Email Behavior Records for Internal Threat Investigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in mitigating sophisticated email threats due to the limitations of secure email gateways and the inability of security operations center analysts to manually address a large volume of threats in a timely and resource-efficient manner, with existing defenses being largely ineffective against business email compromise campaigns, especially those originating from within the enterprise.
Innovation Solution
A threat detection platform that generates comprehensive records of digital activities performed with employee accounts, including safe and unsafe activities, enabling SOC analysts to perform thorough investigations and remediate threats through integrated interfaces, while employing machine learning models to identify abnormal behavior and generate threat intelligence feeds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure email gateways are used to filter spam and block malware, then email security is improved, but the system becomes ineffective against sophisticated business email compromise campaigns and internal threats
Solution Approach 1:
The patent replaces traditional mechanical/email-based filtering mechanisms with AI/ML-based behavioral analysis systems. Instead of relying on static spam filters and malware blocks, the system uses machine learning models to analyze digital behavior patterns, detect anomalies, and identify sophisticated threats including business email compromise and internal threats that evade conventional security measures.
Solution Approach 2:
The system changes the detection parameters from static content-based filtering to dynamic behavior-based analysis. By monitoring changes in digital behavior patterns over time and comparing them against established baselines, the system can detect sophisticated attacks that modify their behavior to evade traditional filters, adapting to new attack vectors continuously.
2Measurement precision
If SOC analysts manually review and address threats, then thorough investigation is achieved, but the large volume of threats cannot be addressed in a timely manner
Solution Approach 1:
The system enables self-service threat detection and initial response through automated AI/ML models that independently analyze digital behavior, detect anomalies, and prioritize threats. This reduces the manual workload for SOC analysts by allowing the system to handle routine monitoring and preliminary investigation autonomously, while analysts focus on complex cases requiring human judgment.
Solution Approach 2:
The system implements continuous feedback loops where detected threats and analyst actions are fed back into the machine learning models to improve detection accuracy over time. This feedback mechanism allows the system to learn from past investigations and refine its algorithms, enabling faster and more accurate threat detection while maintaining high investigation quality through iterative improvement.
3Reliability
If comprehensive digital activity records are maintained for all employee accounts, then threat detection capability is improved, but system complexity and data management burden increase
Solution Approach 1:
The system extracts and analyzes only the critical behavioral parameters and anomaly indicators from comprehensive digital activity records, rather than processing all raw data. By extracting specific behavior patterns, anomaly signals, and risk indicators, the system maintains high threat detection capability while reducing the complexity of data management and processing requirements.
Solution Approach 2:
The patent segments the comprehensive digital activity data into distinct categories and time windows, organizing records by account, activity type, and temporal patterns. This segmentation allows the system to manage large volumes of data efficiently by processing and analyzing specific segments independently, reducing overall system complexity while maintaining comprehensive surveillance capability.
Data Source
AI summary
A method for behavior-based threat investigation may include obtaining data that is related to a series of email communications performed with accounts on a channel through which an employee of an enterprise can communicate with other employees of the enterprise or accounts external to the enterprise. The method may include parsing the data to identify an attribute of each email communication. The method may include generating a series of records populating a data structure with a record of each email communication comprising the respective attribute. The method may include generating a digital profile for the employee based on the series of records. The method may include obtaining a real time email communication on the channel corresponding to an account associated with the employee. The method may include determining a deviation between the real time email communication and the normal email communications.


