Email Metadata Extraction for Security Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Email service providers face inefficiencies in security analysis due to the inability to keep pace with evolving malicious attacks, lack of computing resources, and privacy concerns when performing security analysis across separate computing infrastructures.

Innovation Solution

Implementing a method where only meaningful metadata is extracted from emails at the first computing infrastructure and sent to a second infrastructure for security analysis, offloading resource-intensive processing while minimizing data flow and addressing privacy concerns by excluding private or confidential content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security analysis is performed on the entire email content across separate computing infrastructures, then detection accuracy improves, but data transmission volume increases and privacy concerns arise

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata transmission volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only essential metadata fields (sender address, recipient address, subject line, timestamps, email headers) from the complete email content for transmission to the security infrastructure. This extraction principle resolves the contradiction by selecting only the necessary data elements required for security analysis while excluding unnecessary content, thereby maintaining detection accuracy for security purposes while dramatically reducing data transmission volume and addressing privacy concerns.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If security analysis is performed on the entire email content, then detection accuracy improves, but processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

By extracting only metadata fields rather than analyzing complete email content including attachments and body text, the system reduces processing time significantly while maintaining sufficient detection accuracy for security threats. The metadata contains the critical information needed for security analysis such as sender reputation, recipient patterns, and temporal characteristics of email communication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by performing security analysis on a subset of email data (metadata only) rather than the complete email content. This partial analysis approach is sufficient for detecting security threats while avoiding the excessive processing time that would result from analyzing entire email contents including large attachments.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If additional computing resources are utilized for security analysis, then detection capability improves, but infrastructure complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the email processing system into two distinct infrastructures: the email service infrastructure that handles complete email content and storage, and the security analysis infrastructure that receives only metadata for analysis. This segmentation allows each infrastructure to be optimized independently, improving detection capability through specialized security resources while managing overall complexity through clear functional separation and standardized interfaces.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11677758B2Minimizing data flow between computing infrastructures for email security
Publication Date: 2023.06.13 CISCO TECHNOLOGY INC
  • US11677758B2 patent drawing
  • US11677758B2 patent drawing
  • US11677758B2 patent drawing

AI summary

Techniques for minimizing data flow from a first computing infrastructure hosting an email service platform to a second computing infrastructure at least partly hosting an email security platform that provides security analysis on emails of the email service. The email security platform may extract metadata from emails received at the first computing infrastructure, and send that metadata to the second computing infrastructure that is hosting a back end of the email service platform. The metadata extracted from the emails may include less confidential contained in an email, but enough information for the email security platform to determine whether an email is potentially malicious. Thus, the security analysis performed on emails to detect malicious attacks may be offloaded to the second computing infrastructure, but the metadata that leaves the first computing infrastructure and flows to the second computing infrastructure may be minimized by extracting meaningful metadata.