Malicious Communication Detection System Using Indicator Packages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of electronic communications has led to an increase in malicious communications that are difficult to detect and mitigate in real-time across multiple computer terminals, posing threats to data security and system functionality.

Innovation Solution

A computerized system configured to analyze electronic communications for malicious attachments, URLs, and indicators of compromise, constructing indicator packages for threat prevention systems, and transmitting these indicators to networked devices to enhance threat defense, while also simulating malicious communications for user training and transmitting threat trigger signals to third-party provider systems for real-time blocking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security systems are used to detect malicious communications, then system complexity is reduced, but detection capability and response time deteriorate

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security system is divided into multiple specialized modules: communication interceptor for capturing communications, analyzer for examining communications and extracting indicators, database for storing indicators, and threat prevention system for blocking threats. Each module performs a specific function, improving detection capability while managing complexity through functional segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces indicator packages as intermediary data structures that bridge the gap between communication analysis and threat prevention. These standardized packages containing indicators of compromise (IOCs) enable efficient information exchange between modules and external systems, improving detection precision without proportionally increasing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If real-time analysis of all electronic communications is performed, then detection speed is improved, but processing load and resource consumption increase

Engineering Contradiction:
Improveresponse timeVSAvoidprocessing load
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary extraction of indicators of compromise from communications during the analysis phase, storing these indicators in advance in the database. This preliminary action enables the threat prevention system to quickly compare incoming communications against known indicators without performing full analysis in real-time, reducing processing load while maintaining fast response times.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The analyzer extracts specific indicators of compromise (such as malicious URLs, email addresses, file hashes) from communications and separates them into standardized indicator packages. This extraction approach focuses processing on identifying key threat indicators rather than analyzing entire communications, significantly reducing processing load while maintaining detection speed.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If comprehensive threat indicators are collected and distributed across multiple devices, then protection coverage is improved, but communication overhead and data transmission increase

Engineering Contradiction:
Improveprotection coverageVSAvoidcommunication overhead
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

Each networked device maintains its own threat prevention system with locally stored indicator packages. This local quality approach allows each device to independently block threats using indicators relevant to its specific context, improving protection coverage across the network without requiring constant centralized communication. Devices receive indicator packages from the security system and apply them locally.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If multiple analysis methods are applied to each communication, then detection accuracy is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The analyzer dynamically selects and applies analysis methods based on the characteristics of each communication and the current threat landscape. Rather than applying all possible analysis methods uniformly to every communication, the system adapts its analysis approach, applying more comprehensive methods only when necessary, thereby improving detection accuracy while minimizing processing time.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11516248B2Security system for detection and mitigation of malicious communications
Publication Date: 2022.11.29 ECRIME MANAGEMENT STRATEGIES INC D B A PHISHLABS
  • US11516248B2 patent drawing
  • US11516248B2 patent drawing
  • US11516248B2 patent drawing

AI summary

Embodiments of the present invention relate to, in general, detecting and mitigating malicious communications. Typically, a system of the present invention is configured to deliver indicators of compromise in response to identifying and isolating malicious communication. Moreover, the system is configured to analyze an electronic communication to determine if it is malicious or if it has a malicious payload. In some embodiments, the system is configured to determine an indicator of compromise for the electronic communication determined to be malicious, and transmit this indicator of compromise to the first networked device. In some embodiments, the system transmits a threat trigger signal to a third party provider. The threat trigger signal is configured to allow an application or system provided by the third party provider to block a threat caused by the electronic communication. In some embodiments, the system provides training to help users better identify and report threats.