Endpoint Phishing Detection via Traffic Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for improved techniques to detect and protect against malicious activity, such as phishing attacks, in enterprise networks.
Innovation Solution
A technique is disclosed that involves monitoring outbound web traffic and inbound electronic mail traffic to detect potential phishing attacks. When a hyperlink in an email lacks a source in the outbound web traffic, access to the hyperlink is restricted to prevent phishing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If outbound web traffic monitoring is implemented to detect phishing sources, then phishing detection capability is improved, but system complexity increases
Solution Approach 1:
The system divides phishing detection into two independent components: outbound web traffic monitoring and inbound email monitoring. Each component operates separately but contributes to the overall detection capability, allowing the system to maintain high detection precision while managing complexity through modular architecture
Solution Approach 2:
The system performs preliminary monitoring of outbound web traffic before phishing emails arrive. By establishing a baseline of legitimate web requests in advance, the system can quickly compare incoming email links against this pre-collected data, improving detection speed and accuracy without requiring complex real-time analysis
2Reliability
If access to hyperlinks is restricted when no source is found, then phishing protection is improved, but user convenience deteriorates
Solution Approach 1:
The system introduces an intermediary verification mechanism that acts as a mediator between the user and the hyperlink. Instead of directly blocking or allowing access, the system checks whether the hyperlink has a corresponding source in outbound web traffic monitoring data. This intermediary layer provides reliable phishing protection while maintaining user convenience by allowing legitimate links to pass through without restriction
Solution Approach 2:
The system applies partial restriction rather than complete blocking. When no source is found in outbound monitoring, the system restricts access to that specific hyperlink while leaving other links unaffected. This partial action approach maintains phishing protection for suspicious links while preserving user convenience for legitimate communications
Data Source
AI summary
Disclosed herein is a technique for detecting potential phishing attacks by monitoring outbound web traffic from an endpoint, along with inbound electronic mail traffic addressed to a user of the endpoint. With this information, a search can be performed for possible sources in the web traffic of a request for a hyperlink located in the inbound mail traffic, and when no source is located, phishing remediation can be performed, including restrictions on access to the hyperlink at an endpoint operated by the user.


