Messaging Security Gateway Doppelganger Domain Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network and mail security solutions are ineffective in preventing doppelganger domain name attacks, which exploit typographical errors or similar domain names to intercept sensitive information, posing a growing threat to email security.

Innovation Solution

A system and method that monitor and secure outbound email communications by checking domain names against a global doppelganger database, preventing transmission to unacceptable domain names and allowing transmission to acceptable ones, using a network device with a messaging security gateway that evaluates domain names against local and global lists, and dynamically verifies domain names using tools like WHOIS.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing network and mail security solutions are used, then basic email security is provided, but doppelganger domain name attacks cannot be prevented

Engineering Contradiction:
Improveemail securityVSAvoiddoppelganger domain name attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of domain names against multiple databases (WHOIS, doppelganger database, blacklists, whitelists) before allowing email transmission. This advance checking prevents harmful domain names from being used in email communications, resolving the contradiction by proactively blocking attacks before they occur rather than reacting after security solutions are in place

Inventive Principle:
Principle #10Preliminary action

2Reliability

If domain name verification against multiple databases is performed, then doppelganger attacks are prevented, but system complexity increases

Engineering Contradiction:
Improvedomain name validationVSAvoidsecurity system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces intermediary components including a messaging security gateway and domain name validation module that mediate between email sending and receiving. These intermediaries handle the complex verification process against multiple databases (WHOIS, doppelganger database, blacklists, whitelists), isolating the complexity from the core email transmission function while maintaining high reliability in domain name validation

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If outbound email monitoring and domain name checking is implemented, then sensitive information protection is improved, but email transmission time increases

Engineering Contradiction:
Improvesensitive information protectionVSAvoidemail transmission time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs domain name verification against trusted databases (WHOIS, doppelganger database, blacklists, whitelists) before email transmission occurs. By completing the security checking in advance, the actual email transmission can proceed quickly without repeated verification delays, thus protecting sensitive information while minimizing time loss during transmission

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9521114B2Securing email communications
Publication Date: 2016.12.13 FORTINET INC
  • US9521114B2 patent drawing
  • US9521114B2 patent drawing
  • US9521114B2 patent drawing

AI summary

Methods and systems are provided for securing email communications. According to one embodiment, a network device receives an outbound email originated by a computing device of an internal network and directed to a target recipient. It is determined whether a domain name of the target recipient is present in a global doppelganger database. When the domain name is determined to be present in the global doppelganger database, transmission of the outbound email to the target recipient is prevented if the domain name is an unacceptable domain name and transmission of the the outbound email to the target recipient is permitted if the domain name is an acceptable domain name.