BEC Email Detection Using Peer Models for New Employees
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Business Email Compromise (BEC) detection processes are inadequate for new employees due to insufficient data on trust relationships, making them vulnerable to sophisticated phishing attacks, which often go undetected for months.
Innovation Solution
An email security detection system that utilizes relationship models of peers, reporting hierarchies, and conversation histories to analyze incoming emails, applying algorithms to identify potential BEC attacks by determining the intent and likelihood of malicious intent based on the relationships and past interactions of email recipients.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing BEC detection processes relying on past email conversation history are used, then detection accuracy for established employees is maintained, but detection accuracy for new employees deteriorates due to insufficient data
Solution Approach 1:
The system pre-establishes trust relationship models for new employees before they receive emails, using organizational data such as reporting hierarchies, team memberships, and peer relationships from HR systems. This preliminary population of trust data eliminates the need to wait for conversation history to accumulate, enabling immediate BEC detection capability for new hires
Solution Approach 2:
The system introduces an intermediary trust relationship model that bridges the gap between new employees and the BEC detection system. This model uses organizational structure data as an intermediary layer to establish trust relationships without requiring direct email conversation history, allowing the detection system to evaluate incoming emails against predefined trust parameters
2Measurement precision
If relationship models of peers and reporting hierarchies are applied, then detection accuracy for new employees is improved, but system complexity increases
Solution Approach 1:
The trust relationship model is segmented into distinct modular components: reporting hierarchy relationships, peer relationships, team member relationships, and manager relationships. Each segment can be independently configured and evaluated, allowing the system to build detection accuracy through multiple independent relationship dimensions without creating an unmanageably complex monolithic model
Solution Approach 2:
The relationship model framework is designed to be universal across different organizational structures and employee types. The same model infrastructure handles reporting hierarchies, peer relationships, and team memberships uniformly, allowing the system to scale to different organizations without requiring complete model redesign, thereby managing complexity through standardized multi-functional components
Data Source
AI summary
Techniques for an email-security detection system to analyze incoming emails for Business Email Comprise (BEC) attacks of targeted new email users in an enterprise based on peer models of email recipients in an enterprise and the conversation history of recipients. A method is disclosed that includes analyzing an incoming email and identifying one or more recipients of the incoming email in an enterprise network; analyzing contextual information in the incoming email for the email intent, and associating the email with a target recipient; applying a relational model associated with peers of the target recipient for detecting whether the incoming email is a business email compromise (BEC) attack directed to the target recipient; applying a relationship model of other recipients of the incoming email for detecting whether the BEC attack is associated with the target recipient; and determining, whether the incoming email is a BEC attack.


