, including the email's HTML structure, font, and color, to identify abnormal formats; the behavioral features of the emails can be extracted, including the user's email contacts and email processing habits, for behavioral pattern analysis; and the system features of the emails can be extracted, including collecting system resource usage and network traffic characteristics, to detect abnormal activity.

[0022] Optionally, the email can be identified and judged in three steps, with appropriate thresholds set for each step to determine the conditions for marking the email as a suspected phishing email, and then marked with different levels of warning colors to alert the user.

[0023] On the other hand, embodiments of this application also provide a computer device, which includes a processor and a memory;

[0024] The memory is used to store program code and transmit the program code to the processor;

[0025] The processor is used to execute the phishing email identification method according to the instructions in the program code.

[0026] On the other hand, embodiments of this application also provide a computer-readable storage medium for storing a computer program for executing the method for identifying phishing emails.

[0027] The beneficial effects of this invention are as follows:

[0028] This system enhances risk control against phishing emails, enriches risk models and handling methods, and adds a color-coded warning feature for suspicious emails. When customers receive emails of varying degrees of suspicion, the system automatically identifies and flags them based on the model, alerting the customer to the importance of information security. This represents a significant innovative direction for risk control mechanisms in enterprises' online and digital email transformation. Attached Figure Description

[0029] The above and other objects, features and advantages of the present invention will become more apparent from the accompanying drawings, in which like reference numerals generally denote like parts.

[0030] Figure 1 The diagram illustrates the structural composition of a device for identifying phishing emails according to an embodiment of the present invention.

[0031] Figure 2 A flowchart illustrating the steps of a method for identifying phishing emails according to an embodiment of the present invention is shown. Detailed Implementation

[0032] While preferred embodiments of the invention are shown in the accompanying drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that the invention will be more thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0033] A device for identifying phishing corporate emails includes a data collection module, a feature extraction module, a model training module, and a risk warning and control module;

[0034] The data collection module collects data including, but not limited to, phishing email samples, legitimate email samples, and user behavior data.

[0035] The data collection module gathers a large number of known phishing email samples, tagging phishing emails received by each employee within the enterprise. It also collects a large number of legitimate email samples to train models that can distinguish between legitimate and phishing emails. Furthermore, it collects user behavior data, such as email interactions, for behavioral pattern analysis.

[0036] The feature extraction module extracts content features, structural features, behavioral features, and system features from emails;

[0037] Email content feature extraction includes, but is not limited to, the extraction of features such as email subject, body, sender, recipient, links, and attachments.

[0038] Email structure feature extraction includes, but is not limited to, analyzing the email's HTML structure, font, color, etc., to identify and extract abnormal formats.

[0039] Behavioral characteristics include extracting features such as the users' email contacts and email processing habits, which are used for behavioral pattern analysis.

[0040] System feature extraction includes collecting features such as system resource usage and network traffic to detect abnormal activity.

[0041] The model training module uses the Bayesian algorithm to train the model and evaluates the model's performance through methods such as cross-validation, making adjustments and optimizations as needed.

[0042] Specifically, the model training module includes an advanced text context understanding training unit, an intelligent image processing training unit, and a feature selection training unit;

[0043] Advanced text context understanding (ACT) is an AI algorithm capable of deep processing of natural language. Its unique bidirectional understanding capability allows it to comprehend the semantic context of words within sentences, providing more accurate language interpretations. Traditional email security systems typically only detect common phishing emails, such as those requesting personal information or clicking on suspicious links. However, attackers are now employing more subtle linguistic techniques to disguise their messages, making them difficult for traditional email security systems to identify. ACT training units analyze the language and context of emails to determine if any suspicious behavior or requests exist. For example, if an email appears to be from a bank but the language or format does not conform to the bank's usual usage, it may be a phishing email. ACT training units identify this unusual language use and mark the email as suspicious.

[0044] Furthermore, the advanced text context understanding training unit can analyze the relationship between the sender and recipient of an email. For example, if you have never communicated with a sender but suddenly receive an email requesting personal information, that email may be a phishing email.

[0045] The intelligent image processing training unit uses intelligent image processing technology to identify hidden threats in images. It can analyze details in images and determine their authenticity, significantly improving the ability to identify phishing emails and ensuring a more secure inbox.

[0046] The feature selection training unit trains multiple feature selection criteria, comprehensively considering the importance of each feature item, to select the optimal feature subset. Through an optimization process, the feature items in the feature subset are dynamically adjusted to achieve the best classification performance.

[0047] In phishing email filtering systems, the OMFS algorithm can be used to select the most representative features to distinguish between phishing and legitimate emails. This algorithm evaluates the importance of each feature based on different feature selection criteria, such as information gain, chi-square test, and mutual information. By optimizing the algorithm, the best feature subset is selected, resulting in optimal classification performance. The advantage of the OMFS algorithm lies in considering multiple feature selection criteria and its ability to dynamically adjust based on specific circumstances. By selecting the optimal feature subset, the classification accuracy and efficiency of the phishing email filtering system can be improved, reducing false positives and false negatives.

[0048] The risk warning and control module performs in-depth analysis of email content, and identifies and judges it through three steps: list analysis, link and attachment detection, and behavioral pattern analysis.

[0049] The first step is to analyze the list, judging based on the sender's email address name, format, etc., to determine whether it falls within the scope of the suspicious list;

[0050] We conduct in-depth analysis of email content, including the subject, body, sender address, and recipient address. Through natural language processing and machine learning techniques, we can identify unusual email suffixes, unusual vocabulary, sentence structure, and grammatical errors—common characteristics of phishing emails. For example, email addresses not belonging to our company are automatically highlighted with color to alert users and added to a suspicious list.

[0051] The second step is link and attachment detection. This involves using intelligent image processing technology to analyze suspicious points in visual links and attachments in the email, analyzing details in the images, and determining whether they are genuine.

[0052] Regarding links and attachments in emails: For links, the system checks their source, domain legitimacy, and whether the link text matches the actual address. It also determines whether the URL in the email is a phishing website link. For attachments, the system checks their type, size, and content to determine if they contain malware or viruses.

[0053] The third step is to perform behavioral pattern analysis, which involves advanced text context analysis of the email content, such as the subject and language. The OMFS algorithm is used to select the most representative features to distinguish between phishing emails and legitimate emails.

[0054] In addition to analyzing the emails themselves, the method also considers user behavior patterns. Because phishing emails are becoming increasingly sophisticated, the third step in this approach is to enrich the judgment by analyzing user work scenarios and behavioral patterns. A corresponding scenario-based behavioral learning library can be established. Employees within the company can add relevant phishing emails to the library. Artificial intelligence analyzes the corresponding scenarios of phishing emails, continuously enriching the learning library, and gradually forming a complete AI-based method model for identifying phishing emails.

[0055] Set thresholds: Based on the three-step identification process, set appropriate thresholds to determine when to mark emails as potentially phishing emails. Use different levels of warning colors to highlight and alert the user.

[0056] The device identifies phishing emails and performs real-time detection on every incoming email. For suspected phishing emails, it can choose to automatically block them or send a warning to the user. Blocked emails are collected in a designated spam folder, and users can manually intervene if necessary.

[0057] On the other hand, embodiments of this application also provide a method for identifying phishing emails, such as... Figure 2 It includes the following steps:

[0058] S1: Collect email data including but not limited to phishing email samples, normal email samples, and user behavior data;

[0059] S2: Extract content features, structural features, behavioral features, and system features from the email;

[0060] S3: Train the model based on the collected and extracted data, evaluate the model's performance through methods such as cross-validation, and adjust and optimize it as needed;

[0061] S4: Perform in-depth analysis of email content, including three steps of identification and judgment: list analysis, link and attachment detection, and behavioral pattern analysis.

[0062] Specifically, the content features of emails are extracted as follows: subject, body, sender, recipient, links, and attachments. The structural features of emails are extracted as follows: HTML structure, font, and color, to identify abnormal formats. The behavioral features of emails are extracted as follows: the users' email contacts and email processing habits, for behavioral pattern analysis. The system features of emails are extracted as follows: system resource usage and network traffic characteristics are collected to detect abnormal activities.

[0063] Optionally, the email can be identified and judged in three steps, with appropriate thresholds set for each step to determine the conditions for marking the email as a suspected phishing email, and then marked with different levels of warning colors to alert the user.

[0064] At each step of the recognition hit, different shades of warning color are set according to the corresponding level. Warning color level I means that only one layer of recognition is hit, warning color level II means that two layers of recognition are hit, and warning color level III means that three layers of recognition are hit.

[0065] In another aspect, embodiments of this application provide a computer device, the device including a processor and a memory;

[0066] The memory is used to store program code and transmit the program code to the processor;

[0067] The processor is used to execute the method for identifying phishing emails provided in the above embodiments according to the instructions in the program code. The computer device may include a terminal device or a server, and the aforementioned phishing email identification device may be configured in the computer device.

[0068] In another aspect, embodiments of this application also provide a storage medium for storing a computer program for executing the phishing email identification method provided in the above embodiments.

[0069] Additionally, embodiments of this application also provide a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method for identifying phishing emails provided in various optional implementations of the above aspects.

[0070] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present invention can be implemented using various computer languages, such as the object-oriented programming language Java and the interpreted scripting language JavaScript.

[0071] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0072] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0073] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0074] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention.

[0075] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. A device for identifying phishing emails, characterized in that, The device for identifying phishing emails includes a data collection module, a feature extraction module, a model training module, and a risk warning and control module. The data collection module collects data including, but not limited to, phishing email samples, normal email samples, and user behavior data. The feature extraction module extracts the content features, structural features, behavioral features, and system features of the email; The model training module uses the Bayesian algorithm to train the model and evaluates the model's performance through methods such as cross-validation, making adjustments and optimizations as needed. The risk warning and control module performs in-depth analysis of email content, and identifies and judges the content through three steps: list analysis, link and attachment detection, and behavioral pattern analysis.

2. The device for identifying phishing emails according to claim 1, characterized in that, The model training module includes an advanced text context understanding training unit, an intelligent image processing training unit, and a feature selection training unit.

3. The device for identifying phishing emails according to claim 2, characterized in that, The content feature extraction of the email includes the extraction of the email subject, body, sender, recipient, links, and attachments; The email structure feature extraction includes the email's HTML structure, font, and color, in order to identify and extract abnormal formats; The email behavior feature extraction includes the extraction of email correspondents and email processing habits, which are used for behavior pattern analysis. The email system feature extraction includes collecting system resource usage and network traffic characteristics to detect abnormal activity.

4. A method for identifying phishing emails, characterized in that, The method includes: S1: Collect email data including but not limited to phishing email samples, normal email samples, and user behavior data; S2: Extract the content features, structural features, behavioral features, and system features of the email; S3: Train the model based on the collected and extracted data, evaluate the model's performance through methods such as cross-validation, and adjust and optimize it as needed; S4: Perform in-depth analysis of email content, including three steps of identification and judgment: list analysis, link and attachment detection, and behavioral pattern analysis.

5. The method for identifying phishing emails according to claim 4, characterized in that, The content features of the emails are extracted as the subject, body, sender, recipient, links, and attachments. Extracting structural features of emails, including their HTML structure, fonts, and colors, to identify abnormal formats; Extracting behavioral characteristics from emails includes the user's email contacts and email processing habits, which are used for behavioral pattern analysis. Extracting system characteristics from emails includes collecting information on system resource usage and network traffic patterns to detect abnormal activity.

6. The method for identifying phishing emails according to claim 5, characterized in that, The system performs a three-step identification and judgment process for emails, setting appropriate thresholds for each step to determine the conditions under which an email is marked as a suspected phishing email, and then marking it with different levels of warning colors to alert the user.

7. A computer device, characterized in that, The computer device includes a processor and memory: The memory is used to store program code and transmit the program code to the processor; The processor is configured to execute the method described in any one of claims 4-6 according to the instructions in the program code.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program for performing the method according to any one of claims 4-6.