User-Based Inquiry for Enterprise Email Threat Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in effectively securing endpoints against malicious activities, particularly in identifying and remediating potential threats within the network, as existing solutions often rely on network addresses rather than user-based inquiries, leading to inadequate protection and response times.

Innovation Solution

Implementing a threat management facility that monitors electronic communications for indicators of malicious activity, uses user-based inquiries to identify potential sources, and employs a combination of security management, policy management, and remedial actions to analyze and protect endpoints, including behavioral-based protection and reputation filtering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network address-based identification is used to locate potential threat sources, then the scope of monitoring can be established, but the precision of identifying the actual user source is insufficient

Engineering Contradiction:
Improveidentification precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the identification process into two stages: first identifying the network address of the potential threat source, then performing user-based inquiry to identify the specific user associated with that address. This segmentation allows the system to maintain broad monitoring coverage while achieving precise user-level identification when needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary mechanism (user-based inquiry) between network address identification and threat remediation. This intermediary step resolves the ambiguity between network addresses and actual users by establishing the mapping relationship, thereby improving identification precision without requiring complete reconfiguration of the monitoring system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive monitoring of electronic communications is implemented, then threat detection capability is improved, but response time may be increased due to analysis complexity

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing user-based inquiry mechanisms and mapping relationships between network addresses and users before threats occur. This preliminary preparation enables rapid identification and response to threats once detected, reducing the time loss associated with complex analysis during incident response.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If user-based inquiry is implemented to identify potential sources, then the accuracy of threat source identification is improved, but the complexity of the security management process increases

Engineering Contradiction:
Improvethreat source identification accuracyVSAvoidsecurity management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements a universal user-based inquiry mechanism that can be applied across different threat scenarios and communication types. This multi-functional approach consolidates various identification methods into a single unified process, improving threat source identification accuracy while avoiding the need for multiple separate complex systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10972483B2Electronic mail security using root cause analysis
Publication Date: 2021.04.06 SOPHOS LTD
  • US10972483B2 patent drawing
  • US10972483B2 patent drawing
  • US10972483B2 patent drawing

AI summary

Electronic communications passing through a communication gateway or similar device for an enterprise can be monitored for indicators of malicious activity. When potentially malicious activity is identified, a user-based inquiry can be employed to identify potential sources of the malicious activity within the enterprise network. More specifically, by identifying a user that sourced the communication, instead of or in addition to a network address, devices within the enterprise network associated with the user can be located, analyzed, and remediated as appropriate.