Intercepting Harmful Emails via Cloud API Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Third-party e-mail security vendors face challenges in accessing potentially harmful or deceptive e-mails from users of services like Microsoft Office 365 and Google Gmail without requiring users to install custom add-ons.
Innovation Solution
A data security system utilizing network API calls to a cloud-based service, allowing end users to report suspicious transactions, which are then analyzed by a data inspector using machine learning, intercepting and controlling the transmission of reported e-mails to either a central authority or a security manager for analysis and remedial actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If third-party e-mail security vendors provide their own e-mail server and client, then they can access suspect e-mails for security analysis, but the complexity of the system increases and users must manage multiple e-mail infrastructure components
Solution Approach 1:
The patent introduces an intermediary component that sits between the existing e-mail service provider's infrastructure and the third-party security vendor. This intermediary captures reported e-mails and forwards them to security vendors without requiring vendors to build their own e-mail infrastructure. The intermediary acts as a bridge that enables security analysis capabilities while maintaining reliance on existing e-mail service infrastructure.
2Reliability
If third-party e-mail security vendors require custom Outlook add-ons to be installed by end users, then they can access reported e-mails, but the ease of operation decreases due to additional installation requirements
Solution Approach 1:
The patent extracts the e-mail reporting functionality from requiring custom client-side add-ons and moves it to the server-side e-mail service provider. The existing e-mail service provider's infrastructure is modified to capture and forward reported e-mails to security vendors, eliminating the need for users to install and configure additional client software while maintaining security inspection capabilities.
3Extent of automation
If e-mail services forward all reported e-mails to a central authority, then centralized control is maintained, but the ability of third-party vendors to perform independent security analysis is limited
Solution Approach 1:
The patent segments the e-mail reporting workflow into multiple independent pathways. Instead of a single centralized authority receiving all reported e-mails, the system divides the flow to allow simultaneous forwarding to both the original central authority and to third-party security vendors. This segmentation enables both centralized control and independent third-party analysis to coexist without conflict.
Data Source
AI summary
A data security system, including a security manager computer making network application programming interface (API) calls to a cloud-based service that (i) performs data exchange transactions for end users, and (ii) includes a mechanism for an end user to invoke in order to report a transaction received by the end user to a central authority as being a potentially harmful or deceptive transaction, the API calls remotely controlling the cloud-based service so that the security manager computer accesses transactions that have entered the cloud-based service, and a data inspector operative to analyze a transaction as being harmful or deceptive, by applying machine learning, wherein the security manager computer controls the cloud-based service so as to transmit transactions reported by the mechanism to the security manager, instead of or in addition to the central authority, for analysis by the data inspector.


