Email Traffic Analysis for Unauthorized Bulk Forwarding Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for preventing the unauthorized forwarding of confidential and sensitive data via email are inadequate, as they rely on untrusted computers and fail to detect bulk forwarding effectively.
Innovation Solution
A system that detects unauthorized bulk forwarding by determining the arrival rate of internal emails and the sending rate of external emails, using statistical models to correlate timing, size, and content characteristics, and maps user accounts to computer systems to identify potential data breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If filtering mechanisms are installed on computers within the enterprise network, then the ability to scan outgoing emails for confidential data is improved, but the reliability of detection deteriorates because these computers cannot be fully trusted
Solution Approach 1:
The patent introduces an intermediary monitoring system that positions itself between internal and external email networks. This mediator passively observes email traffic patterns, arrival rates, and sending behaviors without requiring trust from endpoint computers. The intermediary detects bulk forwarding by analyzing statistical correlations in email flows, thereby resolving the contradiction by eliminating the need to trust untrusted computers while maintaining detection precision.
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring email arrival rates from internal networks and comparing them against external sending rates. When statistical anomalies or correlations indicate potential bulk forwarding, the system generates alerts and can trigger countermeasures. This closed-loop feedback enables reliable detection without compromising the integrity of untrusted endpoint computers.
2Object-affected harmful factors
If traditional filtering mechanisms are used to scan outgoing emails, then some unauthorized transfers are reduced, but bulk forwarding detection capability deteriorates due to reliance on untrusted computers
Solution Approach 1:
The patent transitions from traditional content-based filtering to a dimensional approach that analyzes email traffic patterns, timing, rates, and statistical correlations. By adding temporal and statistical dimensions to detection, the system can identify bulk forwarding behaviors that content filters miss, thereby improving detection precision without relying on untrusted computers to execute filtering logic.
Solution Approach 2:
The system changes the parameters of detection from content-based metrics to flow-based metrics such as arrival rates, sending rates, timing patterns, and statistical correlations. This parameter transformation enables the system to detect bulk forwarding by analyzing behavioral patterns rather than relying on endpoint computers to filter content, thereby improving both unauthorized transfer prevention and detection precision.
3Measurement precision
If statistical analysis of email patterns is performed to detect bulk forwarding, then detection accuracy is improved, but system complexity deteriorates due to correlation analysis requirements
Solution Approach 1:
The patent applies partial statistical analysis by focusing on specific key parameters such as arrival rates, sending rates, and timing correlations rather than performing exhaustive analysis of all email attributes. This selective statistical approach maintains high detection accuracy while reducing computational complexity and resource requirements compared to comprehensive statistical modeling.
Data Source
AI summary
Methods and apparatus are provided for detecting unauthorized bulk forwarding of sensitive data over a network. A bulk forwarding of email from a first network environment is automatically detected by determining an arrival rate for internal emails received from within the first network environment into one or more user accounts; determining a sending rate for external emails sent from the one or more user accounts to a second network environment; and detecting the bulk forwarding of email from a given user account by comparing the arrival rate for internal emails and the sending rate for external emails. The bulk forwarding of email from a given user account can be detected by determining whether statistical models of the arrival rate for internal emails and of the sending rate for external emails are correlated in time.


