Arabic Phishing Email Detection Using IoC Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures struggle to effectively detect Arabic phishing emails due to a lack of categorization for non-English phishing patterns, making it difficult to identify malicious intent in these emails.

Innovation Solution

A method and system that integrates a spam repository with a log management solution to identify and flag potential phishing emails by using Indicators of Compromise (IoCs) derived from confirmed Arabic phishing emails, assigning authenticity scores, and generating reports for remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security measures (spam filters, security software) are used to detect phishing emails, then general phishing detection is provided, but detection effectiveness for Arabic phishing emails deteriorates due to lack of categorization for non-English patterns

Engineering Contradiction:
Improvephishing detection effectivenessVSAvoiddetection capability for non-English patterns
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by creating a specialized detection mechanism for Arabic phishing emails distinct from general English phishing detection. The system uses Arabic NLP models and locale-specific IoC databases to provide tailored detection for Arabic language patterns, subject lines, and cultural context specific to Arabic phishing campaigns, thereby improving reliability for this specific language while maintaining general detection capabilities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the phishing detection system into separate functional components: a general phishing detection module and a specialized Arabic phishing detection module. The Arabic module independently processes Arabic language content, extracts locale-specific indicators, and uses separate NLP models, allowing optimized detection for Arabic patterns without compromising the performance of other language detections.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If Indicators of Compromise (IoCs) are used to identify phishing emails, then detection precision is improved, but the complexity of the detection system increases

Engineering Contradiction:
Improvephishing email identification accuracyVSAvoiddetection system structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements universality by designing a multi-functional IoC database that serves multiple purposes: storing general phishing indicators, maintaining Arabic-specific IoCs, and providing both filtering and scoring capabilities. The same IoC framework handles both English and Arabic phishing detection, reducing the need for separate systems while maintaining high precision through localized indicator sets.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary scoring mechanism that mediates between raw IoC matches and final phishing determination. The authenticity score calculator acts as a mediator that processes multiple IoC matches, applies weighting factors, and produces a unified risk assessment, simplifying the overall decision-making process while maintaining detection precision through structured evaluation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a comprehensive IoC database is maintained for phishing detection, then detection capability is enhanced, but data management and system updates become more complex

Engineering Contradiction:
Improvephishing detection capabilityVSAvoiddata management operations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by implementing real-time IoC database updates through automated feeds from spam repositories and threat intelligence sources. The system dynamically adds new Arabic phishing indicators, removes outdated ones, and adjusts IoC weights based on emerging phishing patterns, maintaining high detection capability while simplifying management through automation rather than manual curation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements self-service through automated IoC collection mechanisms that autonomously gather phishing indicators from spam repositories, email headers, and threat intelligence feeds. The system automatically processes and indexes new IoCs, eliminating the need for manual data entry and reducing operational complexity while maintaining comprehensive detection coverage through continuous self-updating.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260067331A1Method of detecting potential arabic phishing emails
Publication Date: 2026.03.05 SAUDI ARABIAN OIL CO
  • US20260067331A1 patent drawing
  • US20260067331A1 patent drawing
  • US20260067331A1 patent drawing

AI summary

A method for detecting Arabic phishing emails includes connecting a log management solution to an email management solution that includes a spam repository and one or more emails. The spam repository includes one or more Indicators of Compromise (IoCs) that is digital information associated with a cyberattack. An IoC index of the log management solution is populated with the IoCs. The log management solution searches the emails using the IoC index and flags one or more potential phishing emails when an email matches an IoC in the IoC index. The log management solution assigns an authenticity score to each of the potential phishing emails and generates a potential phishing email report containing the potential phishing emails and the authenticity score assigned to each of the potential phishing emails. Based on the potential phishing email report, an assigned user performs one or more remediation actions.