Dynamic URL Replacement for Phishing Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack effective methods to provide comprehensive visibility into persistent threats and efficiently detect and neutralize malicious emails, particularly those designed to deceive users into revealing sensitive information through spoofed or phishing attacks.
Innovation Solution
A cloud-based threat detection system that processes emails by analyzing links for potential malicious resources, replacing them with safe alternatives, and generating threat insight dashboards to track and visualize metrics on malicious attacks, thereby preventing user exposure and providing administrators with actionable remediation insights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional email filtering systems are used, then basic spam detection is provided, but they lack effective detection of sophisticated phishing attacks and provide insufficient visibility into persistent threats
Solution Approach 1:
The patent introduces an intermediary cloud-based threat detection system that sits between users and malicious resources. This intermediary analyzes URLs dynamically, performs safe navigation, and provides visibility dashboards without requiring complex local installation on user devices. The intermediary handles the complexity of threat detection centrally while providing simple user-facing email clients.
Solution Approach 2:
The system performs preliminary analysis of URLs and emails before users interact with them. By pre-analyzing links and performing safe navigation in advance, the system identifies malicious content before it can harm users, improving detection accuracy without requiring complex real-time analysis on user devices.
2Measurement precision
If comprehensive threat analysis is performed on all emails, then detection accuracy improves, but processing time and system resources increase
Solution Approach 1:
The system applies partial analysis to all emails (basic filtering) and excessive/detailed analysis only to suspicious emails that match threat patterns. This selective approach maintains fast processing for legitimate emails while performing comprehensive analysis only when necessary, balancing accuracy with processing time.
Solution Approach 2:
The system uses feedback from threat dashboards and detection results to continuously improve filtering accuracy. By learning from detected threats and updating detection rules, the system improves precision over time without increasing processing time for each individual email, as the learning occurs in the background.
3Loss of information
If users are provided with detailed threat information, then awareness and remediation capability improve, but user experience may deteriorate due to alarm fatigue
Solution Approach 1:
The system provides detailed threat information locally at the dashboard level where administrators need it, while keeping the user email interface clean and simple. Different quality levels of information are provided to different user groups based on their needs, maintaining good user experience for end users while providing comprehensive visibility to security personnel.
Solution Approach 2:
The system segments threat information delivery by user role and context. Administrators receive comprehensive threat dashboards with detailed metrics, while end users receive simplified notifications only when necessary. This segmentation prevents alarm fatigue for general users while maintaining full visibility for security personnel who need the detailed information.
Data Source
AI summary
Dynamically detecting abnormalities in otherwise legitimate emails containing Uniform Resource Locators (URLs) is provided. An example method includes determining one or more rules defining normal patterns in a number of sending Top-Level Domains of previously received emails received via a computer network to a user or group of users; generating a trusted trends criteria for a received email, associated with the user or the group of users, by evaluating the received email against the one or more rules; determining whether the trusted trends criteria exceeds a predetermined threshold; in response to exceeding the predetermined threshold, generating a second URL and applying it to the received email by replacing a first URL of the received email with the second URL; and redetermining the one or more rules defining normal patterns in the number of sending Top-Level Domains based on the previously received emails and the received email.


