Phishing Detection Platform Preserving Email Headers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise organizations face challenges in accurately distinguishing between phishing messages and legitimate messages due to loss of header information and metadata when forwarding messages for analysis, leading to less accurate phishing identification.

Innovation Solution

A computing platform that includes a processor, communication interface, and memory, capable of receiving messages flagged as potentially malicious, parsing them using machine learning algorithms, and generating new messages with attached header information and metadata for further analysis, thereby preserving important details for enhanced phishing identification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If messages are forwarded to another computing platform for further analysis, then message analysis capability is improved, but header information and metadata are lost

Engineering Contradiction:
Improvemessage analysis capabilityVSAvoidheader information and metadata
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent creates a copy of the original message including all header information and metadata, and attaches it to the forwarded message. This copying approach allows the message to be analyzed at multiple platforms without losing critical header data, as the attached copy preserves all original information while enabling distributed analysis capability.

Inventive Principle:
Principle #26Copying

2Measurement precision

If header information and metadata are preserved when forwarding messages, then phishing identification accuracy is improved, but message processing complexity increases

Engineering Contradiction:
Improvephishing identification accuracyVSAvoidmessage processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent embeds the original message with its complete header information and metadata as an attachment within a new forwarded message. This nesting structure allows preservation of all critical analysis data while maintaining a clean, organized message format that doesn't significantly increase processing complexity. The nested attachment contains the complete original message structure, enabling comprehensive analysis without complicating the outer message framework.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11257090B2Message processing platform for automated phish detection
Publication Date: 2022.02.22 BANK OF AMERICA CORP
  • US11257090B2 patent drawing
  • US11257090B2 patent drawing
  • US11257090B2 patent drawing

AI summary

Aspects of the disclosure relate to a message processing platform for enhanced phishing message detection. A computing platform may receive a first message from a first source entity, where the first message was flagged as potentially malicious through selection of a malicious message button in a mobile banking application, and where the first message includes content from the first source entity pretending to be a second source entity different than the first source entity. Using one or more machine learning algorithms, the computing platform may parse the first message to identify the second source entity. The computing platform may identify an enterprise security system associated with the second source entity, and may generate a second message that includes the first message as an attachment and indicates that the first message was flagged as potentially malicious. Subsequently, the computing platform may send, to the enterprise security system, the second message.