Email Behavior Baselines for Account Compromise Investigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in mitigating sophisticated email threats due to the limitations of secure email gateways and the inability of security operations center analysts to manually address a high volume of threats in a timely and resource-efficient manner, especially in collaboration suites like Microsoft Office 365 and Google Workspace.
Innovation Solution
A threat detection platform that generates comprehensive records of digital activities performed with employee accounts, allowing for thorough investigations and remediation actions, including the use of machine learning models to identify abnormal behavior and generate threat intelligence feeds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If SOC analysts manually address threats using traditional tools, then they can investigate and remediate emails, but they cannot do so in a timely and resource-efficient manner due to the large number of threats
Solution Approach 1:
The system enables self-service through automated threat detection and classification. The machine learning model automatically analyzes email content, identifies threats, and assigns priorities without requiring manual intervention from SOC analysts, allowing the system to serve itself in the initial assessment phase.
Solution Approach 2:
The system implements feedback mechanisms where SOC analysts can review and correct automated classifications, and this feedback is used to retrain and improve the machine learning model. This continuous feedback loop enhances the system's accuracy over time while maintaining analyst involvement for edge cases.
2Reliability
If enterprises use secure email gateways to filter spam and malware, then they can block harmful content, but they cannot effectively examine the vast number of emails handled by collaboration suites
Solution Approach 1:
The patent replaces traditional mechanical filtering mechanisms with machine learning-based automated detection. The system uses trained models to analyze email content, sender behavior patterns, and communication contexts, substituting manual or rule-based filtering with intelligent automated systems that scale effectively.
Solution Approach 2:
The system changes the parameters of email analysis by examining multiple dimensions including sender reputation, message content, communication patterns, and contextual factors. This multi-parameter approach enables more comprehensive security assessment without proportionally increasing resource requirements.
3Measurement precision
If SOC analysts use AI and machine learning tools to stop sophisticated attacks, then they can improve threat detection, but they still lack the tools needed to review, investigate, and remediate emails efficiently
Solution Approach 1:
The system segments the email security workflow into distinct phases: automated threat detection, priority classification, analyst review, and remediation. This segmentation allows each phase to be optimized independently, with automation handling routine tasks and analysts focusing on complex cases.
Solution Approach 2:
The system introduces an intermediary layer between automated detection and manual response. This intermediary component provides enriched context, suggested actions, and prioritized threat lists to analysts, making the transition from automated detection to manual intervention smoother and more efficient.
Data Source
AI summary
A method for behavior-based account compromise investigation may include obtaining data that is related to a series of email communications corresponding to an employee linked to an enterprise. The method may include generating, for the employee, a baseline based on the data that is related to the series of email communications, the baseline indicating normal email behavioral traits of the employee. The method may include obtaining a real time email communication corresponding to an account associated with the employee, the real time email communication comprising one or more signals. The method may include determining, based on the one or more signals and the baseline, whether the real time email communication is representative of the normal email behavioral traits of the employee. The method may include performing a first action with respect to the real time email communication.


