Real-time Bulk Email Detection via Traffic Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-virus software filtration techniques are ineffective in real-time detection and prevention of bulk email messages, as spammers adapt their methods to evade filters, leading to significant manual intervention and resource burdens.

Innovation Solution

A detection server analyzes network traffic patterns of email messages against specified rates and thresholds to automatically assign statuses, enabling real-time detection and prevention of bulk messages without human intervention, by generating keys from message attributes and processing them based on assigned statuses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If filtration techniques are used to protect against viruses and spam, then computers are protected against unwanted messages, but spammers can adapt their messages to evade filters and manual intervention becomes necessary

Engineering Contradiction:
Improveprotection against unwanted messagesVSAvoidmanual intervention required
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system enables self-service by having the detection server automatically monitor network traffic patterns, generate keys from message attributes, compare them against expected patterns, and assign statuses without requiring manual intervention. The server monitors itself and takes automated actions based on predefined thresholds and rates.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback by continuously monitoring network traffic patterns, comparing actual patterns against expected patterns, and adjusting detection responses based on the results. The server receives feedback from message processing and uses this feedback to maintain accurate detection without manual reconfiguration.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual intervention is used to react to attacks, then filtration rules can be updated, but by the time intervention occurs, large numbers of unwanted messages have already been processed

Engineering Contradiction:
Improvefiltration effectivenessVSAvoidresponse time to attacks
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-configuring expected network traffic patterns, rates, and thresholds before attacks occur. The detection server is ready to immediately compare actual traffic against these pre-established patterns, enabling rapid detection and response without waiting for manual analysis of attack characteristics.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuity of useful action by continuously monitoring network traffic patterns in real-time without interruption. The detection server operates continuously, comparing each message's attributes against expected patterns, ensuring that no unwanted messages slip through undetected while waiting for manual intervention.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If commercial senders send millions of email messages, then business communication is enabled, but the marginal cost of sending messages becomes negligible and spam attacks increase

Engineering Contradiction:
Improvemessage sending volumeVSAvoidspam and phishing attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system applies parameter changes by monitoring specific parameters of network traffic patterns, such as message rates, timing intervals, and attribute distributions. By analyzing changes in these parameters against expected patterns, the system can distinguish between legitimate high-volume communication and spam attacks, enabling protection without blocking legitimate messages.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7734703B2Real-time detection and prevention of bulk messages
Publication Date: 2010.06.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7734703B2 patent drawing
  • US7734703B2 patent drawing
  • US7734703B2 patent drawing

AI summary

A method and system for detecting and preventing bulk messages in real-time is provided. A detection server detects and prevents bulk messages in real-time by analyzing the network traffic pattern of attributes of messages, such as email messages, that are passing through the network against an expected network traffic pattern. The expected network traffic pattern may be specified as a combination of a rate and one or more thresholds, where each threshold has a corresponding status. The rate specifies a quantity of an attribute measured with respect to a quantity of time. A status associated with a threshold is attained when the rate is exceeded the requisite threshold number of times. The status indicates an action that is to be taken in processing the email message containing the attribute. An email message can then be processed in accordance with a status assigned to an attribute of the email message.