Dynamic Message Analysis for Compromised Domain URL Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise security systems struggle to effectively identify compromised domains and impersonated domains in electronic communications, particularly within and between organizations, while balancing network security with computing resource constraints.
Innovation Solution
A computing platform applies a security scoring process to endpoint relationships, computes weighted security scores, and tags compromised relationships, rewriting URLs from compromised endpoints to open in an isolation environment, and executes enhanced protection actions based on these scores.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If comprehensive message analysis is performed to identify compromised domains, then security detection capability is improved, but computing resource consumption increases
Solution Approach 1:
The system segments domain analysis by identifying relationships between internal enterprise domains and external domains. Instead of analyzing all domains uniformly, it focuses on specific endpoint relationships that exist within the enterprise's supply chain or communication network, dividing the analysis into relationship-specific segments that can be evaluated independently with reduced computational overhead.
Solution Approach 2:
The system applies different analysis depths to different endpoint relationships based on their security risk profiles. By computing weighted security scores for each relationship and applying enhanced protection actions selectively to high-risk relationships, the system concentrates computing resources on areas of greatest need rather than uniformly analyzing all communications.
2Reliability
If enhanced protection actions are applied to all endpoint relationships, then security coverage is improved, but system complexity increases
Solution Approach 1:
The system applies enhanced protection actions selectively to only those endpoint relationships that exceed a predetermined security score threshold, rather than applying comprehensive protection to all relationships. This partial action approach maintains security coverage for high-risk areas while reducing system complexity by avoiding unnecessary protection mechanisms for low-risk relationships.
Solution Approach 2:
The system performs preliminary security scoring and relationship identification before applying enhanced protection actions. By pre-computing security scores and identifying compromised domains in advance, the system prepares protection measures only where needed, reducing the complexity of real-time decision-making and enabling more straightforward implementation of protection actions.
3Object-affected harmful factors
If URL rewriting to isolation environment is implemented, then threat mitigation is improved, but processing time increases
Solution Approach 1:
The system performs URL rewriting and isolation environment preparation in advance, before users attempt to access potentially malicious URLs. By pre-identifying compromised domains and pre-configuring isolation environments for high-risk URLs, the system reduces the time penalty during actual user interactions, as the protective infrastructure is already in place rather than being created on-demand.
Solution Approach 2:
The system introduces an intermediary isolation environment that sits between users and potentially malicious URLs. Instead of directly blocking or allowing access, the intermediary environment safely renders and previews URLs, allowing threat mitigation without requiring extensive real-time processing when users interact with messages, as the intermediary has already performed preliminary safety checks.
Data Source
AI summary
Aspects of the disclosure relate to dynamic message analysis using machine learning. A computing platform may apply a security scoring process to an endpoint relationship to compute a weighted security score for the endpoint relationship. Subsequently, the computing platform may determine a weighted grade for the endpoint relationship based on the weighted security score for the endpoint relationship. Based on identifying that the weighted grade exceeds a predetermined threshold, the computing platform may tag the endpoint relationship as compromised. Subsequently, the computing platform may monitor an electronic messaging server to detect messages corresponding to the compromised endpoint relationship. Based on detecting that the electronic messaging server has received a first message, corresponding to an endpoint of the compromised endpoint relationship, the computing platform may rewrite a URL included in the first message to point to a security service that is configured to open the URL in an isolation environment.


