Sender Influence Analysis for Email Security Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current email security systems face challenges in effectively distinguishing between legitimate and spoofed messages, particularly those from high-influence senders, leading to false positives and negatives, which can result in legitimate emails being misclassified as threats or genuine threats being missed.
Innovation Solution
A system that analyzes the influence of a message sender by evaluating past communications, including volume, content, and role within an organization, to determine a security risk score for each message, allowing for tailored filtering and action based on the sender's influence and relationship with the recipient.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional email security filtering is applied uniformly to all senders, then security risk is reduced, but false positive rate increases causing legitimate emails to be blocked
Solution Approach 1:
The patent applies different security filtering criteria to different senders based on their influence level. High-influence senders (executives, managers) receive tailored analysis that considers their communication patterns, relationship with recipients, and contextual factors. This localized approach adjusts the security threshold dynamically, reducing false positives for legitimate high-influence communications while maintaining strict filtering for unknown or low-trust senders.
Solution Approach 2:
The security filtering system dynamically adapts its behavior based on sender characteristics, recipient relationships, and communication context. The system continuously learns from communication patterns and adjusts filtering sensitivity in real-time, making the security measure flexible rather than static. This allows the system to respond appropriately to each message's specific risk profile.
2Device complexity
If uniform security filtering is applied to all emails, then processing simplicity is maintained, but measurement precision of security risk deteriorates
Solution Approach 1:
The patent segments the email population into different categories based on sender influence, recipient relationship, and communication context. Instead of treating all emails uniformly, the system divides them into risk tiers and applies appropriate analysis depth to each segment. This segmentation enables precise risk measurement without requiring complex analysis of every single email.
Solution Approach 2:
The system changes key parameters such as analysis depth, filtering threshold, and evaluation criteria based on the sender's influence level and relationship with the recipient. For high-influence senders with established relationships, the system uses different (less stringent) parameters compared to unknown senders, thereby improving measurement precision without uniform complexity.
3Measurement precision
If sender influence analysis is implemented, then false positive rate is reduced, but computational resources and processing time increase
Solution Approach 1:
The patent applies partial analysis to most emails and reserves excessive (full) analysis only for cases where it is necessary. The system performs quick initial assessment on all incoming emails and only applies comprehensive sender influence analysis when the initial filter identifies potential high-risk or high-value messages. This partial action approach reduces overall computational resource consumption while maintaining high false positive reduction capability.
Solution Approach 2:
The system performs preliminary filtering and basic analysis before applying the more computationally intensive sender influence analysis. By pre-processing emails and identifying only those that require detailed examination, the system reduces the total computational load. The preliminary action stage quickly eliminates obvious spam and low-risk messages, preventing unnecessary resource expenditure on them.
4Reliability
If comprehensive sender analysis is performed on all messages, then security risk detection is improved, but processing speed decreases
Solution Approach 1:
The patent implements periodic or phased analysis where comprehensive sender evaluation is applied selectively rather than continuously to all messages. The system uses a multi-stage process where only certain messages undergo full analysis at different processing phases. This periodic application of intensive analysis maintains threat detection capability while preserving overall processing speed.
Solution Approach 2:
The system skips comprehensive analysis for messages that can be quickly evaluated as low-risk based on initial criteria. High-volume, low-risk traffic is rushed through a streamlined path with minimal analysis, while only suspicious or high-value messages receive the full comprehensive treatment. This skipping approach maintains processing speed for the majority of traffic while ensuring thorough analysis where needed.
Data Source
AI summary
A measure of influence of a sender entity is determined for a message receiving entity based at least in part on an analysis of previous electronic messages sent by the sender entity. An electronic message associated with the sender entity is received. The measure of influence of the sender entity is utilized to determine a security risk associated with the received electronic message.


