Dynamic URL Replacement for Phishing Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack effective methods to provide comprehensive visibility into persistent threats and efficiently detect and neutralize malicious emails, particularly those designed to deceive users into revealing sensitive information through spoofed or phishing attacks.

Innovation Solution

A cloud-based threat detection system that processes emails by analyzing links for potential malicious resources, replacing them with safe alternatives, and generating threat insight dashboards to track and visualize metrics on malicious attacks, thereby preventing user exposure and providing administrators with actionable remediation insights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional email filtering systems are used, then basic spam detection is provided, but they lack effective detection of sophisticated phishing attacks and provide insufficient visibility into persistent threats

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary cloud-based threat detection system that sits between users and malicious resources. This intermediary analyzes URLs dynamically, performs safe navigation, and provides visibility dashboards without requiring complex local installation on user devices. The intermediary handles the complexity of threat detection centrally while providing simple user-facing email clients.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary analysis of URLs and emails before users interact with them. By pre-analyzing links and performing safe navigation in advance, the system identifies malicious content before it can harm users, improving detection accuracy without requiring complex real-time analysis on user devices.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive threat analysis is performed on all emails, then detection accuracy improves, but processing time and system resources increase

Engineering Contradiction:
Improvemalicious email detection accuracyVSAvoidemail processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial analysis to all emails (basic filtering) and excessive/detailed analysis only to suspicious emails that match threat patterns. This selective approach maintains fast processing for legitimate emails while performing comprehensive analysis only when necessary, balancing accuracy with processing time.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system uses feedback from threat dashboards and detection results to continuously improve filtering accuracy. By learning from detected threats and updating detection rules, the system improves precision over time without increasing processing time for each individual email, as the learning occurs in the background.

Inventive Principle:
Principle #23Feedback

3Loss of information

If users are provided with detailed threat information, then awareness and remediation capability improve, but user experience may deteriorate due to alarm fatigue

Engineering Contradiction:
Improvethreat visibilityVSAvoiduser experience
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system provides detailed threat information locally at the dashboard level where administrators need it, while keeping the user email interface clean and simple. Different quality levels of information are provided to different user groups based on their needs, maintaining good user experience for end users while providing comprehensive visibility to security personnel.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments threat information delivery by user role and context. Administrators receive comprehensive threat dashboards with detailed metrics, while end users receive simplified notifications only when necessary. This segmentation prevents alarm fatigue for general users while maintaining full visibility for security personnel who need the detailed information.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10616272B2Dynamically detecting abnormalities in otherwise legitimate emails containing uniform resource locators (URLs)
Publication Date: 2020.04.07 PROOFPOINT INC
  • US10616272B2 patent drawing
  • US10616272B2 patent drawing
  • US10616272B2 patent drawing

AI summary

Dynamically detecting abnormalities in otherwise legitimate emails containing Uniform Resource Locators (URLs) is provided. An example method includes determining one or more rules defining normal patterns in a number of sending Top-Level Domains of previously received emails received via a computer network to a user or group of users; generating a trusted trends criteria for a received email, associated with the user or the group of users, by evaluating the received email against the one or more rules; determining whether the trusted trends criteria exceeds a predetermined threshold; in response to exceeding the predetermined threshold, generating a second URL and applying it to the received email by replacing a first URL of the received email with the second URL; and redetermining the one or more rules defining normal patterns in the number of sending Top-Level Domains based on the previously received emails and the received email.