Email Campaign Attribution via Incriminating Feature Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer security systems are unable to determine whether a malicious email is an isolated incident or part of a targeted email campaign, and they struggle to accurately attribute such campaigns to known threat groups, which hampers timely deployment of effective countermeasures.

Innovation Solution

The system identifies potentially malicious email campaigns by detecting incriminating features linked to known threat groups, using data clusters and open-source intelligence resources to attribute the campaigns and notify targeted organizations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional computer security systems detect malicious emails, then email attack detection capability is improved, but the ability to determine whether attacks are part of a targeted campaign or attribute them to threat groups deteriorates

Engineering Contradiction:
Improveemail attack detection capabilityVSAvoidthreat group attribution information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments the email analysis process into multiple independent modules: header analysis module, body analysis module, attachment analysis module, and URL analysis module. Each module extracts specific features independently, and their results are aggregated to form a comprehensive threat profile. This segmentation allows the system to maintain detection reliability while gathering sufficient information for threat group attribution without overwhelming complexity in a single monolithic system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component - the threat intelligence database - that acts as a mediator between email detection and threat group attribution. This database stores pre-collected indicators of compromise (IOCs), threat group profiles, and attribution data from multiple sources. The intermediary enables the system to match detected email features against known threat patterns without requiring direct complex analysis, thus preserving attribution information that would otherwise be lost.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the system analyzes email features to attribute campaigns to threat groups, then attribution accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveattribution accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements partial action by analyzing only the most relevant email features for attribution purposes. Rather than examining every possible email attribute, the system focuses on specific high-value indicators such as sender header patterns, attachment signatures, and URL structures that are most strongly correlated with threat group identification. This selective approach maintains high attribution accuracy while avoiding the complexity of comprehensive analysis.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent employs parameter changes by dynamically adjusting the weight and importance of different email features based on the analysis context. The system uses machine learning models that can adaptively change parameters such as feature weighting, threshold values, and analysis depth depending on the email type, sender reputation, and detected threat level. This allows accurate attribution without requiring a uniformly complex system architecture for all email analyses.

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If the system notifies targeted organizations about threat groups, then organizational response time is improved, but information security risks increase

Engineering Contradiction:
Improveorganizational response timeVSAvoidinformation security risks
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary action by pre-processing and validating attribution information before notification. The threat intelligence database contains pre-verified threat group profiles and attribution data that have been cross-checked against multiple sources. When an email is analyzed, the system matches features against these pre-established profiles, ensuring that only verified attribution information is communicated to organizations. This preliminary verification reduces response time while minimizing the risk of transmitting inaccurate or harmful information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where notified organizations can report back on the accuracy and usefulness of the attribution information received. The system collects feedback data regarding whether the threat group identification was correct and whether the notification helped prevent or mitigate attacks. This feedback loop allows the system to refine its attribution algorithms and reduce false positives over time, thereby decreasing information security risks associated with notifications while maintaining rapid response capabilities.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9548988B1Systems and methods for attributing potentially malicious email campaigns to known threat groups
Publication Date: 2017.01.17 GEN DIGITAL INC
  • US9548988B1 patent drawing
  • US9548988B1 patent drawing
  • US9548988B1 patent drawing

AI summary

The disclosed computer-implemented method for attributing potentially malicious email campaigns to known threat groups may include (1) identifying a potentially malicious email campaign targeting at least one organization, (2) detecting, within the potentially malicious email campaign, an incriminating feature that has been linked to a known threat group, (3) determining, based at least in part on detecting the incriminating feature linked to the known threat group, that the known threat group is likely responsible for the potentially malicious email campaign, and then in response to determining that the known threat group is likely responsible for the potentially malicious email campaign, (4) attributing the potentially malicious email campaign to the known threat group. Various other methods, systems, and computer-readable media are also disclosed.