AI Email Account Takeover Detection via Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email security solutions are ineffective in detecting email account takeover attacks as they cannot monitor or stop internal emails, and traditional gateway-based systems only filter external communications, failing to identify malicious signals from compromised accounts.

Innovation Solution

An AI engine/classifier continuously monitors communication patterns via API calls to detect and remediate email account takeover attacks by analyzing sender and recipient identities, forwarding rules, IP logins, and link information, enabling real-time detection and remediation of compromised accounts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional gateway-based email security solutions are used, then external email communications are filtered, but internal emails from compromised accounts cannot be monitored or stopped

Engineering Contradiction:
Improveemail security detection capabilityVSAvoidmonitoring scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The AI engine is designed to perform multiple functions: it monitors both external and internal email communications, detects account takeover attempts, analyzes communication patterns, and remediates compromised accounts. This multi-functional approach allows the system to address the limitation of traditional gateway-based solutions that only handle external communications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system transitions from a single-layer gateway filtering approach to a multi-dimensional monitoring system that operates at multiple levels: external email filtering, internal email monitoring, communication pattern analysis, and account behavior tracking. This dimensional expansion enables comprehensive detection of account takeover attacks regardless of email origin.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If emails from compromised accounts are analyzed using traditional methods, then legitimate sender headers are assumed safe, but malicious signals are missed

Engineering Contradiction:
Improveemail security operationVSAvoidmalicious signal detection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

Instead of assuming emails from known senders are legitimate (traditional approach), the system inverts the assumption by treating all emails as potentially suspicious and analyzing them for anomalous patterns. The AI engine looks for deviations from normal communication behaviors rather than relying on sender reputation, enabling detection of compromised accounts that appear legitimate.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system continuously monitors communication patterns and uses feedback from analyzed emails to refine detection accuracy. By tracking sender-recipient relationships, response patterns, and communication frequency over time, the AI engine learns normal behaviors and can identify subtle deviations that indicate account compromise, improving detection precision without false positives.

Inventive Principle:
Principle #23Feedback

3Reliability

If real-time detection of email account takeover is implemented, then attacks can be prevented, but system complexity increases

Engineering Contradiction:
Improveattack prevention capabilityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The AI engine performs self-learning and self-adjustment by automatically analyzing communication patterns and adapting to new attack methods without requiring manual configuration or intervention. The system autonomously identifies anomalous behaviors, makes detection decisions, and triggers remediation actions, reducing operational complexity while maintaining high detection reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The AI engine acts as an intermediary layer between email systems and security responses. It receives email data, analyzes patterns, and mediates between detection and remediation actions by automatically triggering alerts, blocking suspicious communications, or notifying users. This intermediary role simplifies the overall system architecture by centralizing complex analysis functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10778717B2System and method for email account takeover detection and remediation
Publication Date: 2020.09.15 BARRACUDA NETWORKS INC
  • US10778717B2 patent drawing
  • US10778717B2 patent drawing

AI summary

A new approach is proposed that contemplates systems and methods to support email account takeover detection and remediation by utilizing an artificial intelligence (AI) engine/classifier that detects and remediates such attacks in real time. The AI engine is configured to continuously monitor and identify communication patterns of a user on an electronic messaging system of an entity via application programming interface (API) calls. The AI engine is then configured to collect and utilize a variety of features and/or signals from an email sent from an internal email account of the entity. The AI engine combines these signals to automatically detect whether the email account has been compromised by an external attacker and alert the individual user of the account and/or a system administrator accordingly in real time. The AI engine further enables the parties to remediate the effects of the compromised email account by performing one or more remediating actions.