Decoy Email Account for Internal Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively detect and prevent the internal propagation of malicious software within trusted networks, as spam recognition engines do not block emails from trusted sources, leading to potential widespread infection before detection.

Innovation Solution

Implementing a decoy email account system within the trusted network, where a detector decoy email account is set up to bait malicious software, and a policy-based infection response is generated upon detection, isolating infected systems to prevent further propagation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If spam recognition engine is used to block unsolicited emails, then external malware propagation is prevented, but internal malware propagation within trusted network is not detected

Engineering Contradiction:
Improveexternal malware blockingVSAvoidinternal malware detection
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system segments the network into probe accounts and decoy accounts, with each segment serving a specific detection function. Probe accounts monitor for malware attempts while decoy accounts provide bait, creating multiple detection zones that work together to identify internal malware propagation without blocking legitimate communications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including a probe account that acts as a mediator between external threats and internal systems, and a decoy account that mediates between legitimate users and malware. These intermediaries enable detection of internal malware propagation while maintaining normal network operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If anti-virus signatures are updated to detect malware, then known malware is detected, but zero-day worms and polymorphic malware remain undetected

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddetection delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by setting up probe and decoy accounts in advance that automatically detect and report malware attempts. This preliminary detection mechanism operates continuously before anti-virus signature updates are applied, eliminating the time delay between malware emergence and detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where probe and decoy accounts continuously monitor network traffic and provide real-time information about malware attempts. This feedback loop enables immediate detection and response to both known and unknown malware, including zero-day worms and polymorphic variants.

Inventive Principle:
Principle #23Feedback

3Productivity

If spam filter updates content filtering engine with unsolicited email addresses, then external spam is blocked, but emails from infected trusted addresses pass through

Engineering Contradiction:
Improvespam filtering efficiencyVSAvoidinternal malware propagation
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Instead of blocking emails based on sender reputation as traditional spam filters do, the patent inverts the approach by using probe and decoy accounts to actively seek out and identify malware attempts. This inversion allows the system to distinguish between legitimate emails from trusted addresses and malicious emails by detecting the presence of malware rather than relying on address reputation.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS7636944B2Method and apparatus for detecting and responding to email based propagation of malicious software in a trusted network
Publication Date: 2009.12.22 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7636944B2 patent drawing
  • US7636944B2 patent drawing
  • US7636944B2 patent drawing

AI summary

Embodiments of the invention provide a method and an apparatus for detecting and responding to email based propagation of malicious software (malware) in a trusted network. One embodiment provides a detector decoy email account to serve as generic bait for malicious software for a domain within the trusted network. In addition, at least one email account for the domain within the trusted network is provided as a detector probe account. In so doing, when the detector decoy email account receives an email from the detector probe account within the trusted network a policy based infection response rule is generated.