Malicious Message Defense via Automated Risk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies are ineffective in defending against malicious electronic messages that induce detrimental actions, such as financial loss or security breaches, as they often rely on recipients ignoring such messages, and professional scammers target recipients with multiple messages to achieve desired results.

Innovation Solution

A computer-implemented method that analyzes electronic messages for predefined risk elements, detects potential security risks associated with user actions, and performs preventive security actions to mitigate these risks, including preventing harmful actions and notifying users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If recipients ignore malicious electronic messages, then security risk is reduced, but productivity is worsened due to loss of time for manual review and response

Engineering Contradiction:
Improvesecurity risk reductionVSAvoidtime loss for manual review
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables automatic self-protection by analyzing electronic messages and detecting security risks without requiring user intervention. The computer automatically performs risk analysis, detects potential threats, and executes preventive actions, freeing users from manual security review while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

An intermediary system is introduced between the user and malicious messages. This intermediary automatically analyzes messages for risk elements, detects security risks, and performs preventive actions, serving as a buffer that protects users from harmful content without requiring their direct involvement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If professional scammers send multiple messages to recipients, then the likelihood of achieving desired results is improved, but the complexity of detecting and measuring the security threat worsens

Engineering Contradiction:
Improvescammer success rateVSAvoidthreat detection complexity
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary analysis of electronic messages by identifying risk elements before users interact with them. By detecting potential security risks in advance and executing preventive actions beforehand, the system neutralizes threats from multiple scammer messages before they can accumulate or overwhelm the user.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors and analyzes electronic messages, providing ongoing feedback about detected security risks. This continuous feedback mechanism tracks multiple messages over time, identifying patterns and escalating threats, thereby simplifying the detection of coordinated scammer campaigns despite their complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10333950B2Defending against malicious electronic messages
Publication Date: 2019.06.25 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10333950B2 patent drawing
  • US10333950B2 patent drawing
  • US10333950B2 patent drawing

AI summary

Defending against malicious electronic messages by analyzing electronic messages sent via a computer network to identify predefined risk elements found within the electronic messages, detecting attempts to perform computer-mediated actions that are associated with the electronic messages, identifying a potential security risk associated with the electronic messages and the computer-mediated actions, and performing a predefined preventive security action responsive to identifying the potential security risk.