Email Endpoint Agent for ML-Based Data Exfiltration Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber defense systems are insufficient in addressing modern cyber threats originating from or associated with emails, as they lack effective detection and response mechanisms for anomalous and malicious activities.

Innovation Solution

A cyber defense system with an endpoint agent extension that integrates machine learning models to analyze normal email and user behavior, autonomously detects threats, and takes actions such as preventing email transmission, stripping attachments, or notifying security personnel, using secure communications with network-based appliances for contextual information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls and antivirus security methods are used, then basic cyber defense is provided, but they are insufficient in detecting and responding to modern email-based cyber threats

Engineering Contradiction:
Improvecyber defense effectivenessVSAvoidability to detect modern email threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces traditional mechanical security methods (firewalls, antivirus) with an AI-based system that uses machine learning models to analyze email behavior patterns. The system substitutes rule-based mechanical detection with intelligent, adaptive analysis that can identify sophisticated email-based threats including data exfiltration and business email compromise.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the detection parameters from static security rules to dynamic behavioral analysis. Machine learning models continuously learn from normal email activity patterns and detect deviations, allowing the system to adapt to evolving threats while maintaining reliability in detecting both known and novel email-based attacks.

Inventive Principle:
Principle #35Parameter changes

2Speed

If autonomous actions are taken against suspected threats, then response time is reduced, but false positives may cause business disruption

Engineering Contradiction:
Improvethreat response timeVSAvoidbusiness continuity
Core Design Contradiction:
SpeedVSEase of operation

Solution Approach 1:

The system applies partial autonomous actions based on threat confidence levels. For high-confidence threats, full autonomous actions are taken (blocking, stripping attachments). For lower-confidence cases, the system takes partial actions or requests human review, balancing rapid response with minimizing false positives and business disruption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system incorporates feedback loops where autonomous actions are monitored and evaluated. Machine learning models continuously learn from outcomes, adjusting their detection thresholds and action selections to reduce false positives over time while maintaining rapid response capabilities for confirmed threats.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If machine learning models analyze all email activity, then detection accuracy improves, but system complexity and computational resources increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsystem architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments email analysis into multiple specialized machine learning models, each trained on specific threat types (data exfiltration, business email compromise, phishing). This segmentation allows precise detection for different threat categories while managing system complexity through modular architecture and specialized analysis pipelines.

Inventive Principle:
Principle #1Segmentation

4Reliability

If comprehensive email analysis is performed, then threat detection capability is enhanced, but processing time and resource consumption increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidemail processing throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system uses periodic analysis where machine learning models evaluate emails at key stages (inbound, outbound, attachment analysis) rather than continuously analyzing every byte. This periodic approach maintains comprehensive detection capability while managing processing time and resource consumption through staged analysis.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3786823B1An endpoint agent extension of a machine learning cyber defense system for email
Publication Date: 2025.12.17 DARKTRACE HLDG LTD
  • EP3786823B1 patent drawingFigure 1
  • EP3786823B1 patent drawingFigure 2
  • EP3786823B1 patent drawingFigure 3

AI summary

An endpoint agent extension (100) of a cyber defense system for email that includes modules and machine learning models. An integration module integrates with an email client application to detect email cyber threats in emails in the email client application as well as regulate emails. An action module interfaces with the email client application to direct autonomous actions against an outbound email and/or its files when a cyber threat module determines the email and/or its files (a) to be a data exfiltration threat, (b) to be both malicious and anomalous behavior as compared to a user's modeled email behavior, and (c) any combination of these. The autonomous actions can include actions of logging a user off the email client application, preventing the sending of the email, stripping the attached files and/or disabling the link to the files from the email, and sending a notification to cyber security personnel regarding the email.