Automated Clustering of Malicious Communications for Efficient Triage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in efficiently identifying and managing large volumes of phishing, spam, and malicious electronic communications within local networks, requiring significant resources and often lacking sufficient information for effective decision-making.

Innovation Solution

A computer-implemented data analysis system that groups potentially undesirable electronic communications into clusters based on shared characteristics, automatically analyzes these clusters, and generates an interactive user interface for efficient evaluation and triage, reducing resource requirements and enabling quicker navigation and prioritization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If individual electronic communications are evaluated separately, then decision-making accuracy is improved, but resource consumption and time requirements increase significantly

Engineering Contradiction:
Improvedecision-making accuracyVSAvoidresource efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent groups related electronic communications into clusters based on shared characteristics (sender, subject, recipient, etc.), allowing analysts to evaluate multiple communications simultaneously as a single unit. This merging approach maintains decision-making accuracy by preserving individual communication details within clusters while reducing the overall evaluation burden through batch processing of clustered items.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If all potentially undesirable electronic communications are analyzed in detail, then identification accuracy is improved, but the complexity and time of the process increases

Engineering Contradiction:
Improveidentification accuracyVSAvoidprocess complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the analysis process into two distinct stages: automated clustering that groups communications by shared characteristics, and selective detailed analysis of clustered groups. This segmentation reduces process complexity by handling the volume of communications through automated grouping while reserving detailed analysis for smaller, manageable clusters that require human evaluation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary clustering analysis automatically before human analysts begin detailed evaluation. By pre-grouping communications based on objective criteria (sender addresses, subject lines, recipient patterns), the system prepares the data in advance, reducing the complexity of the subsequent analysis phase and allowing analysts to focus only on evaluating clustered groups rather than individual communications.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive information from individual communications is gathered, then decision quality is improved, but the time required for evaluation increases

Engineering Contradiction:
Improvedecision qualityVSAvoidevaluation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines information from multiple communications within clusters to create a comprehensive view of related threats. By merging data across communications that share characteristics (such as identical senders or subjects), the system accumulates evidence more efficiently, improving decision quality through aggregated information while reducing the time required compared to evaluating each communication separately.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3451201B1Processing malicious communications
Publication Date: 2021.10.27 PALANTIR TECHNOLOGIES INC
  • EP3451201B1 patent drawingFigure 1
  • EP3451201B1 patent drawingFigure 2
  • EP3451201B1 patent drawingFigure 3

AI summary

A data analysis system receives potentially spam, phishing or malicious electronic communications and automatically groups them in computationally-efficient data clusters, automatically analyze those data clusters, automatically tags and groups those data clusters, and provides results of the automated analysis and grouping in an optimized way. The automated analysis of the data clusters may include an automated application of various criteria or rules so as to generate an ordered display of the groups of related data clusters such that quick and efficient evaluation the groups of data clusters may be performed. In particular, the groups of data clusters may be dynamically re-grouped and/or filtered in an interactive user interface so as to enable quick navigation among information associated with various groups of data clusters and efficiently evaluation of those data clusters.