Instrumented Message Security Scanner Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current automated message security systems, such as sandboxes, interfere with legitimate instrumented messages by mimicking user interactions, making it difficult for organizations to determine if the interaction was performed by an automated system or the intended recipient, leading to potential false positives and interference with message delivery.
Innovation Solution
An electronic messaging system that uses distinct identifiers, one visible and one hidden to humans, to determine if a message has been intercepted by a sandbox by monitoring interactions with these identifiers within a threshold time period, allowing the system to differentiate between human and automated interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If automated message security systems (sandboxes) inspect all incoming messages by mimicking user interactions, then message security is improved, but false positives increase and legitimate instrumented messages are interfered with
Solution Approach 1:
The patent segments the interaction detection process into multiple distinct identifier types (visible identifiers for human users, hidden identifiers for automated detection). This segmentation allows the system to separately track human interactions versus automated sandbox interactions, improving measurement precision by accurately attributing interactions to their true source while maintaining security through comprehensive monitoring.
Solution Approach 2:
The patent introduces hidden identifiers as intermediaries between the message content and the detection system. These hidden identifiers serve as a mediator that allows automated security systems to detect sandbox interactions without interfering with legitimate human user interactions, thereby resolving the contradiction between security monitoring and accurate interaction detection.
2Adaptability or versatility
If sandboxes mimic user behavior to inspect messages, then security detection capability is improved, but it becomes difficult to determine if interaction was performed by automated system or intended recipient
Solution Approach 1:
The patent applies local quality by making identifiers differentially visible - visible identifiers are designed to be interacted with by human users, while hidden identifiers are designed to be interacted with by automated systems but are invisible to humans. This local differentiation in identifier properties enables precise identification of interaction sources while maintaining versatile security inspection capabilities.
Solution Approach 2:
The patent uses the concept of visibility changes analogous to color changes - hidden identifiers are 'invisible' to human users but 'visible' to automated sandboxes, while visible identifiers are the opposite. This visibility differentiation allows the system to simultaneously support both human interaction and automated detection without confusion about interaction source.
3Object-affected harmful factors
If organizations use automated message security systems to block malicious messages, then security protection is improved, but legitimate messages may be blocked due to false positives
Solution Approach 1:
The patent implements feedback mechanisms where the detection system monitors interactions with both visible and hidden identifiers, and this information feeds back into the message delivery decision process. When a message is determined to have been interacted with by a sandbox (through hidden identifier interaction), the system feedbacks this information to avoid blocking the legitimate message, thereby reducing false positives while maintaining protection from malicious messages.
Data Source
AI summary
An electronic messaging system includes a messaging server that identifies a recipient for an electronic message. The messaging system sends the recipient an electronic message that includes instrumented content. A web server monitors activity and determines whether interaction occurred with the instrumented content. The web server determines whether a sandbox intercepted the message based on whether interaction occurred, or did not occur, with the instrumented content within a threshold time period or with one or more activity characteristics.


