Social Engineering Protection Appliance Using Behavioral Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for protecting users from social engineering attacks are limited, as they primarily focus on analyzing email content for standard patterns, which is ineffective when the email lacks these patterns or when external information is constantly changing.

Innovation Solution

The system analyzes incoming emails by comparing extracted information against a data store, performing behavioral analysis, analyzing semantic information for patterns suggestive of social engineering attacks, and forwarding emails to analysts for manual review, all of which can be done in real-time or near real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional email analysis methods focus on standard patterns within email content, then the analysis process is simple, but the detection accuracy decreases when emails lack standard patterns or use evolving external information

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The analysis process is divided into four distinct operations: comparing extracted information against a data store, performing behavioral analysis, analyzing semantic information for patterns, and forwarding to analysts for manual review. This segmentation allows each operation to specialize in specific detection aspects, improving overall detection accuracy while managing complexity through modular processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary data store that contains previously collected information about malicious entities, domains, and IP addresses. This intermediary enables the system to detect social engineering attacks by referencing external information without requiring direct analysis of all external sources, thus improving detection accuracy while simplifying the analysis process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system performs comprehensive analysis including external data comparison and behavioral analysis, then detection capability improves, but processing time increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-collecting and storing information about malicious entities, domains, and IP addresses in a data store before actual email analysis occurs. This preliminary action enables faster detection during email processing, as the system can quickly compare extracted information against pre-existing data rather than performing comprehensive external analysis in real-time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements partial analysis by performing four specific operations that may not all be applied to every email. The system can selectively apply comparison against the data store, behavioral analysis, and semantic analysis based on the email's characteristics, thereby maintaining high detection capability while reducing processing time for emails that require fewer analysis operations.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If the system uses external information that is constantly changing, then detection accuracy improves, but the system complexity and maintenance requirements increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem adaptability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system incorporates feedback mechanisms where analysts review emails forwarded for manual analysis and provide feedback on detection accuracy. This feedback loop enables the system to learn from real-world cases and improve its detection algorithms, allowing it to adapt to evolving social engineering tactics while maintaining high detection accuracy through continuous improvement rather than constant system redesign.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9123027B2Social engineering protection appliance
Publication Date: 2015.09.01 QINETIQ NORTH AMERICA
  • US9123027B2 patent drawing
  • US9123027B2 patent drawing
  • US9123027B2 patent drawing

AI summary

Methods and systems for detecting social engineering attacks comprise: extracting one or more non-semantic data items from an incoming email; determining whether the one or more non-semantic data items match information stored in a data store of previously collected information; performing behavioral analysis on the one or more non-semantic data items; analyzing semantic data associated with the email to determine whether the non-semantic data matches one or more patterns associated with malicious emails; and based on the determining, performing, and analyzing, identifying the email as potentially malicious or non-malicious. The system also includes processes for collecting relevant information for storage within the data store and processes for harvesting information from detected social engineering attacks for entry into the data store and seeding of the collection processes.