Email Behavior Baselines for Account Compromise Investigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in mitigating sophisticated email threats due to the limitations of secure email gateways and the inability of security operations center analysts to manually address a high volume of threats in a timely and resource-efficient manner, especially in collaboration suites like Microsoft Office 365 and Google Workspace.

Innovation Solution

A threat detection platform that generates comprehensive records of digital activities performed with employee accounts, allowing for thorough investigations and remediation actions, including the use of machine learning models to identify abnormal behavior and generate threat intelligence feeds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If SOC analysts manually address threats using traditional tools, then they can investigate and remediate emails, but they cannot do so in a timely and resource-efficient manner due to the large number of threats

Engineering Contradiction:
Improvethreat remediation throughputVSAvoidresponse time per threat
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables self-service through automated threat detection and classification. The machine learning model automatically analyzes email content, identifies threats, and assigns priorities without requiring manual intervention from SOC analysts, allowing the system to serve itself in the initial assessment phase.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where SOC analysts can review and correct automated classifications, and this feedback is used to retrain and improve the machine learning model. This continuous feedback loop enhances the system's accuracy over time while maintaining analyst involvement for edge cases.

Inventive Principle:
Principle #23Feedback

2Reliability

If enterprises use secure email gateways to filter spam and malware, then they can block harmful content, but they cannot effectively examine the vast number of emails handled by collaboration suites

Engineering Contradiction:
Improveemail security filtering effectivenessVSAvoidemail examination capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces traditional mechanical filtering mechanisms with machine learning-based automated detection. The system uses trained models to analyze email content, sender behavior patterns, and communication contexts, substituting manual or rule-based filtering with intelligent automated systems that scale effectively.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the parameters of email analysis by examining multiple dimensions including sender reputation, message content, communication patterns, and contextual factors. This multi-parameter approach enables more comprehensive security assessment without proportionally increasing resource requirements.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If SOC analysts use AI and machine learning tools to stop sophisticated attacks, then they can improve threat detection, but they still lack the tools needed to review, investigate, and remediate emails efficiently

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidemail investigation efficiency
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system segments the email security workflow into distinct phases: automated threat detection, priority classification, analyst review, and remediation. This segmentation allows each phase to be optimized independently, with automation handling routine tasks and analysts focusing on complex cases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary layer between automated detection and manual response. This intermediary component provides enriched context, suggested actions, and prioritized threat lists to analysts, making the transition from automated detection to manual intervention smoother and more efficient.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260058981A1Investigation of threats using queryable records of behavior
Publication Date: 2026.02.26 ABNORMAL AI INC
  • US20260058981A1 patent drawing
  • US20260058981A1 patent drawing
  • US20260058981A1 patent drawing

AI summary

A method for behavior-based account compromise investigation may include obtaining data that is related to a series of email communications corresponding to an employee linked to an enterprise. The method may include generating, for the employee, a baseline based on the data that is related to the series of email communications, the baseline indicating normal email behavioral traits of the employee. The method may include obtaining a real time email communication corresponding to an account associated with the employee, the real time email communication comprising one or more signals. The method may include determining, based on the one or more signals and the baseline, whether the real time email communication is representative of the normal email behavioral traits of the employee. The method may include performing a first action with respect to the real time email communication.