Behavior Query Records for Investigating Enterprise Email Threats

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in mitigating sophisticated email threats due to the limitations of secure email gateways and the inability of security operations center analysts to manually address a large volume of threats in a timely and resource-efficient manner, particularly in collaboration suites like Microsoft Office 365 and Google Workspace.

Innovation Solution

A threat detection platform that generates comprehensive records of digital activities performed with employee accounts, allowing for thorough investigations and remediation actions, including the use of machine learning models to identify abnormal behavior and generate threat intelligence feeds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure email gateways are used to filter spam and block malware, then email security is improved, but the ability to detect sophisticated attacks in collaboration suites deteriorates

Engineering Contradiction:
Improveemail securityVSAvoiddetection capability for sophisticated attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces traditional mechanical email filtering mechanisms with machine learning-based behavioral analysis systems. The system uses ML models to detect sophisticated attacks by analyzing user behavior patterns, communication metadata, and interaction contexts rather than relying solely on signature-based filtering, enabling adaptation to novel attack vectors in collaboration suites.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the detection parameters from static black/white lists to dynamic behavioral metrics. By continuously monitoring parameters such as communication frequency, timing patterns, recipient relationships, and content characteristics, the system adapts its detection capabilities to identify sophisticated attacks that evade traditional filters.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If SOC analysts manually address threats, then threat response is improved, but productivity deteriorates due to large volume of threats

Engineering Contradiction:
Improvethreat response qualityVSAvoidthreat addressing throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service threat detection and classification by automatically analyzing communications and assigning risk levels. The machine learning models autonomously evaluate threats, reducing the manual workload on SOC analysts while maintaining high response quality through automated preliminary assessment and prioritization.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary threat analysis and classification before human intervention is needed. By pre-processing communications through machine learning models and preparing prioritized threat lists, the system enables SOC analysts to focus only on high-risk items, significantly improving overall productivity without sacrificing response quality.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive monitoring of digital activities is implemented, then threat detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex monitoring function into separate modular components: data collection modules for different communication channels, machine learning analysis modules for different threat types, and prioritization modules for different risk levels. This segmentation reduces overall system complexity by allowing independent development, testing, and optimization of each component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal platform that handles multiple communication channels (email, chat, video conferencing) and various threat detection functions through a single integrated machine learning framework. This multi-functional approach reduces complexity compared to maintaining separate specialized systems for each communication type and detection task.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260058982A1Investigation of threats using queryable records of behavior
Publication Date: 2026.02.26 ABNORMAL AI INC
  • US20260058982A1 patent drawing
  • US20260058982A1 patent drawing
  • US20260058982A1 patent drawing

AI summary

A method for threat detection may include obtaining data related to a series of email communications corresponding to employees linked to an enterprise. The method may include identifying an attribute of each email communication in the series of email communications indicative of a potential threat associated with a respective email communication. The method may include generating a series of records by populating a data structure with a record of each email communication including a respective attribute. The method may include obtaining a first criterion for record retrieval, the first criterion indicating one or more attributes corresponding to the series of records. The method may include retrieving one or more records of the series of records that satisfy the first criterion. The method may include generating a graphical user interface associated with the one or more records including information associated with email communications corresponding to the one or more records.