Email Phishing Detection via Organizational Characteristic Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing email protocols lack effective validation of sender identity, leading to phishing attacks where bad actors impersonate others to gain unauthorized access to confidential data, and existing solutions are not robust enough to prevent sophisticated phishing attacks.
Innovation Solution
A system and method for analyzing electronic messages that involves parsing received emails based on predetermined characteristics, comparing them with known sender and recipient organization characteristics, and declaring emails as phishing messages based on statistical distributions and weight assignments to determine the likelihood of phishing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing email protocols are used without validation, then email communication is simple and open, but sender identity cannot be verified leading to phishing attacks
Solution Approach 1:
The system performs preliminary actions by establishing organizational email characteristics and statistical distributions before phishing detection is needed. Email characteristics such as header fields, formatting patterns, and metadata are collected and stored in advance, creating a baseline for comparison when actual emails are received, enabling reliable sender verification without complicating the email protocol itself
Solution Approach 2:
The patent introduces an intermediary analysis system that sits between email sending and receiving. This intermediary component parses emails, compares them against stored organizational characteristics, and determines authenticity without requiring changes to standard email protocols. The intermediary acts as a mediator that verifies sender identity while keeping the underlying email communication simple and compatible
2Reliability
If existing phishing detection solutions check IP addresses or URLs, then detection is simple to implement, but the solutions are not robust enough to prevent sophisticated phishing attacks
Solution Approach 1:
The detection system is segmented into distinct functional modules: an import module for collecting email data, an analysis and data warehouse module for parsing and storing characteristics, and a detection module for comparing incoming emails against organizational baselines. This segmentation allows the system to implement sophisticated multi-factor analysis while maintaining modularity and manageable complexity
Solution Approach 2:
The patent moves phishing detection from traditional single-dimension approaches (checking only IP addresses or URLs) to multi-dimensional analysis by examining numerous email characteristics simultaneously. The system analyzes header fields, formatting patterns, metadata, and content features across multiple dimensions, creating a comprehensive detection framework that is far more robust against sophisticated attacks
3Measurement precision
If email characteristics are parsed and compared with organizational data, then phishing detection accuracy is improved, but processing time and computational resources increase
Solution Approach 1:
The system performs preliminary actions by pre-parsing emails and storing their characteristics in an organized data warehouse structure before detection is needed. Email characteristics including header fields, formatting patterns, and metadata are extracted and stored in advance, so when actual emails arrive, the system can quickly compare them against pre-processed organizational baselines rather than analyzing everything from scratch
Solution Approach 2:
The patent implements parameter changes by transforming email data into standardized characteristic parameters that can be efficiently compared. The system converts various email attributes into consistent parameter formats, enabling rapid statistical comparison against organizational distributions. This parameter standardization allows high-precision detection while reducing computational complexity during the actual detection phase
Data Source
AI summary
A system and method for analyzing electronic messages for phishing detection are disclosed. In one example, email characteristics are obtained by parsing a received email message from a sender/sender organization to a recipient/recipient organization based on a set of predetermined email characteristics; the email characteristics of the received email message are then compared with email characteristics associated with the recipient/recipient organization and/or the sender/sender organization, and the received email message is then declared as a phishing electronic message based on the outcome of the comparison.


