Spear-phishing Detection via Social Network and Email Data Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies are ineffective in accurately identifying and preventing spear-phishing attempts in electronic mail, as they fail to distinguish between legitimate and malicious sources, often relying on superficial analysis and lacking comprehensive data integration from social networks and email servers.
Innovation Solution
A security system that analyzes social-network data, including page-view and page-content information, and compares it with email data to identify potentially malicious sources, generating alerts or instructions to block or process suspicious messages, thereby enhancing the accuracy of spear-phishing detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If comprehensive data analysis from multiple sources is implemented, then identification accuracy of spear-phishing attempts is improved, but system complexity increases
Solution Approach 1:
The system segments the complex security analysis task into distinct functional modules: a social-network data analysis unit that processes social-network data to identify potentially malicious sources, and an e-mail data analysis unit that processes e-mail data to identify suspicious messages. These segmented units work independently but coordinate through a central security unit, making the overall complex system more manageable and maintainable while achieving high identification accuracy through comprehensive multi-source data analysis.
Solution Approach 2:
The patent introduces intermediary components including a security unit that acts as a mediator between social-network data analysis and e-mail data analysis, and an e-mail server that serves as an intermediary between the security system and end users. These intermediaries coordinate data flow and analysis results across different system components, enabling comprehensive multi-source data integration while maintaining system modularity and reducing overall complexity.
2Reliability
If social-network data and e-mail data are integrated for analysis, then spear-phishing detection capability is improved, but data processing time increases
Solution Approach 1:
The system performs preliminary analysis of social-network data to identify potentially malicious sources before e-mail messages from these sources are received or while they are being processed. The social-network data analysis unit proactively monitors and analyzes social-network data, pre-identifying suspicious sources. When e-mail messages from these pre-identified sources arrive, the security unit can quickly match them against the pre-analyzed malicious source data, significantly reducing the time required for comprehensive multi-source data integration and analysis.
3Measurement precision
If multiple data sources are analyzed, then accuracy of identifying malicious sources is improved, but resource consumption increases
Solution Approach 1:
The system applies local quality analysis by focusing computational resources on specific high-risk areas rather than uniformly processing all data. The social-network data analysis unit identifies potentially malicious sources with high precision, and the security unit then focuses e-mail analysis primarily on messages from these identified sources. This localized focus on high-probability threat areas maintains high identification accuracy while significantly reducing overall resource consumption compared to analyzing all e-mail data from all sources equally.
Data Source
AI summary
One or more processors receive, from one or more social-network sources, social-network data that identifies at least one potentially malicious source accessing a plurality of social-network profiles for a group of users. The one or more processors receive, from one or more e-mail servers, e-mail data associated with a plurality of e-mail messages received by the group of users. The one or more processors determine, based on the social-network data and the e-mail data, that an e-mail message of the plurality of e-mail messages is from the at least one potentially malicious source. The one or more processors output information identifying the e-mail message as being from the potentially malicious source.


