Malicious Email Detection With Text and Rendered Image Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email security systems struggle to effectively detect sophisticated malicious email attacks due to the rapid evolution of attack methods, making it difficult to maintain security mechanisms at the same pace as the changing landscape of threats.

Innovation Solution

An email security system that utilizes machine learning models to analyze both text and image data derived from email markup payloads, rendering emails into image data to detect visual indicators of malicious content, and determining predictions based on both representations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional text-based analysis methods are used to detect malicious emails, then the system is simple to implement, but the detection precision is insufficient against sophisticated attacks

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms email detection from traditional text-based analysis to visual representation analysis by rendering email markup payloads as images. This dimensional change allows the system to detect malicious content through visual patterns that are not apparent in text form, thereby improving detection precision while using established image processing techniques.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent replaces traditional text-based security scanning mechanisms with machine learning models trained on visual representations of emails. This substitution enables the system to identify sophisticated malicious patterns through visual特征 recognition, significantly improving detection accuracy against modern phishing and spoofing attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If multiple machine learning models are used to analyze both text and image data, then the detection reliability is improved, but the computational resources and processing time increase

Engineering Contradiction:
Improvedetection reliabilityVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary rendering of email markup payloads into visual representations before analysis. By pre-processing emails into a standardized visual format, the system enables efficient batch processing by machine learning models, reducing redundant computational operations while maintaining high detection reliability through multi-model analysis.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If visual indicators are used to detect malicious emails, then the detection effectiveness is improved, but the processing time increases due to rendering and image analysis

Engineering Contradiction:
Improvedetection effectivenessVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by selectively analyzing visual indicators only for emails that exhibit suspicious characteristics in preliminary text-based filtering. This approach focuses computational resources on high-risk emails, maintaining high detection effectiveness while minimizing processing time for benign emails that can be quickly filtered using traditional methods.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12381914B2Detecting malicious email attacks based on entity image analysis
Publication Date: 2025.08.05 CISCO TECHNOLOGY INC
  • US12381914B2 patent drawing
  • US12381914B2 patent drawing
  • US12381914B2 patent drawing

AI summary

In some aspects, the techniques described herein relate to a method for detecting malicious emails, the method including: receiving an email, wherein the email is associated with a markup payload; determining, based on the markup payload, text data associated with the email; determining, using the text data and a first machine learning model, a first representation of the email representing text associated with the email; rendering the email to generate image data that represents a rendering of the email; determining, using the image data and a second machine learning model, a second representation of the email that represents at least the rendering of the email; and determining a prediction for the email based on the first representation and the second representation, wherein the prediction represents whether the email is predicted to be malicious based on the first representation and the second representation.