AI Email Account Takeover Detection via Internal Pattern Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email security solutions are ineffective in detecting email account takeover attacks as they only monitor external communications and cannot identify malicious signals in emails sent from compromised internal accounts, leading to significant financial losses, with over $12 billion worth of assets lost due to such incidents.

Innovation Solution

A system utilizing an AI engine that continuously monitors communication patterns and signals within an organization's email accounts through API calls, combining features like sender and recipient identities, forwarding rules, and IP logins to detect and remediate email account takeovers in real-time, capable of examining both internal and external messages to identify anomalous activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional gateway-based email security solutions are used, then external email communications can be filtered, but internal emails from compromised accounts cannot be detected

Engineering Contradiction:
Improveemail security detection capabilityVSAvoidmonitoring scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from gateway-based external email filtering to internal mail server-based monitoring, adding a new dimensional capability to detect emails within the organization's internal network. This allows the system to monitor both incoming external emails and outgoing internal emails from compromised accounts, resolving the limitation of traditional solutions that only handle external communications.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If emails from compromised accounts are monitored using traditional solutions, then malicious external emails can be blocked, but legitimate-looking internal emails cannot be identified as malicious

Engineering Contradiction:
Improvemalicious email detectionVSAvoidmalicious signal identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements feedback mechanisms by continuously monitoring email patterns, user behaviors, and account activities. When anomalies are detected (such as unusual sending patterns, unfamiliar recipients, or abnormal login locations), the system feeds this information back to update detection models and trigger alerts, enabling dynamic identification of compromised accounts even when emails appear legitimate.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary analysis layer between the mail server and users that examines email metadata, sender behavior patterns, and account activity without interfering with normal email flow. This intermediary component detects malicious signals by analyzing patterns rather than relying solely on content filtering, allowing identification of compromised accounts sending legitimate-looking emails.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If real-time monitoring of all email communications is implemented, then account takeovers can be detected quickly, but system complexity and resource consumption increase

Engineering Contradiction:
Improvereal-time detection capabilityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of monitoring all email communications equally, the system applies partial monitoring by focusing on specific indicators of compromise such as unusual sending patterns, abnormal login locations, unfamiliar recipients, and changes in account behavior. This selective approach enables real-time detection of account takeovers without requiring comprehensive analysis of every email, thereby reducing system complexity while maintaining effective detection capability.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11159565B2System and method for email account takeover detection and remediation
Publication Date: 2021.10.26 BARRACUDA NETWORKS INC
  • US11159565B2 patent drawing
  • US11159565B2 patent drawing

AI summary

A new approach is proposed that contemplates systems and methods to support email account takeover detection and remediation by utilizing an artificial intelligence (AI) engine/classifier that detects and remediates such attacks in real time. The AI engine is configured to continuously monitor and identify communication patterns of a user on an electronic messaging system of an entity via application programming interface (API) calls. The AI engine is then configured to collect and utilize a variety of features and/or signals from an email sent from an internal email account of the entity. The AI engine combines these signals to automatically detect whether the email account has been compromised by an external attacker and alert the individual user of the account and/or a system administrator accordingly in real time. The AI engine further enables the parties to remediate the effects of the compromised email account by performing one or more remediating actions.