Multi-Attribute Clustering for Malicious Email Campaign Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity systems struggle to efficiently identify and respond to malicious email campaigns due to their reliance on manual intervention and ineffective fingerprinting methods, which are often misleading and unable to keep pace with the evolving tactics of cybercriminals.

Innovation Solution

A malicious activity management system that utilizes multi-attribute cluster-identifiers to assess and identify malicious activities by clustering emails based on attribute sets and generating risk scores, enabling automated detection and response to cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual intervention and traditional fingerprinting methods are used to identify malicious email campaigns, then the system can detect individual malicious emails, but it cannot efficiently identify and respond to organized malicious email campaigns that evolve over time

Engineering Contradiction:
Improvecampaign identification efficiencyVSAvoidcampaign detection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments email campaigns into distinct clusters based on multiple attributes including sending infrastructure characteristics, email template features, and payload types. By dividing the complex task of campaign identification into manageable attribute-based segments, the system can efficiently process and analyze large volumes of emails while maintaining accurate detection of organized malicious campaigns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts detection parameters and thresholds based on evolving campaign characteristics. By monitoring changes in campaign attributes over time and adapting detection sensitivity accordingly, the system maintains high reliability in identifying malicious campaigns while responding efficiently to new attack patterns that differ from historical data.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional email filtering systems are used, then individual malicious emails can be blocked, but sophisticated email attacks can still persist and break through filters over time

Engineering Contradiction:
Improveemail filter effectivenessVSAvoidcampaign persistence time
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The system performs preliminary analysis of email attributes and clusters emails into potential campaign groups before final delivery or processing. By identifying campaign patterns early based on sending infrastructure, template characteristics, and other attributes, the system can proactively block entire campaign clusters rather than reacting to individual malicious emails after they've already bypassed traditional filters.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors email traffic patterns and campaign characteristics, using feedback from detected campaigns to refine clustering algorithms and detection thresholds. This adaptive feedback mechanism allows the system to maintain high filter effectiveness against evolving sophisticated attacks by learning from each detected campaign and adjusting to new attack patterns.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive analysis of all email attributes is performed, then accurate malicious campaign identification can be achieved, but the system complexity and processing time increase significantly

Engineering Contradiction:
Improvemalicious activity identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides comprehensive email analysis into discrete attribute segments such as sending infrastructure characteristics, email template features, payload types, and recipient patterns. By processing emails through multiple specialized clustering modules that each analyze specific attribute segments, the system achieves high identification accuracy without requiring a single monolithic complex system, thereby reducing overall system complexity while maintaining precision.

Inventive Principle:
Principle #1Segmentation

4Speed

If real-time monitoring and analysis of all email traffic is implemented, then malicious campaigns can be detected quickly, but the processing load and resource consumption increase

Engineering Contradiction:
Improvecampaign detection speedVSAvoidprocessing resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system applies partial analysis to individual emails by extracting and clustering only the most critical attributes such as sending infrastructure characteristics and template features, rather than performing exhaustive analysis on every email field. This selective partial action enables real-time monitoring and fast campaign detection while significantly reducing processing resource consumption compared to comprehensive real-time analysis of all email traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4290808B1Campaign intelligence and visualization for combating cyberattacks
Publication Date: 2025.05.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4290808B1 patent drawingFigure 1A
  • EP4290808B1 patent drawingFigure 1B
  • EP4290808B1 patent drawingFigure 1C

AI summary

Methods, systems, and computer storage media for providing a multi-attribute cluster-identifier that supports identifying malicious activity in computing environments. An instance of an activity having an attribute set can be assessed. The attribute set of the instance of the activity is analyzed to determine whether the instance of the activity is a malicious activity. The attribute set of the instance of the activity is compared to a plurality of multi-attribute cluster-identifiers of previous instances of the activity, such that, a determination that the instance of the activity is a malicious activity is made when the attribute set of the instance of the activity corresponds to an identified multi-attribute cluster-identifier. The identified multi-attribute cluster-identifier has a risk score and an attribute set that indicate a likelihood that the instance of the activity is a malicious activity. A visualization that identifies the instance of the activity as a malicious activity is generated.