Decoy Email Account for Internal Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to effectively detect and prevent the internal propagation of malicious software within trusted networks, as spam recognition engines do not block emails from trusted sources, leading to potential widespread infection before detection.
Innovation Solution
Implementing a decoy email account system within the trusted network, where a detector decoy email account is set up to bait malicious software, and a policy-based infection response is generated upon detection, isolating infected systems to prevent further propagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If spam recognition engine is used to block unsolicited emails, then external malware propagation is prevented, but internal malware propagation within trusted network is not detected
Solution Approach 1:
The system segments the network into probe accounts and decoy accounts, with each segment serving a specific detection function. Probe accounts monitor for malware attempts while decoy accounts provide bait, creating multiple detection zones that work together to identify internal malware propagation without blocking legitimate communications.
Solution Approach 2:
The patent introduces intermediary components including a probe account that acts as a mediator between external threats and internal systems, and a decoy account that mediates between legitimate users and malware. These intermediaries enable detection of internal malware propagation while maintaining normal network operations.
2Measurement precision
If anti-virus signatures are updated to detect malware, then known malware is detected, but zero-day worms and polymorphic malware remain undetected
Solution Approach 1:
The system performs preliminary actions by setting up probe and decoy accounts in advance that automatically detect and report malware attempts. This preliminary detection mechanism operates continuously before anti-virus signature updates are applied, eliminating the time delay between malware emergence and detection.
Solution Approach 2:
The patent implements feedback mechanisms where probe and decoy accounts continuously monitor network traffic and provide real-time information about malware attempts. This feedback loop enables immediate detection and response to both known and unknown malware, including zero-day worms and polymorphic variants.
3Productivity
If spam filter updates content filtering engine with unsolicited email addresses, then external spam is blocked, but emails from infected trusted addresses pass through
Solution Approach 1:
Instead of blocking emails based on sender reputation as traditional spam filters do, the patent inverts the approach by using probe and decoy accounts to actively seek out and identify malware attempts. This inversion allows the system to distinguish between legitimate emails from trusted addresses and malicious emails by detecting the presence of malware rather than relying on address reputation.
Data Source
AI summary
Embodiments of the invention provide a method and an apparatus for detecting and responding to email based propagation of malicious software (malware) in a trusted network. One embodiment provides a detector decoy email account to serve as generic bait for malicious software for a domain within the trusted network. In addition, at least one email account for the domain within the trusted network is provided as a detector probe account. In so doing, when the detector decoy email account receives an email from the detector probe account within the trusted network a policy based infection response rule is generated.


