Phishing Source Tool Identifies Original Email

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Phishing emails pose a significant risk to computing systems and networks as they can deceive recipients into providing sensitive information or installing malicious software, and existing methods struggle to effectively identify and block the original source of forwarded phishing emails, making it difficult to prevent further attacks.

Innovation Solution

A system comprising a processor and a phishing management device that analyzes forwarded emails for keywords, searches an email server to identify the original email, and attaches relevant information to the forwarded email, allowing administrators to determine the source and block future phishing attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If phishing emails are forwarded without analysis, then the spread of phishing emails increases, but the ability to identify and block the original source decreases

Engineering Contradiction:
Improvespread of phishing emailsVSAvoididentification of original source
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The system performs preliminary analysis by extracting keywords from the forwarded phishing email and proactively searching the email server for the original message before the phishing campaign can spread further. This preliminary action enables early identification of the source while preventing additional propagation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses keywords as an intermediary element to bridge the forwarded phishing email and the original source email. By extracting distinctive keywords from the phishing email and searching for them in the email server, the system mediates between the harmful forwarded message and the original source that needs to be blocked.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive search is performed to identify original phishing email source, then identification accuracy improves, but processing time increases

Engineering Contradiction:
Improveidentification accuracy of original emailVSAvoidprocessing time for search and analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts only the most relevant keywords from the forwarded phishing email rather than analyzing the entire message. This extraction approach maintains identification accuracy by focusing on distinctive terms while significantly reducing the search space and processing time required to locate the original source in the email server.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs a targeted partial search using selected keywords rather than comprehensive full-text analysis of all emails. This partial action approach achieves sufficient identification accuracy for phishing detection while avoiding the excessive time consumption that would result from exhaustive searching.

Inventive Principle:
Principle #16Partial or excessive action

3Difficulty of detecting and measuring

If keyword search is performed on email server, then source identification capability improves, but system complexity increases

Engineering Contradiction:
Improvesource detection capabilityVSAvoidsystem complexity for search and attach operations
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system uses a universal keyword search mechanism that leverages existing email server search capabilities rather than implementing a specialized detection system. This multi-functional approach uses the same search infrastructure for both routine email operations and phishing source detection, improving source detection capability without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system attaches the identified original email portion back to the phishing report automatically, enabling self-service functionality. This eliminates the need for manual intervention to retrieve and attach source evidence, improving detection capability while keeping the added complexity minimal through automation of routine tasks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10110628B2Phishing source tool
Publication Date: 2018.10.23 BANK OF AMERICA CORP
  • US10110628B2 patent drawing
  • US10110628B2 patent drawing
  • US10110628B2 patent drawing

AI summary

According to one embodiment, an apparatus includes a memory and a processor. The processor is configured to receive a forwarded email and to determine a plurality of keywords in the forwarded email. The processor is further configured to search an email server using the plurality of keywords and to determine that an email message from the plurality of email messages is the original email corresponding to the forwarded email. The processor is also configured to attach a portion of the determined email message to the forwarded email.