IP Tracking Pixels for Email Security Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Detecting online security threats in transaction systems is challenging due to evolving methodologies used by malicious actors, leading to reduced system performance and unnecessary operations.

Innovation Solution

A system that captures and correlates IP addresses from electronic messages, such as emails, with historical access data to detect account access anomalies and implement security measures, using tracking pixels or hypertext links to simulate clicks and register hits on servers, thereby enhancing threat detection and mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If monitoring transactions is used to detect security threats, then security detection capability is improved, but system performance deteriorates due to unnecessary operations

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by capturing IP addresses from electronic messages before transactions occur. Tracking pixels and hypertext links in emails capture recipient IP addresses in advance, creating a baseline of expected communication partners. This preliminary data collection enables later comparison with actual transaction IPs to detect anomalies without continuously monitoring all transactions, thus maintaining security detection while reducing unnecessary monitoring operations.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If continuous transaction monitoring is implemented to detect evolving threats, then detection accuracy is improved, but time consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidtime to detect threats
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

IP addresses are captured in advance through tracking pixels and hypertext links in electronic messages, creating a pre-established baseline of expected communication partners. This preliminary capture occurs naturally as part of normal email interactions, without requiring active monitoring during transactions. When anomalies are detected by comparing actual transaction IPs against this pre-captured baseline, detection is immediate and accurate, eliminating time-consuming continuous monitoring while maintaining high detection precision.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If IP tracking from electronic messages is implemented, then security anomaly detection is improved, but device complexity increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system leverages existing electronic message infrastructure and user behavior to automatically capture IP addresses through tracking pixels and hypertext links. The email client and web browser perform the tracking functions autonomously as part of normal operation, without requiring additional dedicated hardware or complex manual processes. The captured IP data is then automatically correlated with transaction data by the security system, enabling anomaly detection through straightforward comparison operations rather than complex analysis.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11922375B2Security data points from an electronic message
Publication Date: 2024.03.05 PAYPAL INC
  • US11922375B2 patent drawing
  • US11922375B2 patent drawing
  • US11922375B2 patent drawing

AI summary

Systems and techniques for providing security data points from an electronic message are presented. A system can determine a first interne protocol (IP) address of a computing device in response to a user of the computing device opening an email sent to an email address corresponding to a particular electronic account of the user, the email comprising an IP address tracking mechanism. The system can also compare the first IP address with one or more second IP addresses corresponding to one or more electronic accesses of the particular electronic account. Furthermore, the system can determine if an account access anomaly exists in regard to the particular electronic account based on a result of the comparing. The system can also implement a security measure impacting an ability of the particular electronic account to conduct one or more transactions in response to the account access anomaly existing for the particular electronic account.