Email Sender Authentication for Phishing Detection Workflow

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email systems are vulnerable to sophisticated phishing attacks, particularly spear phishing and email spoofing, which deceive employees by mimicking legitimate senders, leading to potential data breaches and delays in identifying fraudulent communications.

Innovation Solution

A computing system with a processor and memory device executes instructions to analyze email headers, comparing sender addresses against a database of valid communication addresses, and displays alerts or forwards suspicious emails to a review team, thereby enhancing the initial detection of phishing attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If employees manually review suspicious emails to verify authenticity, then the accuracy of phishing detection is improved, but the time consumption and workload of the review team increase

Engineering Contradiction:
Improvephishing detection accuracyVSAvoidemail review time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary automated analysis of email headers, sender addresses, and domain information before presenting suspicious emails to the review team. This pre-screening process filters out obviously legitimate emails and prepares analysis results in advance, reducing the time required for manual review while maintaining detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an automated analysis system as an intermediary between incoming emails and the human review team. This intermediary performs initial verification of sender authenticity, domain validation, and header analysis, providing the review team with pre-processed information and reducing their workload while maintaining high detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all suspicious emails are forwarded to the review team for verification, then the reliability of phishing detection is improved, but the productivity of the review team deteriorates due to volume of emails

Engineering Contradiction:
Improvephishing detection reliabilityVSAvoidreview team throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different levels of review based on the specific characteristics of each email. High-risk emails with multiple suspicious features are flagged for mandatory review, while lower-risk emails receive automated verification only. This differentiated approach maintains high reliability for critical threats while preserving review team productivity by avoiding unnecessary reviews of low-risk emails.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial automated verification for all suspicious emails, with full manual review reserved for high-priority cases. The system performs domain validation, header analysis, and sender verification automatically for all emails, then selectively escalates only the most suspicious ones to the review team, achieving reliable detection without overwhelming the review team.

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If automated systems block emails without verification, then the speed of phishing prevention is improved, but the loss of legitimate communications increases

Engineering Contradiction:
Improvephishing prevention speedVSAvoidlegitimate email delivery
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The system performs preliminary verification of sender authenticity, domain validity, and header consistency before blocking any emails. By pre-validating these critical elements, the system can confidently block phishing emails at high speed while maintaining a low false-positive rate, as the preliminary checks have already established a strong basis for determining legitimacy.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements feedback mechanisms where the review team's decisions on blocked emails are used to refine and improve the automated blocking rules. This continuous learning process increases the accuracy of automated decisions over time, allowing faster blocking with reduced loss of legitimate communications as the system becomes more sophisticated in distinguishing phishing from legitimate emails.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260075089A1Sensing a presence of intrustion of digital communications for phishing attempts
Publication Date: 2026.03.12 TRUIST BANK
  • US20260075089A1 patent drawing
  • US20260075089A1 patent drawing
  • US20260075089A1 patent drawing

AI summary

A system and method sense a presence of intrusion of digital communications for phishing attempts including: a processor operatively connected to a memory device and a non-transitory storage device, wherein the processor executes computer-readable instructions of a digital communication application; a computer device with a display communicating with the processor to display digital communications addressed to a receiving communication address; and wherein, upon execution of the computer-readable instructions, the computing system performs steps comprising: in response to selection of the digital communication displayed at the computer device via the computer device, displaying either a Check Phishing button or a submenu listing a Check Phishing action at the computer device; and in response to selection of the button or selection of the action via the computer device, the processor executes computer-readable instructions of a check phishing application stored in the storage device to authenticate the from address of the digital communication.