Signed Email Alert System for Abusive Account Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email systems fail to effectively detect and mitigate malicious activities from compromised or shell email accounts, as users and providers often remain unaware of such threats, leading to increased prevalence of spam, malware, and phishing attempts.

Innovation Solution

Implementing a system where a reporting email with a digital signature is transmitted between email servers to alert both the abusive account owner and provider, utilizing a trust relationship established through encryption keys or Domain Name System (DNS), enabling identification and action against malicious accounts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If email providers and users remain unaware of compromised accounts to maintain system simplicity, then device complexity is reduced, but security reliability deteriorates due to increased spam and malware transmission

Engineering Contradiction:
Improveemail securityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary detection by analyzing email content and sender information before transmission completes, identifying compromised accounts in advance. This allows proactive notification to email providers and users before significant damage occurs, resolving the contradiction by enabling security actions without requiring complex continuous monitoring systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary detection system that analyzes email traffic and communicates findings between senders and receivers. This intermediary layer identifies compromised accounts through content analysis and notifies relevant parties without requiring the entire email system to become complex, thus maintaining reliability while limiting complexity growth.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If automated detection and notification systems are implemented to identify abusive accounts, then email security is improved, but system complexity increases due to additional detection and communication mechanisms

Engineering Contradiction:
Improveabusive account detectionVSAvoidnotification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The detection system enables email providers to self-identify compromised accounts by analyzing their own email traffic patterns and content. The system automatically generates notifications and communicates them to relevant parties without requiring complex external management infrastructure, thus improving detection capability while keeping the notification system relatively simple.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes key parameters by focusing detection on specific email content characteristics and sender attributes rather than monitoring all system activities. This selective approach enables effective abusive account detection through analysis of particular parameters like email content patterns, sender reputation, and communication behavior, reducing the overall system complexity.

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If real-time notification of compromised accounts is implemented, then response time is improved, but information processing requirements and system complexity increase

Engineering Contradiction:
Improvenotification timeVSAvoidreal-time processing complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system implements rapid detection by skipping extensive analysis and focusing directly on key indicators of compromised accounts. When suspicious patterns are detected, the system rushes through the notification process by directly communicating with email providers and users without requiring complex multi-layer verification, thus reducing notification time while maintaining acceptable processing complexity.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS9635038B2Signed response to an abusive email account owner and provider systems and methods
Publication Date: 2017.04.25 PAYPAL INC
  • US9635038B2 patent drawing
  • US9635038B2 patent drawing
  • US9635038B2 patent drawing

AI summary

Systems and methods for abusive email account detection and transmission of a signed response to an abusive email account owner and provider. The methods include receiving an email from a first email account on a second email account, wherein the email contains malicious content, determining if a trust relationship exists between a first email server corresponding to the first email account and a second email server corresponding to the second email account, and transmitting, using a hardware processor of the second email server, an alert email to the first email account corresponding to the trust relationship, wherein the alert email includes a digital signature and a secure field having an abusive category descriptor in an email header. The secure field may include an abusive category descriptor, for example transmitting spam, transmitting malware, transmitting phishing attempts, and committing fraud.