Social Engineering Detection via Communication Event Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional detection systems fail to effectively detect attacks that utilize social engineering methods, as they do not consider psychological manipulation and multiple source interactions when monitoring user behavior.

Innovation Solution

A detection device with a processing circuit that monitors communication events, builds user profiles through machine learning, and determines whether authenticated user behavior aligns with normal access patterns, using natural language and semantic analysis to identify potential attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional detection systems check logs of computers to find lateral movements, then network attacks can be detected, but social engineering attacks cannot be detected because they do not involve lateral movements

Engineering Contradiction:
Improveattack detection capabilityVSAvoiddetection method coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments detection into two distinct modules: one for detecting lateral movements in network logs (technical attacks) and another for detecting social engineering trials through communication event analysis. This segmentation allows each module to specialize in specific attack types, improving overall detection reliability while maintaining versatility through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from purely network-log-based detection to a multi-dimensional approach that includes communication events (emails, messages, calls) as an additional dimension. By analyzing communication patterns, user interactions, and behavioral anomalies across multiple data sources, the system can detect social engineering attacks that do not manifest as traditional lateral movements.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If detection systems monitor multiple sources for social engineering trials, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system merges multiple detection functions into a unified platform that simultaneously monitors network logs and communication events. By integrating profile building, anomaly detection, and correlation analysis into a single system, it achieves high detection accuracy across multiple sources while managing complexity through unified architecture rather than separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system automatically builds user profiles through machine learning and performs self-adjusting anomaly detection without requiring manual configuration for each user or attack scenario. This self-service capability allows the system to handle multiple data sources and complex analysis tasks while maintaining operational simplicity for users.

Inventive Principle:
Principle #25Self-service

3Reliability

If machine learning is used to build user profiles for behavior analysis, then social engineering detection improves, but processing time and computational resources increase

Engineering Contradiction:
Improvesocial engineering detection capabilityVSAvoidprofile building and analysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously building and updating user profiles in the background using machine learning, so that when a potential social engineering attack occurs, the detection can immediately compare against pre-established behavioral baselines. This eliminates the need for time-consuming analysis at the moment of detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The profile building process operates continuously in the background, constantly learning from user communications and behaviors. This continuous learning ensures that profiles are always up-to-date and accurate without interrupting normal operations or requiring periodic batch processing, thereby minimizing time loss while maintaining high detection reliability.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11743346B2Detection device, detection method, and detection program
Publication Date: 2023.08.29 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11743346B2 patent drawing
  • US11743346B2 patent drawing

AI summary

A detection device monitors a communication event including communication by humans when a legitimate user accesses sensitive data for each legitimate user. The detection device builds a profile of the user indicating normal behavior when the user accesses the sensitive data by performing machine learning on a result of the monitoring. After that, the detection device acquires a communication event when a user to be authenticated accesses sensitive data. The detection device determines whether behavior of the user to be authenticated indicated in the acquired communication event corresponds to normal behavior when the user accesses the sensitive data indicated in a profile of the user, and outputs a result of the determination.