Instrumented Message Security Scanner Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current automated message security systems, such as sandboxes, interfere with legitimate instrumented messages by mimicking user interactions, making it difficult for organizations to determine if the interaction was performed by an automated system or the intended recipient, leading to potential false positives and interference with message delivery.

Innovation Solution

An electronic messaging system that uses distinct identifiers, one visible and one hidden to humans, to determine if a message has been intercepted by a sandbox by monitoring interactions with these identifiers within a threshold time period, allowing the system to differentiate between human and automated interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated message security systems (sandboxes) inspect all incoming messages by mimicking user interactions, then message security is improved, but false positives increase and legitimate instrumented messages are interfered with

Engineering Contradiction:
Improvemessage securityVSAvoidinteraction detection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the interaction detection process into multiple distinct identifier types (visible identifiers for human users, hidden identifiers for automated detection). This segmentation allows the system to separately track human interactions versus automated sandbox interactions, improving measurement precision by accurately attributing interactions to their true source while maintaining security through comprehensive monitoring.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces hidden identifiers as intermediaries between the message content and the detection system. These hidden identifiers serve as a mediator that allows automated security systems to detect sandbox interactions without interfering with legitimate human user interactions, thereby resolving the contradiction between security monitoring and accurate interaction detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If sandboxes mimic user behavior to inspect messages, then security detection capability is improved, but it becomes difficult to determine if interaction was performed by automated system or intended recipient

Engineering Contradiction:
Improvesecurity inspection capabilityVSAvoidinteraction source identification
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent applies local quality by making identifiers differentially visible - visible identifiers are designed to be interacted with by human users, while hidden identifiers are designed to be interacted with by automated systems but are invisible to humans. This local differentiation in identifier properties enables precise identification of interaction sources while maintaining versatile security inspection capabilities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses the concept of visibility changes analogous to color changes - hidden identifiers are 'invisible' to human users but 'visible' to automated sandboxes, while visible identifiers are the opposite. This visibility differentiation allows the system to simultaneously support both human interaction and automated detection without confusion about interaction source.

Inventive Principle:
Principle #32Color changes

3Object-affected harmful factors

If organizations use automated message security systems to block malicious messages, then security protection is improved, but legitimate messages may be blocked due to false positives

Engineering Contradiction:
Improveprotection from malicious messagesVSAvoidmessage delivery accuracy
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent implements feedback mechanisms where the detection system monitors interactions with both visible and hidden identifiers, and this information feeds back into the message delivery decision process. When a message is determined to have been interacted with by a sandbox (through hidden identifier interaction), the system feedbacks this information to avoid blocking the legitimate message, thereby reducing false positives while maintaining protection from malicious messages.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10182031B2Automated message security scanner detection system
Publication Date: 2019.01.15 PROOFPOINT INC
  • US10182031B2 patent drawing
  • US10182031B2 patent drawing
  • US10182031B2 patent drawing

AI summary

An electronic messaging system includes a messaging server that identifies a recipient for an electronic message. The messaging system sends the recipient an electronic message that includes instrumented content. A web server monitors activity and determines whether interaction occurred with the instrumented content. The web server determines whether a sandbox intercepted the message based on whether interaction occurred, or did not occur, with the instrumented content within a threshold time period or with one or more activity characteristics.