Phishing Detection Platform Preserving Email Headers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise organizations face challenges in accurately distinguishing between phishing messages and legitimate messages due to loss of header information and metadata when forwarding messages for analysis, leading to less accurate phishing identification.
Innovation Solution
A computing platform that includes a processor, communication interface, and memory, capable of receiving messages flagged as potentially malicious, parsing them using machine learning algorithms, and generating new messages with attached header information and metadata for further analysis, thereby preserving important details for enhanced phishing identification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If messages are forwarded to another computing platform for further analysis, then message analysis capability is improved, but header information and metadata are lost
Solution Approach 1:
The patent creates a copy of the original message including all header information and metadata, and attaches it to the forwarded message. This copying approach allows the message to be analyzed at multiple platforms without losing critical header data, as the attached copy preserves all original information while enabling distributed analysis capability.
2Measurement precision
If header information and metadata are preserved when forwarding messages, then phishing identification accuracy is improved, but message processing complexity increases
Solution Approach 1:
The patent embeds the original message with its complete header information and metadata as an attachment within a new forwarded message. This nesting structure allows preservation of all critical analysis data while maintaining a clean, organized message format that doesn't significantly increase processing complexity. The nested attachment contains the complete original message structure, enabling comprehensive analysis without complicating the outer message framework.
Data Source
AI summary
Aspects of the disclosure relate to a message processing platform for enhanced phishing message detection. A computing platform may receive a first message from a first source entity, where the first message was flagged as potentially malicious through selection of a malicious message button in a mobile banking application, and where the first message includes content from the first source entity pretending to be a second source entity different than the first source entity. Using one or more machine learning algorithms, the computing platform may parse the first message to identify the second source entity. The computing platform may identify an enterprise security system associated with the second source entity, and may generate a second message that includes the first message as an attachment and indicates that the first message was flagged as potentially malicious. Subsequently, the computing platform may send, to the enterprise security system, the second message.


