Sender Influence Analysis for Email Security Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current email security systems face challenges in effectively distinguishing between legitimate and spoofed messages, particularly those from high-influence senders, leading to false positives and negatives, which can result in legitimate emails being misclassified as threats or genuine threats being missed.

Innovation Solution

A system that analyzes the influence of a message sender by evaluating past communications, including volume, content, and role within an organization, to determine a security risk score for each message, allowing for tailored filtering and action based on the sender's influence and relationship with the recipient.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional email security filtering is applied uniformly to all senders, then security risk is reduced, but false positive rate increases causing legitimate emails to be blocked

Engineering Contradiction:
Improvesecurity risk reductionVSAvoidemail delivery rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different security filtering criteria to different senders based on their influence level. High-influence senders (executives, managers) receive tailored analysis that considers their communication patterns, relationship with recipients, and contextual factors. This localized approach adjusts the security threshold dynamically, reducing false positives for legitimate high-influence communications while maintaining strict filtering for unknown or low-trust senders.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security filtering system dynamically adapts its behavior based on sender characteristics, recipient relationships, and communication context. The system continuously learns from communication patterns and adjusts filtering sensitivity in real-time, making the security measure flexible rather than static. This allows the system to respond appropriately to each message's specific risk profile.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If uniform security filtering is applied to all emails, then processing simplicity is maintained, but measurement precision of security risk deteriorates

Engineering Contradiction:
Improvefiltering system complexityVSAvoidsecurity risk assessment accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent segments the email population into different categories based on sender influence, recipient relationship, and communication context. Instead of treating all emails uniformly, the system divides them into risk tiers and applies appropriate analysis depth to each segment. This segmentation enables precise risk measurement without requiring complex analysis of every single email.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes key parameters such as analysis depth, filtering threshold, and evaluation criteria based on the sender's influence level and relationship with the recipient. For high-influence senders with established relationships, the system uses different (less stringent) parameters compared to unknown senders, thereby improving measurement precision without uniform complexity.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If sender influence analysis is implemented, then false positive rate is reduced, but computational resources and processing time increase

Engineering Contradiction:
Improvefalse positive reductionVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies partial analysis to most emails and reserves excessive (full) analysis only for cases where it is necessary. The system performs quick initial assessment on all incoming emails and only applies comprehensive sender influence analysis when the initial filter identifies potential high-risk or high-value messages. This partial action approach reduces overall computational resource consumption while maintaining high false positive reduction capability.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary filtering and basic analysis before applying the more computationally intensive sender influence analysis. By pre-processing emails and identifying only those that require detailed examination, the system reduces the total computational load. The preliminary action stage quickly eliminates obvious spam and low-risk messages, preventing unnecessary resource expenditure on them.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If comprehensive sender analysis is performed on all messages, then security risk detection is improved, but processing speed decreases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidemail processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements periodic or phased analysis where comprehensive sender evaluation is applied selectively rather than continuously to all messages. The system uses a multi-stage process where only certain messages undergo full analysis at different processing phases. This periodic application of intensive analysis maintains threat detection capability while preserving overall processing speed.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system skips comprehensive analysis for messages that can be quickly evaluated as low-risk based on initial criteria. High-volume, low-risk traffic is rushed through a streamlined path with minimal analysis, while only suspicious or high-value messages receive the full comprehensive treatment. This skipping approach maintains processing speed for the majority of traffic while ensuring thorough analysis where needed.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11722513B2Using a measure of influence of sender in determining a security risk associated with an electronic message
Publication Date: 2023.08.08 AGARI DATA INC
  • US11722513B2 patent drawing
  • US11722513B2 patent drawing
  • US11722513B2 patent drawing

AI summary

A measure of influence of a sender entity is determined for a message receiving entity based at least in part on an analysis of previous electronic messages sent by the sender entity. An electronic message associated with the sender entity is received. The measure of influence of the sender entity is utilized to determine a security risk associated with the received electronic message.