Email Component Scoring for Cybersecurity Threat Triage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex enterprise environments face significant challenges in preventing infiltration by malicious emails, efficiently determining threat levels, and instructing associates on detecting and responding to potential threats due to the rapid growth of malware and phishing attacks.

Innovation Solution

A software tool for cybersecurity triaging that deconstructs suspicious emails into components, scores them for threat type and level, and facilitates user customization of analysis modules, integrating with external services for threat assessment and providing actionable feedback.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual review of suspicious emails is performed by security personnel, then threat detection accuracy is improved, but processing time and operational costs increase significantly

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the email analysis process into multiple independent analysis modules, each focusing on specific threat indicators (phishing, malware, spam). This segmentation allows automated analysis of individual email components while maintaining comprehensive threat detection, reducing the time burden on manual reviewers without sacrificing accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an automated analysis system as an intermediary between incoming emails and security personnel. This intermediary performs preliminary triage, scoring, and prioritization of suspicious emails, filtering out low-risk messages before they reach manual reviewers, thereby significantly reducing processing time while maintaining high detection accuracy for genuine threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive analysis of all email components is performed, then threat detection accuracy is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements dynamic analysis module selection based on email characteristics and threat indicators. The system automatically activates only the relevant analysis modules needed for each specific email (e.g., phishing analysis for suspicious links, malware analysis for attachments), rather than running all modules on every email. This dynamic approach maintains comprehensive detection accuracy while reducing overall system complexity and resource consumption.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different levels of analysis depth to different email components based on their risk profiles. High-risk elements (suspicious links, unknown senders, attachment emails) receive comprehensive multi-module analysis, while low-risk elements receive minimal or no analysis. This local quality differentiation maintains overall detection accuracy while significantly reducing the complexity burden of analyzing every component of every email at maximum depth.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If multiple analysis modules are used to score emails, then threat identification accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidprocessing throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies partial action by selectively running analysis modules based on email risk indicators. The system performs a baseline analysis on all emails using lightweight modules, then applies additional heavier analysis modules only to emails that exceed certain risk thresholds. This approach maintains high threat identification accuracy for suspicious emails while preserving processing throughput by avoiding excessive analysis on benign emails.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements periodic action through staged analysis where emails undergo initial quick scoring, then proceed to more comprehensive periodic analysis only if initial scores indicate potential threats. This multi-stage periodic approach allows the system to maintain high productivity by quickly processing most emails, while still achieving high identification accuracy through deeper periodic analysis of suspicious cases.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10333974B2Automated processing of suspicious emails submitted for review
Publication Date: 2019.06.25 BANK OF AMERICA CORP
  • US10333974B2 patent drawing
  • US10333974B2 patent drawing
  • US10333974B2 patent drawing

AI summary

Systems and methods for enterprise cybersecurity triaging of emails suspected of malicious content. Triaging may include analyzing threat level of email submitted for cybersecurity review. The systems and methods may deconstruct an email into components scorable for threat type and/or threat level. The systems and methods may include multiple dynamically selectable threat scoring modules. Email threat level may be based on component scores. Evaluated emails and scored components may be stored. Cybersecurity threat analysis may include comparison of the email and/or the scorable components against previously stored evaluated emails and previously stored scored components. Triaging may include identifying enterprise response teams experienced in the threat type and/or threat level of the email and/or of its components. Triaging may include preventing infiltration of an enterprise by malicious emails. The systems and methods may include feedback to enterprise associates regarding detecting and handling potentially malicious emails.