Messaging Security Gateway Doppelganger Domain Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network and mail security solutions are ineffective in preventing doppelganger domain name attacks, which exploit typographical errors or similar domain names to intercept sensitive information, posing a growing threat to email security.
Innovation Solution
A system and method that monitor and secure outbound email communications by checking domain names against a global doppelganger database, preventing transmission to unacceptable domain names and allowing transmission to acceptable ones, using a network device with a messaging security gateway that evaluates domain names against local and global lists, and dynamically verifies domain names using tools like WHOIS.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing network and mail security solutions are used, then basic email security is provided, but doppelganger domain name attacks cannot be prevented
Solution Approach 1:
The system performs preliminary verification of domain names against multiple databases (WHOIS, doppelganger database, blacklists, whitelists) before allowing email transmission. This advance checking prevents harmful domain names from being used in email communications, resolving the contradiction by proactively blocking attacks before they occur rather than reacting after security solutions are in place
2Reliability
If domain name verification against multiple databases is performed, then doppelganger attacks are prevented, but system complexity increases
Solution Approach 1:
The patent introduces intermediary components including a messaging security gateway and domain name validation module that mediate between email sending and receiving. These intermediaries handle the complex verification process against multiple databases (WHOIS, doppelganger database, blacklists, whitelists), isolating the complexity from the core email transmission function while maintaining high reliability in domain name validation
3Loss of information
If outbound email monitoring and domain name checking is implemented, then sensitive information protection is improved, but email transmission time increases
Solution Approach 1:
The system performs domain name verification against trusted databases (WHOIS, doppelganger database, blacklists, whitelists) before email transmission occurs. By completing the security checking in advance, the actual email transmission can proceed quickly without repeated verification delays, thus protecting sensitive information while minimizing time loss during transmission
Data Source
AI summary
Methods and systems are provided for securing email communications. According to one embodiment, a network device receives an outbound email originated by a computing device of an internal network and directed to a target recipient. It is determined whether a domain name of the target recipient is present in a global doppelganger database. When the domain name is determined to be present in the global doppelganger database, transmission of the outbound email to the target recipient is prevented if the domain name is an unacceptable domain name and transmission of the the outbound email to the target recipient is permitted if the domain name is an acceptable domain name.


