Email Plugin Phishing Detection via Source Code Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Regular employees often fail to detect phishing emails, exposing networks and computers to exploitation due to the complexity of advanced phishing tactics, despite security training, highlighting a need for sophisticated email analysis tools.

Innovation Solution

A plugin for email clients using a sophisticated analysis engine and algorithms to detect abnormalities in emails, such as sender IP location, domain checks, URL analysis, and threat intelligence, providing a visible warning system to users about potential phishing risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If employees receive security training, then their awareness of phishing risks improves, but they still fail to detect advanced phishing emails

Engineering Contradiction:
Improvephishing detection accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary analysis engine that acts as a mediator between the employee and the phishing email. This engine automatically performs sophisticated analysis of email characteristics (sender IP location, domain registration data, URL analysis, threat intelligence) without requiring the employee to understand these complex factors. The intermediary translates complex security analysis into simple visual indicators (phish-o-meter readings), resolving the contradiction by providing expert-level detection capability without requiring expert knowledge from the user.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically performing security analysis without human intervention in the detection process. The analysis engine autonomously evaluates email characteristics, checks threat intelligence databases, and generates phishing probability assessments. This allows regular employees to benefit from automated expert analysis rather than requiring them to manually perform complex security evaluations, thereby improving detection reliability without increasing operational complexity for users.

Inventive Principle:
Principle #25Self-service

2Reliability

If sophisticated analysis algorithms are implemented, then phishing detection capability improves, but system resource consumption increases

Engineering Contradiction:
Improvephishing detection accuracyVSAvoidcomputational resource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by selectively analyzing only the most relevant email characteristics using the phish-o-meter methodology. Rather than performing exhaustive analysis of all possible email attributes, the system focuses on key indicators (sender IP location, domain registration timing, URL structure, threat intelligence matches) that provide the highest detection value. This selective approach maintains high detection accuracy while reducing unnecessary computational resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If multiple phishing indicators are analyzed, then detection precision improves, but analysis time increases

Engineering Contradiction:
Improvephishing indicator detection accuracyVSAvoidemail analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-loading and caching threat intelligence data, domain reputation information, and IP location databases before they are needed for analysis. The analysis engine has access to pre-computed threat intelligence and domain registration data, eliminating the need to query external databases in real-time during email analysis. This preliminary preparation maintains high detection precision across multiple indicators while significantly reducing the time required to analyze incoming emails.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10574696B2System and method for detecting phishing e-mails
Publication Date: 2020.02.25 REVBITS LLC
  • US10574696B2 patent drawing
  • US10574696B2 patent drawing
  • US10574696B2 patent drawing

AI summary

An application or a plugin to Email client application such as Outlook or Thunderbird is described which automatically analyzes and detects Phishing emails. The application reads emails in an email client that an end user is using to access his/her emails. The application views source code of the email with all email headers, analyzes signatures, SMTP logs, and all traces of email origin.