AI Email Account Takeover Detection via Internal Mail Server Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email security solutions are ineffective in detecting email account takeover attacks, as emails from compromised accounts appear to come from legitimate senders, lacking malicious signals, and cannot monitor or stop internal emails, leading to undetected attacks and privacy concerns with data anonymization affecting model accuracy.

Innovation Solution

A system utilizing an AI engine that continuously monitors user communication patterns on electronic messaging platforms via API calls, collecting and analyzing signals such as sender and recipient identities, IP logins, and link information to detect compromised accounts in real-time, allowing for immediate remediation by blocking or quarantining malicious emails and resetting mailbox rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional gateway-based email security solutions are used, then they can filter external emails, but they cannot detect emails from compromised internal accounts and cannot monitor internal email traffic

Engineering Contradiction:
Improvedetection capabilityVSAvoidmonitoring scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from gateway-based external filtering to internal mail server integration, adding a new dimension of monitoring capability. The system integrates with the internal mail server to access and analyze internal email traffic, enabling detection of compromised accounts that traditional gateway solutions cannot identify.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces an intermediary component that bridges the gap between external security solutions and internal email systems. This intermediary integrates with the mail server infrastructure, allowing security analysis of internal communications without disrupting existing email flow or requiring fundamental changes to the email system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If user login data is collected for detection models, then detection accuracy improves, but privacy concerns arise requiring data anonymization which reduces model accuracy

Engineering Contradiction:
Improvedetection accuracyVSAvoidprivacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts only the necessary features for detection from user login data, separating detectable behavioral patterns from personally identifiable information. By taking out only the essential detection-relevant features while excluding sensitive personal data, the system maintains detection accuracy without compromising user privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different quality levels to different data elements, preserving detailed information where needed for detection while anonymizing elements where privacy is concerned. This local differentiation allows the system to maintain high detection accuracy for behavioral patterns while protecting sensitive personal identifiers through selective anonymization.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11563757B2System and method for email account takeover detection and remediation utilizing AI models
Publication Date: 2023.01.24 BARRACUDA NETWORKS INC
  • US11563757B2 patent drawing
  • US11563757B2 patent drawing
  • US11563757B2 patent drawing

AI summary

A new approach is proposed to support account takeover (ATO) detection based on login attempts by users. The approach relies on assessing fraudulence confidence level of login IP addresses to classify the login attempts by the users. A plurality of attributes/features in one or more user login data logs are extracted and used to build a labeled dataset for training a machine learning (ML) model that relies on statistics of the login attempts to classify and detect fraudulent logins. These attributes make it possible to ascertain if a login attempt or instance by a user is suspicious based on the ML model. In some embodiments, the ML model is trained using anonymized user login data to preserve privacy of the users and a proper level of data anonymization is determined based on the ML model's accuracy in detecting the ATO attacks when trained with different versions of the anonymized data.