SMTP Extension Headers for Phishing Email Differentiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for reporting suspected phishing emails are inefficient, leading to legitimate emails being misidentified and increased burden on threat management systems, causing delays in identifying real phishing threats and posing risks to organizational data.

Innovation Solution

The implementation of Simple Mail Transfer Protocol (SMTP) extension headers with predetermined identifiers and specified content to differentiate between simulated phishing emails and trusted emails, allowing for customizable responses and preventing legitimate emails from being deleted or quarantined unnecessarily.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If employees report suspected phishing emails using a PAB plug-in, then phishing detection capability is improved, but legitimate emails may be misidentified and deleted causing loss of useful information

Engineering Contradiction:
Improvephishing detection capabilityVSAvoidlegitimate email retention
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces SMTP extension headers as an intermediary mechanism that carries trust indicators from sending servers to the PAB plug-in. These headers serve as a mediator that enables the plug-in to distinguish between legitimate and phishing emails without requiring complex analysis, thus preventing false positives while maintaining phishing detection capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by having sending servers add trust indicators to SMTP extension headers before emails are delivered to recipients. This pre-marking of trusted emails allows the PAB plug-in to quickly identify and protect legitimate emails from being mistakenly reported as phishing, eliminating the need for post-delivery analysis

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If all suspected emails are forwarded to threat management systems for analysis, then detection accuracy is improved, but system burden increases and processing time is extended

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidemail processing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts the trust verification function from the threat management system and implements it at the email client level through the PAB plug-in. By using SMTP extension headers that contain trust indicators, the verification process is removed from the centralized threat management system, reducing its burden while maintaining detection accuracy for genuine threats

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The PAB plug-in performs self-service by autonomously evaluating SMTP extension headers and making decisions about whether to allow email delivery or forward to threat management systems. This self-service capability eliminates the need for all emails to undergo centralized analysis, improving processing efficiency while maintaining security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12019741B2Systems and methods for providing configurable responses to threat identification
Publication Date: 2024.06.25 KNOWBE4 INC
  • US12019741B2 patent drawing
  • US12019741B2 patent drawing
  • US12019741B2 patent drawing

AI summary

Systems and methods are described for providing customized message content to be displayed to a user of an email client, responsive to the user selecting, via a plug-in or agent of the email client, to report an email as a potential phishing email. In examples, the user may be an employee of an organization and the systems and methods may facilitate a determination by the plug-in or agent of the email client that the reported email is one that does not pose a security risk, such as a simulated phishing email sent by the organization itself, or an email sent from a trusted partner of the organization. The systems and methods may facilitate a customization of the message content that is displayed to the user. In examples, the customized message content may be included or specified within one or more SMTP extension headers of an SMTP email.