Federated Vendor Reputation Database for Email Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current email security measures, such as secure email gateways and security operations center analysts, are inadequate in detecting and preventing vendor account compromise (VAC) attacks, which originate from legitimate vendor email accounts and are difficult to distinguish due to familiar details and infrequent communication patterns, leading to increased risks of credential-based phishing and financial fraud.

Innovation Solution

A federated database is created and managed by a threat detection platform to share knowledge about vendor reputations across enterprises, allowing for the identification and quantification of risks associated with vendor interactions, enabling preventative actions against VAC attacks by filtering suspicious emails and updating vendor profiles based on detected threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure email gateways and security operations center analysts are used to protect email, then email security is improved, but the system cannot effectively detect vendor account compromise attacks originating from legitimate vendor email accounts

Engineering Contradiction:
Improveemail securityVSAvoiddetection of VAC attacks
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system segments the detection approach by separating traditional email gateway filtering from behavioral analysis. It divides vendor communication monitoring into distinct components: baseline establishment, deviation detection, and risk scoring. This segmentation allows the system to handle legitimate vendor emails differently from compromised ones without false positives.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary federated database that sits between individual enterprise email systems and the detection platform. This intermediary repository stores vendor communication patterns and risk indicators, enabling centralized analysis while preserving individual enterprise data sovereignty. The intermediary layer aggregates insights across multiple enterprises to improve detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If traditional email security measures are implemented, then general email threats are blocked, but vendor account compromise attacks from legitimate accounts remain undetected

Engineering Contradiction:
Improveemail threat blockingVSAvoidprotection against VAC attacks
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing baseline communication patterns for each vendor before attacks occur. It proactively monitors and stores normal email exchange patterns, timing, and content characteristics. When deviations from these baselines are detected, the system can quickly identify potential VAC attacks rather than relying on reactive blocking.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops where detection results from one enterprise are fed back into the federated database to improve overall detection capabilities. Risk indicators and compromised vendor information are shared across the network, allowing all participating enterprises to benefit from each other's security insights and update their protection strategies accordingly.

Inventive Principle:
Principle #23Feedback

3Loss of information

If email analysis is performed at individual enterprise level, then data privacy is maintained, but detection accuracy is reduced due to limited data samples

Engineering Contradiction:
Improvedata privacy preservationVSAvoidrisk detection accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The system merges data from multiple enterprises in a federated architecture where individual enterprise data remains private but aggregated insights are shared. Vendor communication patterns are analyzed across the entire network while preserving individual enterprise boundaries. This combining approach provides sufficient data samples for accurate detection without compromising data privacy.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system adds a new dimension to data utilization by creating a federated space where information from multiple enterprises coexists without direct exposure. Instead of sharing raw emails or sensitive data, the system shares processed risk indicators and aggregated patterns. This dimensional transformation enables cross-enterprise learning while maintaining privacy boundaries.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11483344B2Estimating risk posed by interacting with third parties through analysis of emails addressed to employees of multiple enterprises
Publication Date: 2022.10.25 ABNORMAL AI INC
  • US11483344B2 patent drawing
  • US11483344B2 patent drawing
  • US11483344B2 patent drawing

AI summary

Introduced here are computer programs and computer-implemented techniques for generating and then managing a federated database that can be used to ascertain the risk in interacting with vendors. At a high level, the federated database allows knowledge regarding the reputation of vendors to be shared amongst different enterprises with which those vendors may interact. A threat detection platform may utilize the federated database when determining how to handle incoming emails from vendors.