System and method for determining whether a sender's email has been eavesdropped on - Patent Application 20070122997
By embedding tracking links in emails to analyze IP and geolocation data, the system identifies unauthorized access and alerts senders to potential interception, preventing fraudulent transactions.
Patent Information
- Application Number
- JP2025534575
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-03-21
- Filing Date
- 2023-06-17
- Publication Date
- 2026-01-06
AI Technical Summary
Existing technologies fail to effectively identify and prevent email interception by cybercriminals, who eavesdrop on legitimate email communications to trick recipients into fraudulent transactions, often using sophisticated methods that bypass traditional spam filters and remain undetected.
A system and method that embeds tracking links in emails to capture HTTP data upon opening, analyzing IP addresses and geolocation to determine if unauthorized recipients are accessing the emails, generating alerts and reports to notify senders of potential interception risks.
Enables early detection of email interception attempts, allowing senders to take preventive measures before fraudulent transactions occur, thereby reducing the risk of financial losses due to cybercrime.
Smart Images

Figure 2026500280000001_ABST
Abstract
Description
[Technical Field]
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims the benefit of U.S. Provisional Patent Application No. 63 / 366,685, filed June 20, 2022, and U.S. Non-Provisional Patent Application No. 18 / 124,419, filed March 21, 2023.
[0002] The present invention specifically relates to the field of reducing the risk of communications fraud by providing automated feedback to email senders regarding the likelihood that emails sent to intended recipients will be intercepted by one or more unauthorized and unintended recipients, such as cybercriminals. [Background technology]
[0003] As our communications become increasingly digital, cybercriminals continue to seek to exploit opportunities for illicit activity. Cybercriminals are using increasingly sophisticated schemes to trick email users into sending them money. The Federal Bureau of Investigation (FBI) reported that between June 2016 and July 2019, business email compromise (BEC) and email account compromise (EAC) attempts totaled over $43 billion worldwide. Actual losses from cybercriminals tricking businesses into sending incorrect funds were reported at $2.4 million, with many more likely to remain unnoticed or unreported.
[0004] One systematic method cybercriminals use to trick business personnel into sending money to them involves the following: First, cybercriminals eavesdrop on emails stored in or sent to the recipient's email box when the sender sends the message (using a variety of techniques, including accessing the recipient's email account at the server level and undetectably routing copies of all emails to the cybercriminal's email account). Second, cybercriminals monitor emails coming from the sender and received by the recipient, hoping to identify information about an upcoming transaction (e.g., the recipient's purchase of a product or service from the sender) that, based on the information received from the sender, will naturally result in the recipient paying the sender an invoice. Third, when cybercriminals find a suitable opportunity, they can create a lookalike domain of the sender's domain (e.g., a domain with a one-letter difference), copy the content of one of the emails, and make subtle changes to the content to further their scheme. Fourth, cybercriminals modify the invoice or payment order document, or email content associated with the copied email, to spoof the original sender. Fifth, cybercriminals send modified emails to recipients from domains that look like the original sender, with modified payment details. Finally, the recipients forward the spoofed invoices to their accounts payable clerk, who often then pays the spoofed invoices.
[0005] This common scam relies on the email sender and / or recipient being unaware that their email correspondence is being intercepted by cybercriminals, who are usually located overseas, commonly in countries such as China, Nigeria, and Russia, with certain countries known to have higher rates of cybercrime than others.
[0006] Additionally, it is not uncommon for scammers to use virtual private networks (VPNs) to disguise their online identities and anonymize information related to, for example, the geolocation of the sender, further frustrating efforts to detect when eavesdroppers intercept emails sent to intended recipients.
[0007] While technology exists for identifying potentially fraudulent emails received by email recipients (e.g., spam / junk folders), technical shortcomings exist for identifying potentially fraudulent emails that are near-duplicates of existing legitimate written communications and therefore lack the marketing, high-risk links, or grammatical content elements that typically trigger inbound email filters to identify the message as spam / junk. To prevent successful fraud, rather than simply monitoring or filtering content, it is advantageous to at least identify potential risks long enough for eavesdroppers to begin taking concrete steps toward an attempted attack, such as engaging in activity or creating events for specific emails. In this way, threats can be identified and averted before intended recipients have a chance to fall victim to fraud, for example, by acting on spoofed invoices accompanied by payment information, such as bank details, designed to be routed to a cybercriminal's account.
[0008] One method (among many) cybercriminals use to launch email fraud attempts is by using techniques to create automated systems that guess or purchase passwords associated with email account web client logins, or by using phishing emails with fake linked accounts into which people enter passwords. Once cybercriminals gain access to an email account, they enter the email settings of the incoming email and set the inbox to automatically forward a copy of all incoming email to another email address monitored by the cybercriminal (setting up forwarding and saving a copy of the forwarded email). This is because few email users send using a web interface (most users send from their phone or computer email program rather than a web browser interface), or even if they do, few investigate or monitor changes to the settings. As a result, email account users are often unaware that copies of their emails are set to forward. Another method is to use a password they have obtained or determined to create a connection to the email account using the IMAP protocol at the recipient email server level, thereby copying emails to the cybercriminal's device while leaving a copy on the recipient server.
[0009] Cybercriminals start by using the above and a variety of other tactics to eavesdrop (accessing the contents of the recipient's email account), and when they find the right opportunity, they strike. When cybercriminals decide it's time to trick the email recipient they're eavesdropping on, they purchase a domain similar to the domain of the email account they're monitoring, often with just one letter difference (AnchorInsurance.com vs. AnchorInsurance.com).
[0010] Once the cybercriminal begins receiving copies of the email in their account, they will find a suitable opportunity to "select all" on the email, "copy" the contents and paste them into a new email, overwriting the email as if they were replying to the previous email (mimicking the appearance of an email thread), but this reply comes from a look-alike (spoofed) email domain that mimics the original sender, so the original intended recipient believes it is the original sender and begins corresponding correspondence with the spoofer. Essentially, the spoofing hijacks the email dialogue between the original sender and the intended recipient.
[0011] Finally, cybercriminals acting on the content from the recipient's mailbox create an invoice or alter a previously received invoice with subtle changes including different payment details and send it to the recipient from a look-alike domain. Finally, the recipient may pay the fake invoice or follow the fake wire transfer instructions.
[0012] There is a need in the art to identify email activity (e.g., email opening) associated with higher risk cybercrime and provide alerts to notify email senders and recipients in order to detect eavesdropping as a first step in a criminal scheme and thereby prevent the scheme from escalating into actual communications fraud due to misdirected funds. Likewise, it is important to prevent false alarms that could undermine the perceived seriousness of the alert. Therefore, there is a need to understand factors indicative of unauthorized eavesdropping and effectively evaluate these factors to accurately assess the potential threat. Summary of the Invention
[0013] It is an object of the present invention to provide email senders with an automated assessment of the likelihood that emails sent to authorized recipients will be intercepted by one or more unauthorized recipients.
[0014] According to a first aspect of the present invention, this and other objects are achieved by a system for determining whether an HTTP request generated by a user interaction with an email is the activity of an intended recipient, wherein a link is embedded in the email and configured to be automatically extracted, said system comprising: a link adding module configured to add at least one link to an email sent by a sender, the link being configured to automatically extract data associated with the link when the email is opened at a recipient; and a web server comprising: a processor programmed using hardware and / or software commands, the processor configured to receive an HTTP request at an Internet address when a received email is opened at a recipient, said opening of the email automatically activating the link configured to automatically extract data associated with the link; at least one database including parameters related to the opening of the email; and an analyzer configured to make a determination based on the parameters as to whether returned data associated with the HTTP request includes an indicator that the HTTP request was not initiated by the intended recipient.
[0015] According to a second aspect of the present invention, this and other objects are achieved by a method for determining whether a link configured to be automatically extracted in an email or an HTTP request generated by a user interaction with the link is an activity of an intended recipient of the email, the method comprising: 1) adding a tracking link to a sent email; 2) recording the opening of the email by one or more devices via a tracking link server; 3) extracting and analyzing HTTP data associated with the opening of the email; 4) entering the HTTP data, including at least Internet Protocol (IP) addresses of connections with the one or more devices that open the email, into a database; 5) analyzing geolocation data associated with the intended recipient and / or the one or more devices that open the email; and 6) performing a comparative analysis to assess the risk of email interception.
[0016] According to a third aspect of the present invention, this and other objects are achieved by an analyzer configured to: receive an HTTP request associated with an email message ID of an email opened at one or more devices that open the email; extract and analyze the received HTTP data associated with the HTTP request; input the HTTP data into a first database as first information, the HTTP data including an Internet Protocol (IP) address of a connection with the one or more devices that open the email from the HTTP data; access a second database or a subsection of the first database as second information, the second information including at least one of geolocation or network owner data associated with the Internet Protocol (IP) address or other information in the HTTP data in the first information; accessing a third database or a further subsection of the first database including at least one of IP addresses, IP address ranges, network owners, or device user agent data flagged with a risk level indicative of email interception by at least one unauthorized third party; comparing at least a portion of the first information with at least a portion of the third information or comparing at least a portion of the second information with at least a portion of the third information to determine whether at least a portion of the first information or at least a portion of the second information matches at least a portion of the third information; and generating a report with a risk indication indicating that one or more devices opening the email were not intended devices if at least a portion of the first information or at least a portion of the second information matches at least a portion of the third information.
[0017] Detailed Description of the Invention In the following description, numerous specific details are set forth to provide a thorough understanding of the present disclosure. However, it will be apparent to one of ordinary skill in the art that the present disclosure may be practiced without such specific details. In other instances, well-known components or methods are not described in detail but are instead presented in block diagrams or schematic diagrams to avoid unnecessarily obscuring the present disclosure. More specific numerical references may be made, such as a "first driver." However, the specific numerical references should not be construed as a literal order, but rather that a "first driver" is different from a "second driver." Accordingly, the specific details described are merely exemplary. Variations in the specific details may be made and are still contemplated to be within the spirit and scope of the present disclosure. The term "coupled" is defined to mean either directly connected to a component or indirectly connected to the component via another component.
[0018] Throughout this specification, reference is made to various software programs and hardware components that provide and execute the features and functionality of various embodiments of the present disclosure. The software programs can be embedded in a machine-readable medium. A machine-readable medium includes any mechanism that provides, stores, or transmits information in a form readable by a machine, such as, for example, a computer, a server, or other such device. For example, a machine-readable medium can include read-only memory (ROM), random-access memory (RAM), magnetic disk storage media, optical storage media, flash memory devices, digital video disks (DVDs), EPROM, EEPROM, flash memory, magnetic or optical cards, or any type of medium suitable for storing electronic instructions.
[0019] Some portions of the detailed description are presented in terms of algorithms and symbolic representations of operations on data bits within a computer memory. These algorithmic descriptions and representations are the means used by those skilled in the data processing arts to most effectively convey the substance of their work to others skilled in the art. An algorithm is here, and generally, conceived to be a self-consistent sequence of steps leading to a desired result. The steps are those requiring physical manipulations of physical quantities. Usually, though not necessarily, these quantities take the form of electrical or magnetic signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It has proven convenient at times, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like. These algorithms can be written in a number of different software programming languages. And, algorithms can be implemented as lines of code in software, as configured logic gates in software, or as a combination of both.
[0020] It should be borne in mind, however, that all these and similar terms are associated with the appropriate physical quantities and are merely convenient labels applied to these quantities. Unless specifically stated otherwise, as is clear from the above discussion, it should be understood that throughout this specification, discussions utilizing terms such as "processing" or "computing" or "calculating" or "determining, determining" or "displaying" do not refer to the actions and processes of a general-purpose computer system or similar electronic computing device. Rather, in the context of the following description, such terms relate to processes performed by a computer or similar electronic computing device, under the control of built-in or software programming commands specifically designed to perform specific functions of various embodiments of the present disclosure, that manipulate and transform data represented as physical (electronic) quantities in the computer system's registers and memory into other data similarly represented as physical quantities in the computer system's memory or registers, or other such information storage, transmission, or display device.
[0021] In one embodiment, logic is made up of electronic circuits that follow the rules of Boolean logic, software containing patterns of instructions, or any combination of both.
[0022] The term "server" is used throughout the following description. Those skilled in the art will understand that a server is a computer program that provides services to other computer programs running on the same computer or processor on which the server application is running and / or to other computers or processors different from the computer or processor on which the server is running. Often, the computer or processor on which the server program is running is referred to as the server, although other programs and applications may also be running on the same computer or processor. It should be understood that servers form part of a server / client model. As such, a processor running a server program can act both as a client, requesting services from other programs, and as a server, providing services to other programs upon request. It should be understood that the computer or processor on which the server program is running may have access to other resources, such as memory, storage media, input / output devices, communication modules, etc.
[0023] Similarly, a cloud server is a server that provides shared services to various clients that access the cloud server over a network, such as a local area network or the Internet. In a cloud-based system, the server is remote from the clients, and the various clients share the resources of the cloud server. Information is passed by the clients to the server and returned to the clients over a network, usually the Internet.
[0024] The technology described herein provides a report to a sender (or sender administrator, or recipient of a compromised email account) as to whether and when they should suspect that one of the recipient's email mailboxes to which they are sending invoices or payment details has been compromised or is being eavesdropped on by cybercriminals, thus identifying this type of attack for the sender before it causes losses. The technology described herein is designed to help businesses become aware of compromised client mailboxes before the compromised (recipient's) mailbox results in spoofed emails and successful communications fraud.
[0025] The technology herein describes a method for detecting when a third party not associated with the original sender or intended recipient opens an email intended for the recipient and alerting the sender and / or sender administrator that a third party may have access to the recipient's email.
[0026] This technology describes how to generate electronic alerts and reports to the sender and / or sender administrators (or compromised recipients) that can provide an indication that the recipient's email mailbox has been compromised or that the recipient's emails have been intercepted.
[0027] The technology described herein helps identify cases where a recipient's email box has been unknowingly set to forward a copy of all emails received in that email box to an email box monitored by a cybercriminal, or where a cybercriminal somehow obtains a copy of emails received in the recipient's email account.
[0028] Generally, the present disclosure includes systems and methods for determining whether a sender's email is being intercepted by cybercriminals and notifying email senders and / or recipients that their communications may have been compromised.
[0029] In one aspect of the present invention, the present disclosure describes a system for determining whether a link configured to be automatically extracted in an email or an HTTP request generated by a user interaction with a link is activity of an intended recipient of the email. The system is configured to add a link to the email, and the link is configured to be automatically extracted when the email is opened by the recipient. Such opening of the email at the recipient may occur in various ways, not necessarily by the intended recipient, or even at the recipient, but rather because the email was forwarded or because a cybercriminal is copying all of the emails via an IMAP connection or creating a process to download all of the recipient's emails. Therefore, opening at the recipient can also be more broadly described as "activity" at the recipient (server), for example, a server programmed to extract all links in the email. One example of such activity may serve the purpose of testing to see if a link is associated with a known website that loads malware. All of these activities shall hereinafter be understood as opening of the email at the recipient.
[0030] The system includes a web server that can receive an HTTP request at an Internet address when the link is opened at the recipient. The web server may be coupled to a database that includes parameters and an analyzer that uses the parameters to make a determination as to whether returned data associated with the HTTP request includes indicators that the HTTP request was not initiated by the intended recipient.
[0031] In another aspect of the invention, the analyzer may be further configured to determine whether there are any additional HTTP request records in a location other than the location indicated by the sender of the email as being expected, and record that determination in a database associated with the analyzer.
[0032] The analyzer may be further configured to determine whether there are any additional HTTP request records located in a country different from the declared home country or determined home country of the initial recipient, and record that determination in a database associated with the analyzer.
[0033] The analyzer may be further configured to determine whether there are any additional HTTP request records located in a country different from the sender's home country, and record that determination in a database associated with the analyzer.
[0034] The analyzer may be further configured to determine whether there are any additional HTTP request records for country locations present in the list of countries as parameters in the analyzer, and record that determination in a database associated with the analyzer.
[0035] The analyzer may be further configured to determine whether there are any additional HTTP request records with the ISP or VPN provider IP ranges present in the list of ISP or VPN provider IP ranges or with recipient device information present in the list of recipient device information as parameters in the analyzer, and record the determination in a database associated with the analyzer.
[0036] The analyzer may perform any of the above analyses individually or in any combination.
[0037] The resulting output of the analyzer for any of the aforementioned analyses may be maintained in a report. The report may contain a summary of the sender's associated group's records and may be returned to an administrator associated with the sender. The report may be rendered tamper-evident. The report may contain portions of the HTTP records.
[0038] The report can be returned to the sender or to a user associated with the intended original recipient based on the reporting criteria. Alternatively, or in addition, the report may be returned to an administrator associated with the sender or an administrator specific to the specified reporting criteria based on the reporting criteria. Alternatively, or in addition, the report may be returned to a recipient address associated with the original transmission based on the reporting criteria.
[0039] This technology describes how to generate electronic alerts and reports for senders and / or sender administrators (or compromised recipients) that can provide an indication that a recipient's email mailbox has been compromised or that a recipient's email has been intercepted. The report can be used as evidence that an email has been intercepted, and as such, includes at least a portion of the data recorded from the HTTP connection and an analyzer's determination, or data mapped from the HTTP connection data that is cross-referenced with other data at the server. The report can also be digitally signed, encrypted, or have an encrypted hash or other identifier, allowing the contents of the report to be authenticated.
[0040] The technology described herein helps identify cases where a recipient's email box has been unknowingly set to forward a copy of all emails received in that email box to an email box monitored by a cybercriminal, or where a cybercriminal somehow obtains a copy of emails received in the recipient's email account.
[0041] Before cybercriminals find a suitable opportunity to attack, they may open a "forwarded" copy of the original email sent by the sender to the real recipient (a copy forwarded to the cybercriminal).
[0042] In either situation, if the email to the recipient is forwarded and opened, or forwarded, copied, and pasted, by the cybercriminal, there is HTTP open tracking data that can be collected from the linked image embedded in the email by the sender or the sender's server system and configured to automatically extract it, and if extracted at the recipient, the server associated with the link can capture data about the device and location from which the link was extracted.
[0043] HTTP data received when a recipient opens an email sent by a sender can be analyzed if the email has a link embedded in it and the link is configured for tracking. For example, if the link is configured to automatically display an image (or a pixel-sized white image, etc.) when the recipient opens the email, and the link is configured to automatically call a server associated with the link and return the image for display in the email at the recipient, or if the link is configured to call a server associated with the link and return the image for display in the email at the recipient when the recipient clicks on it. In either scenario, the server records HTTP data associated with the recipient who clicked on the link or automatically opened the link by opening the email displaying the image. This HTTP data includes tracking information, including the IP address associated with the Internet connection of the device on which the image sent from the server to the recipient is displayed, along with device and device software (e.g., browser) information.
[0044] In addition to the configurations described above, the system can be configured so that different senders or user administrators receive different types of alerts depending on the determined likelihood that the activity in the report is from an unauthorized third party.
[0045] Additionally, the system can be configured to work with REPLY to senders who use the system, which means that if a sender sends an email with this functionality, and the recipient replies, and the email is routed to the sender, the reply from the recipient to the sender can be captured by the system to detect email interception, even if the recipient is not registered as a user of the system.
[0046] The technology herein describes a method for detecting when a third party not associated with the original sender or intended recipient opens an email intended for the recipient and alerting the sender and / or sender administrator that a third party may have accessed the recipient's email.
[0047] As used herein, "overseas" refers to a country or region outside the sender's country or region, or a country or region outside the recipient's declared or determined home country or expected region.
[0048] The accompanying drawings that form a part of this specification are included to depict certain aspects of the present disclosure. A clear impression of the components and operation of the various embodiments of the present disclosure, as well as the systems provided therein, will be more readily apparent by reference to the exemplary, and therefore non-limiting, embodiments illustrated in the drawings. In the drawings, like reference numerals refer to like components. [Brief explanation of the drawings]
[0049] [Figure 1] 1 is a flow chart illustrating an embodiment of the present disclosure, namely, parsing HTTP data returned to a server upon opening an email. [Figure 2] 1 is a flowchart with schematic block elements illustrating an embodiment of the present invention, namely, analyzing HTTP data returned to a server upon opening, specifically from a foreign IP address. [Figure 3] 13 is a diagram of an exemplary email activity report generated by the process shown in FIG. 1, FIG. 2, FIGS. 5-7, or FIG. 12. [Figure 4] 13 is a diagram of an exemplary daily aggregate domain security report generated by the process shown in FIG. 1, FIG. 2, FIGS. 5-7, or FIG. 12. [Figure 5]1 is a flowchart illustrating an embodiment of the present disclosure, namely, detecting compromise of an email account by analyzing HTTP data returned to the server upon opening for changes in IP address. [Figure 6] FIG. 1 illustrates an embodiment of a flowchart illustrating an embodiment of the present disclosure: a home country comparison. [Figure 7] FIG. 1 illustrates an embodiment of a flowchart showing one embodiment of the present disclosure: high-risk countries. [Figure 8A] FIG. 10 is a detailed schematic diagram of a comparison of tamper detection reports when tampering is first detected. [Figure 8B] FIG. 10 is a detailed schematic diagram illustrating a comparison of opening detection reports when multiple openings are detected. [Figure 9] FIG. 10 is a partial view of an exemplary interface for specifying risk zones. [Figure 10] 2 is a diagram of an exemplary read receipt report generated by the process shown in FIG. 1. [Figure 11] 2 is a diagram of an exemplary desktop tray notification generated by the process shown in FIG. 1. [Figure 12] 1 is a block diagram illustrating a system and its functionality according to one embodiment of the present disclosure. [Figure 13] FIG. 1 is a schematic diagram of a computer or processing system that may be specifically modified according to various embodiments of the present disclosure. [Figure 14] 1 is a schematic diagram of a network used in accordance with various embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0050] The present disclosure and its various features and advantageous details will be more fully described with reference to exemplary, and therefore non-limiting, embodiments illustrated in the accompanying drawings and detailed in the following description. It should be understood, however, that the detailed description and specific examples, while indicating preferred embodiments, are given by way of illustration only and not by way of limitation. Detailed descriptions of known computer software, hardware, operating platforms, and protocols are omitted so as not to obscure the present disclosure in unnecessary detail. Various substitutions, modifications, additions, and / or rearrangements within the spirit and / or scope of the underlying inventive concepts will become apparent to those skilled in the art from this disclosure.
[0051] FIG. 1 shows an exemplary computer-implemented method for analyzing HTTP data returned to a server upon opening of an email by the intended original recipient and by a spoofer with, for example, a foreign IP address.
[0052] When an email is sent and detected as having been opened, a system operating on behalf of the sender can capture HTTP data that includes at least the IP address from which the email was opened. If the IP address corresponds to a country other than the sender's designated home country or declared safe country(ies), the system can be configured to generate and send a report to the sender or sender administrator alerting them that the email may have been hijacked or opened by someone other than the sender's intended recipient.
[0053] In this case, an "analyzer" analyzes the string content of the HTTP data record returned to a system server acting on behalf of the sender, and upon finding an indicator in the HTTP data record string related to an IP address, identifies a geolocation (e.g., country) associated with the IP address (e.g., by submitting the IP address to an IP geolocation database), and stores an indication as to whether an open was detected within a parameter time frame in a geographic IP location different from the identified location associated with the sender's designated safe or home region.
[0054] The analyzer then determines whether the system can trust the open detection as having been opened by the sender's intended recipient, or by a cybercriminal monitoring the recipient's email account.
[0055] Ultimately, the goal of this technology is to determine whether an unintended third party has opened a recipient's email and report the opening of such email to at least one of the following: (i) the sender, (ii) the sender administrator, or (iii) the recipient, which is then used as one or more indications to determine whether a copy of the message has been forwarded to a second system by an automatic forwarding rule, which may be an indication of a recipient email account takeover.
[0056] The steps of the system may additionally use techniques described in application Ser. No. 17 / 663,425, entitled "IDENTIFYING HTTP REQUESTS GENERATED FROM LINKS EMBEDDED IN EMAILS BY AUTOMATED PROCESSES," which is incorporated herein by reference in its entirety and summarized in more detail below.
[0057] In step 101, the system automatically adds a tracking link to the sender email. One way this can happen is by connecting to a link tracking server via an API upon clicking the send button, generating a unique link associated with the message, and embedding that link in the message at the sender or sending server before sending the message. Alternatively, the message may be directed for outbound routing through a service that adjusts the message content by adding such a tracking link.
[0058] In step 102a, the original intended recipient (or in step 102b, any subsequent recipient to whom the email is forwarded) receives and opens the email, which causes the tracking link server to record the opening of the email.
[0059] In step 103, the tracking link server records the HTTP data associated with each open or activity record and builds a database relating all tracking details associated with each open detection for each message sent. The database includes at least one of the following: (1) the IP address of the connection with the device that opened the email, parsed from the HTTP open tracking data; and (2) the sender's IP address, which can be parsed from the HTTP open tracking data or can be stored data. The sender's IP address can be detected by extracting the IP address information from the server when the message is delivered, or by sending the sender a test email asking them to activate a link in the email or click on a link / image to activate this feature. This sender's IP address can be used to programmatically determine the sender's "home country" or geolocation region.
[0060] In step 104, the analyzer determines the country associated with the IP address or range.
[0061] Additionally, in step 105, the analyzer compares the IP address captured in the HTTP open data at each open with an IP address geolocation table or system to record the geographic location of each open or activity.
[0062] In step 106, the analyzer results are added to a database, compiling at least the following: a) the country associated with the recipient's open, determined based on the IP address in the HTTP open detection, and b) the sender's country or sender's safe country, as declared by the sender or as determined based on the IP address range in the HTTP open detection. The analyzer proceeds to perform a comparative analysis for each message sent. First, based on the IP address or sender's declaration, the analyzer compares whether the recipient's country is different from the sender's country or the sender's declared home or safe geolocation for written communications with the intended recipient. If the locations are different, the analyzer outputs a report stating "International Activity (Based on Sender Location)." Second, the analyzer compares whether two opens associated with the same recipient email occurred in different countries. If the opens occurred in different countries, the analyzer outputs a report stating "International Activity (Based on Recipient Location)." Third, the analyzer generates a report for the sender and / or sender administrator that indicates the risk factor associated with each recipient of the message. If no foreign activity is identified, the report can indicate a risk level of "normal." If foreign activity is identified, the report can indicate a "potential risk."
[0063] In step 107, the report is sent to at least one of the following: (i) the sender; (ii) a sender administrator. In a preferred embodiment, the report can be authenticated in a known manner, thereby increasing its evidentiary value. Additionally or alternatively, the original message content and a uniform timestamp of sending, delivery, and / or opening can be cryptographically associated with the message report. In another preferred embodiment, the report includes transmission metadata or HTTP logs associated with email opening activity. The analyzer may be further configured to generate and send a supplemental alert if a message initially classified as "normal" is subsequently flagged as "foreign activity." Finally, if an email has multiple recipients, the report output can be organized as a table to easily identify the risk per recipient for each outgoing mail. This step may also be advantageous when the sent email is high-value, sensitive in nature, encrypted, or otherwise falls within a specified classification of email.
[0064] In another embodiment, the analyzer performs its function in response to at least one of the following: (i) links embedded in documents, (ii) other methods of tracking when a protected document or email attachment is opened, or (iii) when an HTML document or page is viewed, or (iv) when a download link is clicked. This embodiment is based on the system described in USPTO Patent Application No. 63 / 363,014, which is incorporated herein by reference in its entirety.
[0065] FIG. 2 illustrates a system and method according to the present invention showing the analysis of HTTP data returned to the server upon opening, specifically from a foreign IP address.
[0066] In step 200, the process begins with the sender initiating the sending of a message designated for service by the RMail system, or the system initiating the routing of the transmission. The RMail system is the system that operates this technology.
[0067] In step 201, the system ingests the message and automatically adds one or more tracking links to the sender email at the sender, at the sender's server, or at an intermediate server separate from the sender and separate from the recipient. Optionally, the system adds a header to the email configured to point the DSN to the system's email address. This is accomplished by connecting to a link tracking server via an API upon click of the send button, generating a unique link associated with the message, and embedding that link in the message before sending it. Alternatively, the message may be directed for outbound routing through a service that adjusts the message content by adding such tracking links.
[0068] In step 202, during the process of adding a tracker link to an email, the system obtains the tracker link by generating a unique link associated with the message and the image, which is embedded in the email and configured to be automatically extracted when the message is opened, which calls a server to deliver the image to the message on the device on which the message is opened.
[0069] In step 203a, the recipient (or any subsequent recipient to whom the email is forwarded, according to step 203b) receives and opens the email, which causes the tracking link server to record the open.
[0070] In step 204, the tracking link server records the HTTP data associated with each open and builds a database relating all tracking details associated with each open detection for each message sent. The database includes at least one of the following parsed from the HTTP open tracking data: (1) the IP address of the connection with the device that opened the email, and (2) the sender's IP address or the IP address of a sender-designated "home" or safe geolocation. The sender's IP address can be detected by extracting the IP address information from the server when the message is delivered, or by sending a test email to the sender asking them to activate a link in the email or click on a link / image to activate this feature, or the sender can declare a designated "home" or safe geolocation.
[0071] In step 205, the IP information is received and analyzed within the DSN of the system server to build a database relating all tracking details associated with each delivery notification detection for each message sent. This database includes at least the IP addresses of connections to servers or devices that receive or act on emails. These IP addresses are parsed from the DSN data.
[0072] In step 206, the HTTP information from the HTTP open tracks and DSNs received by the system via rerouting is analyzed to determine country locations. The analyzer identifies the country associated with the sender and the country associated with (i) each recipient open and / or (ii) each recorded (DSN) delivery. The analyzer compares the IP data captured for each open and delivery to an IP address geolocation table or system and records the geographic location. The IP address geolocation table may also be populated using an API connection to an external table.
[0073] In step 207, the system performs a comparison of the determined recipient IP address country with the sender's designated "home" country or countries, as well as with designated high-risk countries. This comparison function considers (1) the recipient country where the open click occurred based on the HTTP open detection IP address, (2) the delivery recipient country based on the DSN delivery IP address, and / or (3) the sender country based on the HTTP open detection IP address or IP range, or as otherwise declared by the sender. The comparative analysis performed by the analyzer for each sent message includes the following steps: (a) comparing whether the sender country is different from the recipient country or a declared safe or risk location based on the IP address or sender's declaration, and / or (b) comparing whether there are two opens associated with the same recipient email address and / or whether the country is a declared safe or risk location, if the opens occurred in different countries.
[0074] In step 208, for each message sent, the analyzer generates a report for the sender and / or sender administrator indicating a risk factor associated with the message sent to each recipient: (a) normal (if no foreign activity was identified), or (b) foreign activity (if a potential risk was identified). If the sender's country is determined to be different from the recipient's country, the analyzer outputs a report announcing "Foreign Activity (based on sender location)" or "Foreign Activity (based on declared home country)," or other notification. If two or more opens associated with the same recipient email address are determined to have occurred in different countries from each other, the analyzer outputs a report announcing, for example, "Foreign Activity (based on recipient location)."
[0075] In step 209, the report generated by the analyzer may be sent to at least one of the sender and a sender administrator.
[0076] The analyzer may be further configured to generate and send a supplemental alert if a message initially classified as "normal" is subsequently flagged as "foreign activity." Finally, if an email has multiple recipients, the report output can be compiled as a table to easily identify the risk per recipient for each outgoing mail. This step may also be advantageous if the outgoing email is high-value, sensitive in nature, encrypted, or otherwise falls within a specified classification of email.
[0077] In another embodiment, the analyzer performs its function in response to at least one of the following: (i) links embedded in documents, (ii) other methods of tracking when a protected document or email attachment is opened, or (iii) when an HTML document or page is viewed, or (iv) when a download link is clicked. This embodiment is based on the system described in USPTO Patent Application No. 63 / 363,014, which is incorporated herein by reference in its entirety.
[0078] FIG. 3 illustrates an exemplary email activity report 300, generated by, for example, the process illustrated in FIGS. 1, 2, 5-7, or 12.
[0079] The report generated by the described method can be returned in a variety of ways, including via email, a web portal, or within the receipt. Alternatively, the report may be attached to the receipt as a digitally signed PDF report with the receipt message ID. Alternatively, the report may be sent as a Windows tray or desktop alert. Yet another alternative is for the report to be dynamically updated in a web table or update view associated with the sent item. Regardless of the format in which the report is sent, it is advantageous for the report to be presented as a table containing the following fields for each recipient address: Delivery Status 315: Identifies how many unique activities have been detected associated with the message to the intended recipient(s) 305. Activity Classification 310: That is, whether the activity associated with the email was (a) normal or (b) high risk based on where or how the recipient acted on the email. Location classification 320: i.e., how many unique locations and how many activities occurred. Email age information 355: the age of the email at the time the report was generated; risk and message analysis details for each activity 325 for a particular message with a transaction ID 360, including the type of activity 330 that occurred for the message at each location 335, along with each network IP address and network provider name 345 of the location 340, and the determined risk level 350 of that activity, along with metadata 365 associated with these activities or the most recent activity to include parts of the message transport dialog and raw HTTP and DSN data.
[0080] Because certain activity detection parameters may not be useful for the purpose of detecting email interception, for example, due to automated system opening by security filters, it may be advantageous to perform additional analysis to minimize nuisance / false alerts. Certain activity detection parameters may be useful additional indicators or may detect email interception and overwrite location-related data. Exemplary relevant parameters to consider in this additional analysis include, for example: (M) = Activity is considered to be on a mobile device (CDN) = Email data delivered to a visitor by a Content Delivery Network. This is an example of information that may override location-related risk data and be deemed low risk. (VPN) = Activity was detected at the location of an anonymizing VPN endpoint. This is an example of information that may override location-related risk data and result in a high risk. Location = Registered location of detected network. Network = A registered network associated with the Internet Protocol.
[0081] These parameters can be used individually or in any combination to calculate a risk score. Various risk scores can be factored based on this data; for example, an international location detected via a content delivery network (CDN) may be scored as low risk, while a home location detected via a VPN anonymizer IP address may be scored as high risk.
[0082] To determine activity accessing email through a VPN anonymizer, the analyzer can parse the data through an additional database that specializes in VPN-related IP addresses versus geolocation, as shown in step 206 of FIG. 2.
[0083] To determine email access activity, browser or device information, or other data through the content delivery network, the analyzer may parse the data through additional databases that specialize in lists of networks or IP address ranges known to be content delivery network addresses versus geolocation, or that specialize in interpreting device and / or browser HTTP information, as shown in step 206 of FIG. 2.
[0084] Additional adjustments may need to be made to suppress reports of repeated opens at the same location within a parameter time period, and adjustments may also be needed to suppress activity recorded within a specified time from the initial send time.
[0085] Some additional parameters that may be considered in the analysis include: (S) = Activity determined to be caused by the server (E) = Activities considered to be professional user activities (M) = Activity determined to be associated with malicious data masking behavior (B) = Activity determined to be related to an automated script or bot
[0086] The parameters (S), (E), (B), and (M) each draw data from the user agent and identify attributes that may be associated with a high risk level. The (S) parameter can indicate when a specific high-risk server is associated with the activity, for example, adding a notation if the user agent contains "apache." The (E) parameter can indicate when software associated with specialized technical users is detected, for example, if the user agent contains "ubuntu," "baidu," or "Vivaldi." In addition to the notation, the risk level may be raised to "yellow" unless it is already "yellow" or "red." The (M) parameter can indicate when activity associated with malicious data masking behavior is detected, for example, if the user agent contains "meterpreter," which can automatically classify the activity as risk level "red." The (B) parameter can indicate activity associated with automated scripts, for example, if the user agent contains "script." Additionally, if the user agent contains commands closely associated with cybercrime, such as "nikto" or "dirb," the risk level may be raised to "yellow" unless it is already classified as "yellow" or "red."
[0087] The email activity report 300 may include the email addresses of the intended recipients 305, but this is the intended recipients of the original message transmission, rather than the addresses where all replies, forwards, deliveries, or opens of the message or parts of the message thread may have occurred. The report 300 may prominently display a determined risk level 310 based on the original sender's actual home location or the most recent activity geolocation associated with a declared safe area. Additionally, the report may detail the total number of activities and unique locations of the activity detected since the original email transmission. Furthermore, the report may list the email age 355, indicating the time elapsed since the original email transmission, for example, in days, hours, and minutes.
[0088] The report 300 may include tables detailing information about message opening, including time 325, activity 330, location and country 335, network address 340, network 345, and risk level 350. This allows for easy auditing of the exact date and time an activity occurred, what type of activity it was (e.g., email delivery or opening), and where the activity occurred (e.g., city, state, country) based on the activity's network IP address and network name. Based on this information, each activity includes a risk level classification, alerting the sender that their email communication may have been compromised. Further insights about the activity may be considered when assigning a risk level, such as whether the email was opened using a mobile device or a personal computer, or whether an anonymizing VPN was used. In embodiments where the risk analysis considers multiple parameters, the report 300 may also include an additional "reason" column (not shown) that indicates to the user why an activity is classified as "green," "yellow," or "red." For example, the "reason" column may explain that the activity was marked green because of the IP address range, not because of the location.
[0089] A transaction ID 360 can be assigned in activity reports to tie together multiple notifications associated with the same original email sent to the intended recipient. Transaction metadata 365 may also be included to give a user or IP administrator insight to perform further analysis.
[0090] If international activity is detected, a report may be generated for each recipient email address. The activity details may provide further information about the international activity detection, such as listing one or more countries (i) other than the sender's home country, (ii) if there are multiple recipient countries, and / or (iii) if at least one recipient country is not the same as the sender's country. Email alerts may be configured based on the appropriate activity type.
[0091] As shown in FIG. 4, a daily aggregate domain security report 400 can be generated to provide an aggregate activity report of all emails sent across sender domains of interest. This can include output identifying the highest risk level 405 across all messages sent from the sender domain during the reporting period, the total number of unique locations analyzed across all messages sent from the sender domain during the reporting period 410, and the total number of activities tracked at such locations 415 across all messages sent from the sender domain during the reporting period. The highest risk level can be determined by comparing all activity across all messages sent from the sender domain during the reporting period based on activity geolocation against the original aggregation of each sender's actual home location or declared safe zone, or other risk determination criteria, including, for example, activity from VPN anonymizers. The report 400 can further include a threat map 420 that highlights and / or pinpoints on a world map the locations where the highest risk level email opens or activity was identified.
[0092] Additionally, report 400 may include a risk analysis table 425 that includes a tabulated breakdown of the number or percentage of messages that were rated as having each risk level, for example, "green," "yellow," "red," etc. These statistics may be compared to statistics for a previous period, and a "delta" may be displayed detailing the trend in risk levels when compared.
[0093] The report 400 may additionally include a transmission statistics table 430 that contains tabulated transmission statistics for the following categories: number of unique centers, aggregate number of recipients, total activity analyzed, total unique Internet locations, median time to first activity, and geographic region of activity. These statistics may be compared to statistics for previous periods.
[0094] Additionally, report 400 may include an encryption features table 435, tabulating the percentage of each type of total messages sent encrypted, for example, by message type, e.g., certified e-delivery receipt, electronic signature, and / or file sharing. These statistics may be compared to statistics for previous periods.
[0095] When an email is sent and detected as having been opened, HTTP data can be captured by a system operating on behalf of the sender. The captured HTTP data includes, at a minimum, the IP addresses where the email was opened or otherwise acted upon. Additionally, if the IP addresses detected in one open are different from other open IP address detections because they are either (i) measured within a short period of time, (ii) not associated with the same ISP, or (iii) not associated within the same geolocation, the system can generate and send a report to the sender and / or sender administrators to alert them that the recipient's email account may have been compromised and that some of the opens detected at that recipient may not have been opened by the sender's intended recipient.
[0096] In this example, the analyzer is configured to perform the following functions: First, the analyzer analyzes the string content of the HTTP data record returned to the system server acting on behalf of the sender. Second, upon finding an indicator associated with an IP address in the HTTP data record string, identify the geolocation (e.g., country) associated with the IP address, parse the string in the set of characters parameter after this string indicator from a list (e.g., IP address range), and store an indication of whether opens were detected in different geographic IP locations within the parameter time frame. Third, the analyzer determines whether the system can trust the open detection as having been opened by the sender's intended recipient, or by a cybercriminal monitoring the recipient's email account.
[0097] Some recipients have email boxes equipped with inbound security systems ("bot clicks") that automatically click and test links, for example to check for malware. In this case, a location may be returned that is different from the location associated with the IP address from which the recipient opened the email. Therefore, analyzers must distinguish between three open detections: (1) intended recipient open detections, (2) bot click open detections, and (3) third-party eavesdropper open detections.
[0098] Additionally, some recipients access the Internet through ISPs that do not have a static link associated with the user. In this case, each new email open may display a different IP address within the IP range associated with the ISP, resulting in each open showing a different IP address. In this case, the analyzer may need to ensure that opens by the same recipient but with different IP addresses are not considered opens by a third party. This distinction can be based on detecting an IP location abroad (relative to the intended recipient's home country).
[0099] Additionally, some recipients legitimately forward emails to colleagues, which, when opened, may trigger open detections separate from those of the original intended recipient. Furthermore, colleagues may themselves have email boxes equipped with inbound security systems ("bot clicks") that automatically click and test links (for malware, etc.). In this case, the opening of a forwarded email by a colleague may return a different location than that associated with the IP address from which the forwarded recipient opened the email, or other matching data, such as a similar time frame, a common locale, country, network, and a different IP network address.
[0100] Ultimately, the goal of this technology is to determine if an unintended third party has opened or manipulated a recipient's email, thereby allowing reporting to the sender and / or sender administrator. This can then be used as an indication to determine if a copy of the message has been forwarded to a second system by an auto-forwarding rule or other IMAP / server connection to the original recipient's email account, which could be an indication of a recipient email account takeover.
[0101] The steps of the system may be techniques described in application Ser. No. 17 / 663,425, entitled "IDENTIFYING HTTP REQUESTS GENERATED FROM LINKS EMBEDDED IN EMAILS BY AUTOMATED PROCESSES," which is incorporated herein by reference in its entirety and summarized in more detail herein.
[0102] As shown in Figure 5, in step 501, the system automatically adds a tracking link to the sender email. This can be accomplished by connecting to a link tracking server via an API upon clicking the send button, generating a unique link associated with the message, and embedding that link in the message before sending it. Alternatively, the message may be directed for outbound routing through a service that adjusts the message content by adding such a tracking link.
[0103] In step 502a, the recipient (or any subsequent recipient to whom the email was forwarded, according to step 502b) receives and opens the email, which causes the tracking link server to record the open.
[0104] In step 503, the tracking link server records the HTTP data associated with each open and builds a database relating all tracking details associated with each open detection for each message sent. The database may include the following information parsed from the HTTP open tracking data: (a) the IP address of the connection with the device doing the opening, (b) a unified timestamp of each open (the tracking link server's time at the time the open detection link was extracted), (c) a device identifier for the device associated with each open detection, and (d) a system-configurable list of countries or regions ("high-risk regions") that the sender considers the recipient not relevant for the sender's business purposes.
[0105] In step 504, the analyzer can use the system described in application Ser. No. 17 / 663,425 to determine whether the open detection was a bot click, which indicates that the email was opened by a server rather than a human.
[0106] In step 505, the analyzer compares the IP address captured in the HTTP open data for each open to an IP address geolocation table or system and records the geographic location and internet service provider associated with each open detection, including whether the open detection was through an IP address associated with a virtual private network (VPN) provider or a list of specific VPN providers. This list may also include sublists, such as free VPN providers most likely to be used by cybercriminals. The analyzer may need to determine the geolocation of the VPN or ISP to which the IP address is attached or associated by passing the IP address to a third-party IP analyzer, which returns the IP address location and ISP data.
[0107] In step 506, the database is further compiled with the analyzer's output: (a) the geolocation of the open click, (b) whether the VPN of the open click was identified, (c) whether the VPN of the open click was on the VPN list, and, if applicable, (d) whether the click was a bot click or a human click. The analyzer begins performing a comparative analysis for each message sent. This comparative analysis proceeds by the analyzer comparing the geolocation for each determined HTTP open detection or human HTTP open detection associated with the message from the device's IP address in the HTTP open detection.
[0108] If the geolocation of the open is in a different country, the analyzer records the geolocation and reports the open as "overseas activity." If the geolocation of the human open is in a different country and one of the countries is in the high risk geographic table, the analyzer records the geolocation and reports the open as "high risk." If the geolocation of the human open is with a VPN found in the VPN list table, the analyzer records the geolocation and reports the open as "potential risk."
[0109] The analyzer then generates a report for each message sent to the sender and / or sender administrator indicating a risk factor associated with the recipient. The indicated risk factor may be at least one of the following, any combination thereof, or the highest applicable risk category: (a) normal, (b) multiple times, (c) overseas activity, (d) potential risk, or (e) high risk. Normal applies to cases where there is no overseas activity and the analyzer does not identify a high or potential risk. Multiple times applies to cases where there is no overseas activity and the analyzer does not identify a high or potential risk, but the IP address of at least one subsequent open detection is different from the previous open detection, indicating opens by multiple different people or multiple opens by the same person with a dynamic IP address on the opening device.
[0110] In step 507, this report is then sent to at least one of the following: (i) the sender, (ii) a sender administrator, or (iii) a recipient. In preferred embodiments, the report can be made verifiable in a known manner, thereby enhancing its evidentiary value. Additionally or alternatively, the original message content and uniform timestamps of sending, delivery, and / or opening can be cryptographically associated with the report of the message.
[0111] The analyzer may be further configured to generate and send a supplemental alert if a message initially classified as “normal” is subsequently flagged as (a) overseas activity, (b) potential risk, or (c) high risk.
[0112] Finally, if a given email has multiple recipients, the report output can be compiled as a table to easily identify the risk per recipient for each sent mail. This step may also be advantageous if the sent email is high value, sensitive in nature, encrypted, or otherwise falls within a specified classification of email.
[0113] In another embodiment, the analyzer performs its function in response to at least one of the following: (i) links embedded in documents, (ii) other methods of tracking when a protected document or email attachment is opened, or (iii) when an HTML document or page is viewed, or (iv) when a download link is clicked. This embodiment is based on the system described in USPTO Patent Application No. 63 / 363,014, which is incorporated herein by reference in its entirety.
[0114] Turning now to the embodiment shown in FIG. 6, the following steps are performed:
[0115] Step 601, the system adds a tracking link to the sender email.
[0116] In step 602, the recipient (or any subsequent recipient to whom the email was forwarded) receives and opens the email, which causes the tracking link server to record the open.
[0117] In step 603, the tracking link server records the HTTP data associated with each open and builds a database relating all tracking details associated with each open detection for each message sent.
[0118] In step 604, the analyzer accesses a table of home IP ranges.
[0119] In step 605, the analyzer may additionally compare the IP address captured by the HTTP open data for each open to an IP address geolocation table or system and record the geographic location and internet service provider associated with each open detection to identify if the open HTTP or DSN IP address is not within the home country IP range.
[0120] In step 606, the analyzer results are added to the database, and the analyzer generates a report based on the results. For example, the report notification may read: "Caution: Your email viewer is located overseas. If this is unexpected, it may mean that an eavesdropper is viewing your intended recipient's email."
[0121] In step 607, the analyzer sends the report to the sender and / or sender administrator.
[0122] Turning now to the embodiment shown in FIG. 7, the following steps are performed:
[0123] Step 701, the system adds a tracking link to the sender email.
[0124] In step 702, the recipient (or any subsequent recipient to whom the email was forwarded) receives and opens the email, which causes the tracking link server to record the open.
[0125] In step 703, the tracking link server records the HTTP data associated with each open and builds a database relating all tracking details associated with each open detection for each message sent.
[0126] In step 704, the analyzer accesses a table of senders that are determined to be IP ranges from high-risk countries.
[0127] In step 705, the analyzer also compares the IP addresses captured by the HTTP open data for each open to an IP address geolocation table or system, recording the geographic location and internet service provider associated with each open detection, to identify whether any open HTTP or DSN IP addresses are in one of the high-risk locations.
[0128] In step 706, the analyzer results are added to the database, and the analyzer generates a report based on the results. For example, the report notification may read: "Warning: The viewer of your email is located in an international location designated as a high-risk cybersecurity zone (view map). This may mean that the recipient's email account has been compromised or hijacked."
[0129] In step 707, the analyzer sends the report to the sender and / or sender administrator.
[0130] As a further embodiment, and a modification to the above embodiment, the sender's message header can be modified so that the DSN is routed to a server, which can parse the IP ranges at the recipient server and perform IP ranges based on the same overseas high-risk countries based on message delivery to unintended countries, high-risk countries, or overseas countries (forwarded messages).
[0131] The report generated by the described method can be returned in a variety of ways, including via email or within the receipt. Alternatively, the report may be attached to the receipt as a digitally signed PDF report with the receipt message ID. Alternatively, the report may be sent as a Windows tray or desktop alert. Yet another alternative is for the report to be dynamically updated in a web table or update view associated with the sent item. Regardless of the format in which the report is sent, it is advantageous for the report to be presented as a table containing the following fields: From the recipient address side, the fields can include: Delivery Status, Details, Activity, Activity Details, and Time. "Delivery Status" can specify whether the item was (a) delivered to the mail server, (b) delivered to the mailbox, (c) delivered and opened, or (d) failed. "Details" can list the IP address for each open.
[0132] The "activity" can specify whether the open was classified as (a) normal, (b) multiple, (c) international, (d) potential risk, or (e) high risk. These activity classifications correspond to the security risk outputs of the analyzer described above. The "activity details" can provide additional context to supplement the "activity" classification. For example, if the activity is classified as "multiple," the activity details can list the number of unique opens the email (i.e., the number of unique IP addresses detected as opening the email). If the activity is classified as "international," the activity details can list the country in which the email was opened. If the activity is classified as "potential risk," the activity details can list the VPN in which the open was detected. If the activity is classified as "high risk," the activity details can list or associate an image of the high-risk country in which the open was detected. The "time" can specify (a) the time of sending, (b) the time of delivery, (c) the time of the first open, and (d) the time of the most recent open.
[0133] Reports to the sender and / or sender's administrator can include a report with the recipient email address with fields for the activity and activity details. The "activity" can specify whether the open was classified as (a) overseas, (b) potential risk, or (c) high risk. The "activity details" can provide additional context to supplement the "activity" classification. For example, if the activity is classified as "overseas," the activity details can list the country in which the email was opened. If the activity is classified as "potential risk," the activity details can list the VPN in which the open was detected. If the activity is classified as "high risk," the activity details can list or associate an image of the high-risk country in which the open was detected. Additionally, configurable email alerts can be generated based on the activity type.
[0134] The report generated by the described method can be returned in a variety of ways, including via email or within the receipt. Alternatively, the report may be attached to the receipt as a digitally signed PDF report with the receipt message ID. Another alternative is for the report to be dynamically updated in a web table or update view associated with the sent item. Regardless of the format in which the report is sent, it is advantageous for the report to be presented as a table containing the following fields:
[0135] 8A and 8B illustrate the current simplified distribution method.
[0136] In step 800, a sender 810 creates and sends an email to at least one recipient.
[0137] In step 801, an email is sent to RMail 820 via an app, SMTP or API.
[0138] In step 802, an email is received by RMail 820 and prepared to be sent to at least one recipient 830 according to selected characteristics.
[0139] In step 803, RMail 820 uses one of the RMail features to deliver the email to the recipient's mail server.
[0140] In step 804, RMail 820 collects delivery and open tracking information and provides the sender 810 with a registered receipt email containing delivery details along with open tracking including open IP addresses if available.
[0141] In step 805, RMail 820 delivers a "read receipt" to sender 810 within 30 days of sending if: (a) there is no registered receipt for that email address in "delivered and opened" status, or (b) the email is detected to have been opened.
[0142] Figure 8B illustrates the case where an eavesdropper (IP2) opens the email in addition to the intended recipient (IP1). This case differs in that the "Details" column of the delivery status table lists two different IP addresses, corresponding to the addresses of the intended recipient (IP1) and the eavesdropper (IP2).
[0143] According to one aspect of the present invention, the system can be configured to generate specific outputs / alerts for additional tamper detections that meet certain threshold criteria.
[0144] In another aspect of the present invention, a new setting titled "Advanced Open Detection" can be enabled. This setting can be found at the bottom of the Settings section of RPortal (the sender management console for service settings), and access to this feature is grayed out for users other than Super Admins. This setting can be controlled via a checkbox; in the default, unchecked state, the system engages in the current open tracking behavior, but when checked, continuous open tracking is enabled.
[0145] RPortal may add a new setting titled "Advanced: Track Opens Per Tracked Message Duration." This setting may be found at the bottom of the RPortal Track and Prove settings section, and access to this feature is grayed out for users other than Super Admins unless the Advanced Open Detection box described above is checked. The setting may be controlled via a drop-down menu that lists time increments, such as (i) 7 days, (ii) 14 days, (iii) 30 days, and (iv) 60 days. A time period may also be specified as the default, such as a "30-day" setting.
[0146] A new setting titled "Open Detection Parameters" may be added to RPortal as a new setting. This setting may be found at the bottom of the RPortal Track and Prove settings section, and access to this feature will be grayed out for users other than Super Admins unless the Advanced Open Detection box is checked. This setting may be controlled via a drop-down menu, which lists the following choices: (i) "Report all opens," which may be designated as the default, and (ii) "Report unique IP opens only." The "Report all opens" choice may be set to report all opens regardless of IP address, while the "Report unique IP opens only" choice may be set to report only opens with a unique IP.
[0147] As shown in Figure 9, there may be further "control picklists" including a home country, high-risk countries, and a high-risk VPN list. The "home country" option identifies that "overseas" activity is not the same as home country. The "high-risk country" option flags high-risk opens associated with high-risk countries, which may vary based on the home country setting. This is because cybercriminals in certain countries are more likely to target users in certain countries based on geopolitical factors, for example. For example, a user whose home country includes the United States might have default high-risk countries including Nigeria, Ukraine, Russia, and China. Users can adjust the classification of each country to suit their business / communication practices. For example, if a user typically conducts regular business with Nigeria and therefore expects emails to be opened regularly in Nigeria, they can reclassify Nigeria from the high-risk "red" zone to a lower-risk classification, such as "yellow" or "green." Conversely, if a user is regularly targeted by a country not normally associated with a high-risk zone, the user may choose to reclassify that country into a high-risk "red" zone to suit their situation.
[0148] In one embodiment, zone classification can be customized based on at least one parameter other than country. For example, custom "green," "yellow," or "red" zones can be designated for a given CIDR or IP range, or for a given network. In another embodiment, zone classification can be based on location parameters other than country, such as city or state. This can be particularly advantageous for users who communicate, business or otherwise, with people in high-risk countries, because this classification can prevent false alerts from being triggered when communicating with their international contacts, while still providing alerts to potentially fraudulent activity originating from other cities or states within the country.
[0149] In another embodiment, preset policies may be included to provide special procedures for a list of specific countries. One example of a preset policy is a "hot zone policy," which automatically classifies countries with a high incidence of cybercrime activity, such as Nigeria, Russia, China, North Korea, and Ukraine, as "red" zones during an incident. Another exemplary preset policy is a "vacation spot policy" that includes popular vacation destinations in specific geographic regions, for which a "yellow" classification can be automatically downgraded to a "green" classification. For example, there may be a list of North and Central America, including countries such as Jamaica, the Bahamas, and Costa Rica, Mexican states such as Yucatan, Baja California Sur, and Quintana Roo, and territories such as the British Virgin Islands. Additionally, there may be a European list including popular tourist destinations such as France, the Netherlands, Italy, and the United Kingdom.
[0150] The high-risk VPN list may be a parameter utilized by a super admin to manage the list.
[0151] Additionally, there may be an "alert picklist," which can set threshold risk classifications to trigger the sending of alerts via email in real time to the RPortal customer administrator's email address. For example, the thresholds can be set for (i) yellow alerts or (ii) red alerts. Furthermore, each risk classification level can have a designated list of alert email recipients. For example, emails with a risk level of "green" may be sent only to the email sender, emails with a risk level of "yellow" may be sent additionally to designated IT professionals, and emails with a risk level of "red" may be sent additionally to the head of IT professionals or the entire IT department. This feature allows for a balance between reducing email flooding and providing proportional alert distribution to the determined risk level, thereby ensuring appropriate security measures are taken.
[0152] When the Advanced Open Tracking feature is enabled, the system behavior is adapted in the following ways:
[0153] Registered Receipts Report When an email is sent, RMail sends a registered receipt to the sender. If an email is sent to multiple people and a single recipient opens the email multiple times from different IP addresses before a registered receipt is generated, the system lists each IP address in the "Details" section of the delivery status table. This can happen, for example, if a recipient opens the email on a PC and a mobile device. However, if a recipient opens the email multiple times from the same IP address, the system lists that IP address only once. This configures the system to distinguish between multiple email opens caused by the intended recipient and multiple email opens that are instead due to an eavesdropper in addition to the intended recipient. The system is then configured to output a registered receipt report that reflects this distinction.
[0154] Read receipt report Depending on the open detection parameter settings, each time an email is opened, a open receipt 1000 may be generated, as shown in Figure 10. The open receipt 1000 may include various items of information relevant to identifying the severity of the risk. The open receipt 1000 may include an open detection IP line 1010 that lists the IP address from which the email was opened.
[0155] The open receipt 1000 may include a security level line 1020 that displays a security level identifier based on the analyzer's security rating. A security rating of "green" may be displayed for the first open of the email and all subsequent opens within the same IP or same home country list as the original open. A security rating of "yellow" may be displayed for all opens that are outside the original open IP address, for example, those identified as "overseas" or "potential risk." A security rating of "red" may be displayed for all opens that are outside the country of the original open address that is deemed "high risk" by the analyzer. It may also be advantageous to include links to knowledgeable articles that explain the meaning and significance of each security level rating.
[0156] The open receipt 1000 may additionally include an open detection reporting row 1030 that provides a button to cancel the open detection. In one embodiment, there may be a "Cancel open detection for this recipient" option that, when clicked, may provide a link to disable open detection for the incident recipient and email. However, open detection continues for other recipients of the email. There may also be a "Cancel open detection for this email" option that, when clicked, may provide a link to disable open detection for the incident email.
[0157] Advantageously, such links have a secondary process, so that if the link is clicked by a bot or sandbox click, the action is not recorded.
[0158] The report generated by the process shown in FIG. 1 and sent to the sender may be in the form of a desktop tray alert 1100, as shown in FIG. 11. Alternatively, it may be in the form of an SMS or other string message alert. It is common for people to open emails on both mobile devices and computers, each of which is identified by a unique IP address. The usage report should include the open IP in a new field. The usage report may display the IP address and open date and time for both the initial open and subsequent opens. Optionally, the usage report may be updated and sent daily as a scheduled report. This information may be sent as a string within the email body, as a string tabulated as an HTML table, and / or as a CSV file. This information may be advantageously added to future user reports. An exemplary desktop tray alert is shown in FIG. 11.
[0159] FIG. 12 shows a system and schematic diagram for eavesdropping detection. An email sender 1 sends an email 2 to an intended recipient 5. Upon sending the email 2, a link addition module 3, forming part of a system 11, adds at least one link 4 to the email. The link 4 can be configured to automatically extract data associated with the recipient 5 opening the email. The recipient 5 opens the email 2 and generates an HTTP request 6 that is sent to a web server 10. The web server 10 can include a processor 7, a database 8, and an analyzer 9. The system 11 can include the link addition module 3 and the web server 10. The processor can be programmed with hardware and / or software commands and can be configured to receive and process the HTTP request 6 received when the recipient opens the email. At least one database can be configured to include some relevant information associated with the opening of the email, such as IP ranges, location data, and / or other parameters described herein. The analyzer may be configured to interface with the processor and at least one database to perform an analysis and return an assessment as to whether the HTTP request generated by the opening of the email was initiated by the intended recipient or by an eavesdropper who is not the intended target of the email.
[0160] FIG. 13 illustrates an exemplary computer system 1300 that may be used in some embodiments of the present invention, which may be, for example, a server or client computer system. The computer system 1300 may take any suitable form, including, but not limited to, an embedded computer system, a system-on-chip (SOC), a single-board computer system (SBC) (e.g., a computer-on-module (COM) or system-on-module (SOM)), a laptop or notebook computer system, a smartphone, a personal digital assistant (PDA), a server, a tablet computer system, a kiosk, a terminal, a mainframe, a mesh of computer systems, or the like. The computer system 1300 may also be a combination of multiple forms. The computer system 1300 may include one or more computer systems 1300, may be monolithic or distributed, may span multiple locations, may span multiple systems, or may reside in a cloud (which may include one or more cloud components within one or more networks).
[0161] In one embodiment, computer system 1300 may include one or more processors 1301, memory 1302, storage 1303, input / output (I / O) interface 1304, communication interface 1305, and bus 1306. Although this disclosure describes and illustrates particular computer systems having particular numbers of particular components in particular arrangements, this disclosure contemplates other forms of computer systems having any suitable number of components in any suitable arrangement.
[0162] In one embodiment, processor 1301 includes hardware for executing instructions such as those constituting software. As used herein, references to software may encompass one or more applications, bytecode, one or more computer programs, one or more executable modules or APIs, one or more instructions, logic, machine code, one or more scripts, source code, etc., as appropriate. By way of example and not limitation, to execute instructions, processor 1301 may retrieve instructions from an internal register, an internal cache, memory 1302, or storage device 1303, decode and execute them, and then write one or more results to an internal register, an internal cache, memory 1302, or storage device 1303. In one embodiment, processor 1301 may include one or more internal caches for data, instructions, or addresses. Memory 1303 may be random access memory (RAM), static RAM, dynamic RAM, or other suitable memory. Storage 1305 may be a hard drive, floppy disk drive, flash memory, optical disk, magnetic tape, or any other form of storage device capable of storing data (including instructions for execution by a processor).
[0163] In one embodiment, storage device 1303 may be a mass storage device for data or instructions, which may include, but is not limited to, a HDD, a solid state drive, a disk drive, a flash memory, an optical disk (DVD, CD, Blu-ray, etc.), a magneto-optical disk, a magnetic tape, or any other hardware device that stores computer-readable storage media, data, and / or combinations thereof. Storage device 1303 may be internal or external to computer system 1300.
[0164] In one embodiment, input / output (I / O) interface 1304 includes hardware, software, or both for providing one or more interfaces for communication between computer system 1300 and one or more I / O devices. Computer system 1300 may have one or more of these I / O devices, as appropriate. By way of example and not limitation, I / O devices may include one or more mice, keyboards, keypads, cameras, microphones, monitors, displays, printers, scanners, speakers, cameras, touchscreens, trackballs, trackpads, biometric input devices or sensors, etc.
[0165] In yet another embodiment, communications interface 1305 includes hardware, software, or both that provide one or more interfaces for communication between one or more computer systems or one or more networks. Communications interface 1305 may include a network interface controller (NIC) or network adapter for communicating with an Ethernet or other wired-based network, or a wireless NIC or wireless adapter for communicating with a wireless network, such as a Wi-Fi network. In one embodiment, bus 1306 includes any hardware, software, or both that couples the components of computer system 1300 together.
[0166] FIG. 14 is a diagrammatic representation of an exemplary network 1400 that may be used to facilitate various embodiments of the present invention. The server 1405 is operated by a service organization 1420 and typically includes at least one processor, input and output equipment or devices, memory, storage, and communication interfaces. The server 1405 also operates under the control of specialized software program commands designed to execute the various processes described above. That is, while the exemplary network 1400 is described in terms of the server 1405 being operated by the service organization 1420, it should be understood that the server 1405 may be operated by a third party employed by the service organization or under the control of the service organization. The server 1405 may also be operated by a third party independent of the service organization, in which case the server 1405 provides information and / or data to the service organization, from which the service organization can provide services to its clients 1425.
[0167] Data storage device 1410, which may be separate from server 1405 but is not necessarily so, may be accessible to server 1405 and may be used to store date related information and any other data relevant to the operation of various embodiments of the systems and methods described above. Data storage device 1410 may be directly connected to server 1405 or may be accessible to server 1405 over a network or internet 1415. Data storage device 1410 may also be a virtual storage device or memory located in the cloud.
[0168] From the foregoing, it may be apparent that the various embodiments disclosed herein may be implemented by computers, servers, or other processors that appear to be organized as a conventional distributed processing system architecture, but the various embodiments disclosed herein are non-conventional because they bridge multiple remote information sources, such as legacy computer applications, legacy storage media, and workstation storage devices, media-resident data, and involve sophisticated analysis of various portions of email messages, as well as the methods, protocols, and communication paths used to send and receive email messages. Indeed, when the various embodiments of the present disclosure are operated with computers, servers, and processors, they transform those computers, servers, and processors into specially programmed computers, servers, and processors in ways that not only improve the operation of the various hardware and software components of the system, but also significantly improve the sending, receiving, and processing of email messages.
[0169] For the purposes of the present invention, there are technologies well known to those skilled in the art, and the methods for implementing the present invention will use technical components commonly used by those skilled in the art, so this description of the present invention will not describe the technology of these components. These include the use of: 1. Sender Email Client 2. Sender's mail server 3. Sender Mail Gateway 4. Secure Transmission Protocol 5. Recipient Mail Gateway 6. Recipient mail server 7. Part of a message a. Message Header b. Message Content 8. Message transmission protocols, including secure message transmission protocols 9. Data reports provided by email 10. Web Viewing of Data Reports 11. Encryption and Authentication Processes and Protocols 12. Use of software tools to extract content and create images of the content 13. Use of tools that create content that can be associated with HTML links and self-extracting HTML links inserted into emails. 14. Linking information in a database 15. Operating the software on web and email servers
[0170] As used herein, the term "email" can refer to any electronic message type, the term "email protocol" can refer to any electronic data exchange protocol, and the term "electronic file" can refer to any file.
[0171] While particular embodiments of the present disclosure have been described, it will be understood that various different modifications within the scope and spirit of the present disclosure are possible. The present disclosure is limited only by the appended claims.
[0172] The following describes the present invention and various preferred embodiments thereof:
[0173] Embodiment 1. A system 11 for determining whether an HTTP request 6 generated by a user interaction with an email is activity of an intended recipient 5, wherein a link 4 is embedded in the email and configured to automatically extract the link, said system comprising: a link 4 adding module 3 configured to add at least one link 4 to an email 2 sent by a sender, the link 4 being configured to automatically extract data associated with the link 4 when the email 2 is opened by a recipient 5; and A web server 10, a processor 7 programmed using hardware and / or software commands, the processor 7 configured to receive an HTTP request 6 at an internet address when the received email 2 is opened by a recipient 5, thereby automatically activating a link 4 configured to automatically extract data associated with the link 4; at least one database 8 containing parameters related to the opening of emails 2; an analyzer 9 configured to make a determination based on said parameters as to whether returned data associated with the HTTP request 6 includes an indicator that the HTTP request was not initiated by the intended recipient 5; Including web servers 10 System 11, comprising:
[0174] Embodiment 2. The system 11 of embodiment 1, wherein the analyzer 9 is further configured to determine whether there are any further HTTP request 6 records in a location other than the location indicated by the sender 1 of the email 2 as being an expected location, and record that determination in a database 8 associated with the analyzer 9.
[0175] Embodiment 3. The system 11 of embodiment 1 or 2, wherein the analyzer 9 is further configured to determine whether there are any further HTTP request 6 records in a location in a country different from the declared home country or determined home country of the first recipient, and record that determination in a database 8 associated with the analyzer 9.
[0176] Embodiment 4. The system 11 of one of embodiments 1 to 3, wherein the analyzer 9 is further configured to determine whether there are any further HTTP request 6 records in locations in a country different from the sender's home country and record that determination in a database 8 associated with the analyzer 9.
[0177] Embodiment 5. The system 11 according to one of embodiments 1 to 4, wherein the analyzer 9 is further configured to determine whether there are any further HTTP request 6 records for a country location present in the list of countries as a parameter in the analyzer 9, and record the determination in a database 8 associated with the analyzer 9.
[0178] Embodiment 6. The system 11 according to one of embodiments 1 to 5, wherein the analyzer 9 is further configured to determine whether there are any further HTTP request 6 records for an ISP or VPN provider IP range that is present in the list of ISP or VPN provider IP ranges as a parameter in the analyzer 9, and record the determination in a database 8 associated with the analyzer 9.
[0179] Embodiment 7. The system 11 according to one of embodiments 1 to 6, wherein the analyzer 9 is further configured to determine whether there is an HTTP request 6 record that includes device information present in the list of device information parameters in the analyzer 9, and record the determination in a database 8 associated with the analyzer 9.
[0180] Embodiment 8. The system 11 according to one of embodiments 1 to 7, wherein the results of the analyzer 9 are kept in a report 300.
[0181] Embodiment 9. The system 11 of embodiment 8, wherein the report 300 is returned to at least one of the sender 1 and an administrator associated with the sender 1.
[0182] Embodiment 10. The system 11 of embodiment 8 or 9, wherein the report 300 includes a summary of records for the sender 1's associated group.
[0183] Embodiment 11. A system 11 according to one of embodiments 8 to 10, wherein the report 300 is rendered in a tamper-detectable manner.
[0184] Embodiment 12. A system 11 according to one of embodiments 8 to 11, wherein the report 300 includes a portion of the HTTP record 6.
[0185] Embodiment 13. The system 11 according to one of embodiments 1 to 12, wherein the at least one database 8 includes a database of IP address ranges for individual countries.
[0186] Embodiment 14. The system 11 according to one of embodiments 1 to 13, wherein at least one database 8 includes a database of IP address ranges of high-risk virtual private network (VPN) networks, mobile devices, and high-risk content delivery networks (CDNs).
[0187] Embodiment 15. A method for determining whether a link configured to be automatically extracted in an email or an HTTP request generated by a user interaction with the link is activity of an intended recipient of the email, the method including: 1) Adding a tracking link 4 to the email sent 2; 2) recording the opening of the email 2 by one or more devices via a tracking link server 10; 3) extracting and analyzing HTTP data associated with the opening of email 2; 4) entering into a database HTTP data including at least the Internet Protocol (IP) addresses of connections to one or more devices that open email 2; 5) analyzing geolocation data associated with the intended recipient(s) 5 and the one or more devices that open the email 2; and 6) Carrying out comparative analysis to assess the risk of email interception.
[0188] Embodiment 16. 7) inputting the IP address of the sender 1 analyzed from the HTTP open tracking data into the database 8, and the comparative analysis is 8) comparing whether the recipient's country is different from the sender's country or the sender's declared home or safe geolocation based on the IP address or the sender's declaration; 9) if there are two opens associated with the same recipient email 2, comparing whether the opens occurred in different countries; and 10) generating a report 300 and sending the report 300 to the sender 1 and / or sender administrator, the report 300 indicating a risk factor associated with each recipient 5 of the email, the risk factor being calculated based on geolocation; inputting the IP address of the sender 1 into said database 8, 16. The method of embodiment 15, further comprising:
[0189] Embodiment 17. The risk factor is: The type of device on which email 2 was opened, whether a VPN was used, and Whether the click was generated by a human or a bot 17. The method of embodiment 16, further calculated based on at least one of:
[0190] Embodiment 18. The method according to one of embodiments 15 to 17, wherein the IP addresses captured by the HTTP open data are compared with an IP address geolocation database 8.
[0191] Embodiment 19. The method according to one of embodiments 15 to 18, further comprising the step of sending an alert 1100 when a given criterion is met.
[0192] Embodiment 20. receiving an HTTP request 6 associated with an email message ID of the opened email 2 at one or more devices that open the email 2; Extracting and parsing received HTTP data associated with the HTTP request; inputting HTTP data into a first database (8) as first information, the HTTP data including Internet Protocol (IP) addresses of connections with one or more devices that open the email (2) from the HTTP data; accessing a second database or a subsection of the first database 8, the second information including at least one of geolocation or network ownership data associated with an Internet Protocol (IP) address or other information in the HTTP data in the first information; accessing a third database or a further subsection of the first database 8, the third information including at least one of IP addresses, IP address ranges, network owners, or device user agent data flagged with a risk level indicative of at least one unauthorized third party interception of the email 2; comparing at least a portion of the first information with at least a portion of the third information, or comparing at least a portion of the second information with at least a portion of the third information, to determine whether at least a portion of the first information or at least a portion of the second information matches at least a portion of the third information; and generating a report with a risk indication that one or more devices opening the email 2 were not the intended devices if at least a portion of the first information or at least a portion of the second information matches at least a portion of the third information; The analyzer 9 is configured to perform the following steps. [Explanation of symbols]
[0193] 1. Sender 2. Email 3 Link Addition Module 4. Links 5. Recipients 6. HTTP Request 7 processors 8 Database 9 Analyzer 10 Servers 11 System 300 Email Activity Report 305 Intended Recipient 310 Activity Classification 315 Delivery Status 320 Place classification 325 Time Information 330 Activity Information 335 Location and Country Information 340 Network Address Information 345 Network Information 350 Risk Level Information 355 Email Age Information 360 Transaction ID 365 Transaction Metadata 400 Security Report 405 Highest Risk Level Output 410 Analyzed Activity Output 415 Analyzed Location Output 420 Threat Map 425 Risk Analysis Table 430 Transmission Statistics Table 435 Encryption Features Table 810 Sender 820 RMail 830 recipients 1000 Opening Receipt 1010 Opening detection IP line 1020 Security Level Line 1030 Open Detection Reporting 1100 Desktop Tray Alert 1300 Computer Systems 1301 processor 1302 memory 1303 Storage device 1304 I / O interface 1305 Communication Interface 1306 Bus 1400 Network 1405 Server 1410 Data storage device 1415 Internet / Network 1420 Provider 1425 Client
Claims
1. A system (11) for determining whether an HTTP request (6) generated by a user interaction with an email (2) is an activity of an intended recipient (5), wherein a link (4) is embedded in said email (2) and configured to automatically extract said link (4), said system comprising: a link (4) adding module (3) configured to add at least one link (4) to an email (2) sent by a sender, the link (4) being configured to automatically extract data associated with the link (4) when the email (2) is opened by a recipient (5); A web server (10), a processor (7) programmed using hardware and / or software commands, the processor (7) configured to receive an HTTP request (6) at an Internet address when the received email (2) is opened at the recipient (5), and to automatically activate the link (4) configured to automatically extract data associated with the link (4); at least one database (8) containing parameters related to the opening of emails (2); an analyzer (9) configured to make a determination based on the parameters as to whether the returned data associated with the HTTP request (6) includes an indicator that the HTTP request (6) was not initiated by the intended recipient (5); A web server (10) including A system (11) comprising:
2. 2. The system (11) of claim 1, wherein the analyzer (9) is further configured to determine whether there are any additional HTTP request (6) records in a location other than the location indicated by the sender (1) of the email (2) as being expected, and to record the determination in a database (8) associated with the analyzer (9).
3. 3. The system (11) of claim 2, wherein the analyzer (9) is further configured to determine whether there are any further HTTP request (6) records located in a country different from the declared or determined home country of the first recipient, and to record the determination in a database (8) associated with the analyzer (9).
4. 3. The system (11) of claim 2, wherein the analyzer (9) is further configured to determine whether there are any additional HTTP request (6) records located in a country different from the sender's home country and record the determination in a database (8) associated with the analyzer (9).
5. 3. The system (11) of claim 2, wherein the analyzer (9) is further configured to determine whether there are any further HTTP request (6) records for a country location present in a list of countries as a parameter in the analyzer (9) and to record the determination in a database (8) associated with the analyzer (9).
6. 3. The system of claim 2, wherein the analyzer is further configured to determine whether there are any additional HTTP request records for an ISP or VPN provider IP range present in a list of ISP or VPN provider IP ranges as parameters in the analyzer, and to record the determination in a database associated with the analyzer.
7. 3. The system (11) of claim 2, wherein the analyzer (9) is further configured to determine whether there is an HTTP request (6) record that includes device information present in a list of device information parameters in the analyzer (9), and to record the determination in a database (8) associated with the analyzer (9).
8. 2. The system (11) of claim 1, wherein the results of the analyzer (9) are maintained in a report (300).
9. 9. The system (11) of claim 8, wherein the report (300) is returned to at least one of the sender (1) and an administrator associated with the sender (1).
10. 10. The system (11) of claim 9, wherein the report (300) includes a summary of the records for a related group of senders (1).
11. The system (11) of claim 8, wherein the report (300) is rendered in a tamper-evident manner.
12. The system (11) of claim 8, wherein the report (300) includes a portion of the HTTP record (6).
13. 2. The system (11) of claim 1, wherein the at least one database (8) includes a database of IP address ranges for individual countries.
14. 10. The system of claim 1, wherein the at least one database includes a database of high-risk virtual private network (VPN) networks, mobile devices, and high-risk content delivery network (CDN) IP address ranges.
15. 1. A method for determining whether a link configured to be automatically extracted in an email (2) or an HTTP request (6) generated by a user interaction with a link is an activity of an intended recipient (5) of said email, said method comprising: 1) adding a tracking link (4) to the sent email (2); 2) recording the opening of said email (2) by one or more devices via a tracking link server (10); 3) extracting and analyzing HTTP data associated with the opening of said email (2); 4) entering said HTTP data, including at least Internet Protocol (IP) addresses of connections to said one or more devices that open said email (2), into a database; 5) analyzing geolocation data associated with the intended recipient (5) and the one or more devices that open the email (2); and 6) Conducting comparative analysis to assess the risk of email interception A method comprising:
16. 7) inputting into the database (8) the IP addresses of the senders (1) analyzed from the HTTP open tracking data, wherein the comparative analysis is 8) comparing whether the recipient's country is different from the sender's country or the sender's declared home or safe geolocation based on the IP address or sender's declaration; 9) if there are two opens associated with the same recipient email (2), comparing whether the opens occurred in different countries; and 10) generating a report (300) and sending said report (300) to said sender (1) and / or a sender administrator, said report (300) indicating a risk factor associated with each recipient (5) of said email, said risk factor being calculated based on geolocation; entering the IP address of the sender (1) into the database (8), 16. The method of claim 15, further comprising:
17. The risk factor is The type of device on which the email (2) was opened; Whether a VPN was used, and Whether the click was generated by a human or a bot The method of claim 16 , further calculated based on at least one of:
18. 16. The method of claim 15, wherein the IP addresses captured by the HTTP open data are compared to an IP address geolocation database (8).
19. The method of claim 15 further comprising sending an alert when a given criterion is met.
20. receiving an HTTP request (6) associated with an email message ID of the email (2) opened at one or more devices that open the email (2); extracting and parsing received HTTP data associated with said HTTP request (6); inputting the HTTP data into a first database (8) as first information, the HTTP data including Internet Protocol (IP) addresses of connections to the one or more devices that open the email (2) from the HTTP data; accessing a second database or a subsection of the first database (8) that includes second information, at least one of geolocation or network ownership data associated with the Internet Protocol (IP) address or other information in the HTTP data within the first information; accessing a third database or a further subsection of said first database (8) including third information, at least one of IP addresses, IP address ranges, network owners, or device user agent data flagged with a risk level indicative of at least one unauthorized third party interception of the email (2); comparing at least a portion of the first information with at least a portion of the third information, or comparing at least a portion of the second information with at least a portion of the third information, to determine whether at least a portion of the first information or at least a portion of the second information matches the at least a portion of the third information; and generating a report with a risk indication that the one or more devices opening the email (2) were not intended devices if at least a portion of the first information or at least a portion of the second information matches the at least a portion of the third information; an analyzer (9) configured to:
Citation Information
Patent Citations
Electronic mail processing apparatus, electronic mail processing method, and program
JP2004080134A
Systems and methods for global virtual networks
JP2018507639A
Behavioral tracking system and method in support of high-engagement communications
US20150294349A1
Filtering network traffic from automated scanners
US20210314269A1