Misuse Detection Scoring Module for Email Malice Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting social engineering attacks, such as phishing, are limited as they primarily focus on analyzing email content for standard patterns and clues, which is ineffective when the email lacks these patterns or when malicious content is constantly changing, necessitating a system that evaluates external information for determining potential maliciousness.

Innovation Solution

A system and method that utilize a scoring module to provide a numerical score for digital documents, evaluating text, links, metadata, and other factors to determine the likelihood of malicious content, incorporating real-time and post-production analysis, behavioral analysis, and manual review to assess potential social engineering attacks across various digital media platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If standard pattern analysis is used to detect malicious emails, then detection speed is improved, but detection accuracy deteriorates when emails lack standard patterns or use evolving malicious content

Engineering Contradiction:
Improvedetection speedVSAvoiddetection accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The system transitions from static pattern matching to dynamic multi-factor analysis. The scoring module continuously evaluates multiple changing factors (text content, links, metadata, external information) and adjusts the maliciousness score based on current conditions, allowing the detection system to adapt to evolving malicious content while maintaining speed through automated real-time scoring.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The detection system combines multiple different types of information (text analysis, link analysis, metadata evaluation, external information) into a composite scoring mechanism. This composite approach integrates diverse data sources to create a more accurate and robust detection capability that overcomes the limitations of any single analysis method.

Inventive Principle:
Principle #40Composite materials

2Measurement precision

If comprehensive external information evaluation is implemented, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The scoring module operates autonomously to evaluate multiple factors and generate maliciousness scores without requiring constant human intervention or complex manual analysis. The system self-manages the integration of external information and automatically produces detection results, reducing operational complexity despite the comprehensive nature of the analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The scoring module serves multiple functions simultaneously: it evaluates text content, analyzes links, assesses metadata, incorporates external information, and generates a unified maliciousness score. This multi-functional design consolidates what would otherwise require separate complex systems into a single integrated component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If real-time and post-production analysis are both performed, then detection thoroughness is improved, but processing time increases

Engineering Contradiction:
Improvedetection thoroughnessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic analysis at different stages (real-time during email transmission and post-production before delivery to users). This staged approach distributes the analysis workload across different time periods, allowing comprehensive evaluation without requiring all analysis to complete simultaneously, thus managing processing time effectively while maintaining thoroughness.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9985978B2Method and system for misuse detection
Publication Date: 2018.05.29 ZEROFOX INC
  • US9985978B2 patent drawing
  • US9985978B2 patent drawing
  • US9985978B2 patent drawing

AI summary

This disclosure discusses methods, systems, and an apparatus that can determine whether email content is potentially malicious, contains potentially malicious content, has originated from a potentially malicious entity, or contains links or other references to potentially malicious web content. The disclosure discusses some embodiments that include evaluating text in the email content to determine if predetermined suspected malicious phrases are present in the text, evaluating one or more links in the email content using an IP address, URL, or DNS to determine if the links reference potentially malicious web content, and evaluating metadata in the email content to determine if the email content is potentially malicious.