Malware Detection via Stored Message Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic message security systems fail to effectively protect against threats like phishing attacks by not providing user authorization and dynamically updating threat protection rules, leading to resource overload and inadequate protection.

Innovation Solution

A malware detection system that uses stored data from messaging systems to check messages for threats, incorporating user authorization and transforming resource references into protected ones, ensuring only authorized users access resources through a secure mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security checking resources are made widely available to protect message recipients, then threat protection coverage is improved, but system resources such as processor capacity, memory, or network bandwidth are overwhelmed

Engineering Contradiction:
Improvethreat protection coverageVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent introduces a server as an intermediary between message recipients and security checking resources. The server receives requests from multiple recipients, consolidates them, and performs centralized security checks. This intermediary architecture allows widespread threat protection while preventing resource overload by batching and deduplicating security checking operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security checks are performed at the time of message recipient access, then protection against dynamic threats is improved, but unauthorized users can also access protected resources

Engineering Contradiction:
Improveprotection against dynamic threatsVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs security checks on resource references before providing them to message recipients. The server validates and secures links and attachments in advance, creating protected resource references that contain security tokens or credentials. When recipients access these pre-secured resources, the authorization is already embedded, preventing unauthorized access while maintaining dynamic threat protection.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If rules and threat signatures are manually configured by administrators, then security control precision is improved, but system complexity and resource intensity increase

Engineering Contradiction:
Improvesecurity control precisionVSAvoidsystem configuration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements automated rule generation that uses stored message data and contact information to dynamically create security rules and threat signatures. The system analyzes patterns from historical messages, identified contacts, and threat data to automatically generate updated security policies. This self-service approach maintains high security control precision while eliminating manual configuration complexity and keeping rules current without administrator intervention.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10764316B2Malware detection system based on stored data
Publication Date: 2020.09.01 MIMECAST SERVICES LTD
  • US10764316B2 patent drawing
  • US10764316B2 patent drawing
  • US10764316B2 patent drawing

AI summary

A malware detection system based on stored data that analyzes an electronic message for threats by comparing it to previously received messages in a message archive or to a contacts list. Threat protection rules may be generated dynamically based on the message and contacts history. A message that appears suspicious may be blocked, or the system may insert warnings to the receiver not to provide personal information without verifying the message. Threat checks may look for unknown senders, senders with identities that are similar to but not identical to previous senders or to known contacts, or senders that were added only recently as contacts. Links embedded in messages may be checked by comparing them to links previously received or to domain names of known contacts. The system may flag messages as potential threats if they contradict previous messages, or if they appear unusual compared to the patterns of previous messages.