Email Account Compromise Detection via Behavioral Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional email security measures, such as anti-spam filters, are ineffective in detecting email account compromise threats that originate from within an enterprise, as they are designed to prevent malicious emails from external sources rather than internal or outgoing threats.

Innovation Solution

A threat detection platform that monitors digital activities associated with email accounts to identify abnormal behavior, using machine learning models, heuristics, and human feedback to detect potential email account compromise by analyzing attributes like geographical origin, sender identity, and email content, and enacting remediation actions such as restricting access or quarantining emails.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If conventional anti-spam filters are used to block external malicious emails, then external email security is improved, but internal email account compromise detection capability deteriorates

Engineering Contradiction:
Improveexternal malicious email blockingVSAvoidinternal account compromise detection
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The email security system is segmented into two distinct detection pathways: one for external malicious emails (anti-spam filters) and another for internal account compromise detection (behavioral analysis platform). This allows each pathway to specialize in its specific threat type without interfering with the other, resolving the contradiction between external blocking and internal detection capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A behavioral analysis platform acts as an intermediary layer between email accounts and the security system. This intermediary monitors digital activities, analyzes behavior patterns, and detects account compromises independently of traditional email filtering mechanisms, enabling simultaneous external spam blocking and internal compromise detection

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-generated harmful factors

If traditional email filtering mechanisms are deployed, then external spam is reduced, but detection of internal threats originating from compromised accounts deteriorates

Engineering Contradiction:
Improveexternal spam preventionVSAvoidinternal threat detection
Core Design Contradiction:
Object-generated harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

Instead of filtering emails to detect threats, the system inverts the approach by monitoring the behavior of email accounts themselves. The behavioral analysis platform examines digital activities, login patterns, and communication behaviors to detect compromises, turning the detection focus from content-based filtering to behavior-based analysis

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The mechanical email filtering system is replaced with a behavioral analysis system that uses machine learning models and heuristics. This substitution enables detection of internal threats by analyzing patterns in digital activities rather than relying on rule-based email content filtering

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If behavioral analysis monitoring is implemented to detect account compromise, then detection capability is improved, but system complexity and computational resources increase

Engineering Contradiction:
Improveaccount compromise detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The behavioral analysis platform implements partial monitoring by focusing on specific digital activities and behavior patterns most indicative of account compromise. Rather than analyzing all possible account actions equally, the system targets key behaviors such as login patterns, email sending frequency, and access locations, reducing complexity while maintaining detection accuracy

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system uses machine learning models that automatically learn and adapt to normal user behavior patterns without requiring manual configuration or complex rule sets. The models self-adjust to individual account behaviors, reducing the need for manual system management and lowering operational complexity

Inventive Principle:
Principle #25Self-service

4Measurement precision

If comprehensive digital activity monitoring is performed, then detection precision is improved, but processing time and computational overhead increase

Engineering Contradiction:
Improvecompromise detection precisionVSAvoidanalysis processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The behavioral analysis platform performs periodic behavior assessments rather than continuous real-time analysis of all activities. The system periodically evaluates accumulated behavior data against established patterns, maintaining high detection precision while reducing continuous processing overhead and computational time requirements

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10911489B1Discovering email account compromise through assessments of digital activities
Publication Date: 2021.02.02 ABNORMAL AI INC
  • US10911489B1 patent drawing
  • US10911489B1 patent drawing
  • US10911489B1 patent drawing

AI summary

Introduced here are threat detection platforms designed to discover possible instances of email account compromise in order to identify threats to an enterprise. In particular, a threat detection platform can examine the digital activities performed with the email accounts associated with employees of the enterprise to determine whether any email accounts are exhibiting abnormal behavior. Examples of digital activities include the reception of an incoming email, transmission of an outgoing email, creation of a mail filter, and occurrence of a sign-in event (also referred to as a “login event”). Thus, the threat detection platform can monitor the digital activities performed with a given email account to determine the likelihood that the given email account has been compromised.