Email Authenticity Analysis for Spear Phishing Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches to protect against phishing attacks are ineffective against spear phishing, as these attacks are precisely targeted and lack widespread distribution, making it difficult to warn users in advance and often appear genuine due to personalized information.

Innovation Solution

An email processing method that performs authenticity analysis on received messages, forwarding suspicious emails to an external central hub for closer review, which includes multi-factor analysis and manual inspection, enabling identification and remediation of spear phishing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional phishing warnings are applied to spear phishing attacks, then general user protection is maintained, but detection effectiveness deteriorates because spear phishing emails are precisely targeted and lack wide distribution

Engineering Contradiction:
Improvephishing detection effectivenessVSAvoidapplicability to targeted attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary authenticity analysis on incoming emails before they reach the user, evaluating multiple factors such as sender address, recipient address, subject line, and email content to identify spear phishing attacks in advance, allowing for proactive protection rather than reactive warnings

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An external central hub is introduced as an intermediary component that receives suspected phishing emails for closer manual review and analysis, separating the automated analysis function from the user interface and enabling specialized handling of targeted attacks without disrupting normal email flow

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If all emails are forwarded to external central hub for review, then detection accuracy is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improveauthenticity analysis accuracyVSAvoidemail processing system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Instead of forwarding all emails to the external central hub, the system applies partial action by forwarding only those emails that fail the automated authenticity analysis test, reducing processing overhead while maintaining high detection accuracy for suspicious messages

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The email processing system is segmented into multiple functional components: automated authenticity analysis module that performs initial screening, external central hub for manual review of suspected messages, and user notification system, allowing each component to handle specific tasks efficiently

Inventive Principle:
Principle #1Segmentation

3Reliability

If manual review of all emails is performed, then detection reliability is maximized, but processing time and operational cost increase

Engineering Contradiction:
Improvephishing identification reliabilityVSAvoidemail processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial manual review by sending only emails that fail automated analysis to the external central hub, rather than reviewing all emails manually, thus maintaining high reliability for suspicious messages while minimizing processing time and operational costs

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The automated authenticity analysis module performs self-service by independently evaluating email authenticity using multiple factors, reducing the burden on manual reviewers and enabling the system to handle the majority of emails automatically

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8752172B1Processing email messages based on authenticity analysis
Publication Date: 2014.06.10 EMC IP HLDG CO LLC
  • US8752172B1 patent drawing
  • US8752172B1 patent drawing
  • US8752172B1 patent drawing

AI summary

A technique processes an email message. The technique involves receiving the email message from a network, and performing an authenticity analysis operation to determine authenticity of the email message. The technique further involves forwarding a copy of the email message to an external central hub through the network when a result of the authenticity analysis operation indicates that the email message is not authentic, and refraining from sending the copy of the email message to the external central hub through the network when the result of the authenticity analysis operation indicates that the email message is authentic. Such an embodiment is well suited for identifying spear phishing attacks within email messages routinely handled by an email server.