Email Phishing Detection via Organizational Characteristic Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email protocols lack effective validation of sender identity, leading to phishing attacks where bad actors impersonate others to gain unauthorized access to confidential data, and existing solutions are not robust enough to prevent sophisticated phishing attacks.

Innovation Solution

A system and method for analyzing electronic messages that involves parsing received emails based on predetermined characteristics, comparing them with known sender and recipient organization characteristics, and declaring emails as phishing messages based on statistical distributions and weight assignments to determine the likelihood of phishing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing email protocols are used without validation, then email communication is simple and open, but sender identity cannot be verified leading to phishing attacks

Engineering Contradiction:
Improvesender identity verificationVSAvoidemail protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing organizational email characteristics and statistical distributions before phishing detection is needed. Email characteristics such as header fields, formatting patterns, and metadata are collected and stored in advance, creating a baseline for comparison when actual emails are received, enabling reliable sender verification without complicating the email protocol itself

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary analysis system that sits between email sending and receiving. This intermediary component parses emails, compares them against stored organizational characteristics, and determines authenticity without requiring changes to standard email protocols. The intermediary acts as a mediator that verifies sender identity while keeping the underlying email communication simple and compatible

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing phishing detection solutions check IP addresses or URLs, then detection is simple to implement, but the solutions are not robust enough to prevent sophisticated phishing attacks

Engineering Contradiction:
Improvephishing detection robustnessVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The detection system is segmented into distinct functional modules: an import module for collecting email data, an analysis and data warehouse module for parsing and storing characteristics, and a detection module for comparing incoming emails against organizational baselines. This segmentation allows the system to implement sophisticated multi-factor analysis while maintaining modularity and manageable complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent moves phishing detection from traditional single-dimension approaches (checking only IP addresses or URLs) to multi-dimensional analysis by examining numerous email characteristics simultaneously. The system analyzes header fields, formatting patterns, metadata, and content features across multiple dimensions, creating a comprehensive detection framework that is far more robust against sophisticated attacks

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If email characteristics are parsed and compared with organizational data, then phishing detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvephishing detection accuracyVSAvoidemail processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-parsing emails and storing their characteristics in an organized data warehouse structure before detection is needed. Email characteristics including header fields, formatting patterns, and metadata are extracted and stored in advance, so when actual emails arrive, the system can quickly compare them against pre-processed organizational baselines rather than analyzing everything from scratch

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements parameter changes by transforming email data into standardized characteristic parameters that can be efficiently compared. The system converts various email attributes into consistent parameter formats, enabling rapid statistical comparison against organizational distributions. This parameter standardization allows high-precision detection while reducing computational complexity during the actual detection phase

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8566938B1System and method for electronic message analysis for phishing detection
Publication Date: 2013.10.22 VADE SECURE SAS
  • US8566938B1 patent drawing
  • US8566938B1 patent drawing
  • US8566938B1 patent drawing

AI summary

A system and method for analyzing electronic messages for phishing detection are disclosed. In one example, email characteristics are obtained by parsing a received email message from a sender/sender organization to a recipient/recipient organization based on a set of predetermined email characteristics; the email characteristics of the received email message are then compared with email characteristics associated with the recipient/recipient organization and/or the sender/sender organization, and the received email message is then declared as a phishing electronic message based on the outcome of the comparison.