Stylometric Sender Authentication for Spear Phishing Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing email security solutions fail to prevent sophisticated spear phishing attacks due to their inability to authenticate the identity of email senders effectively, as they rely on pattern recognition and keyword analysis, which are ineffective against customized messages from trusted sources and do not protect against compromised local accounts.
Innovation Solution
A personalized message classification system that authenticates senders by analyzing their writing style and relationship through stylometric analysis, comparing message features to stored sender profiles, and validating outgoing messages to prevent account hijacking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional pattern recognition and keyword analysis are used for email filtering, then spam detection is effective, but spear phishing attacks from trusted sources cannot be detected
Solution Approach 1:
The patent replaces traditional mechanical pattern recognition and keyword analysis with stylometric analysis that examines writing style characteristics. This substitution enables detection of spear phishing attacks by analyzing authorship attributes rather than relying on fixed patterns, thereby improving reliability against sophisticated attacks while maintaining adaptability to customized messages.
Solution Approach 2:
The system changes the parameters used for email analysis from static keywords and patterns to dynamic stylometric features such as writing style, vocabulary usage, and sentence structure. This parameter transformation allows the system to detect spear phishing attacks from trusted sources by identifying inconsistencies in authorship characteristics rather than relying on traditional filtering parameters.
2Reliability
If sender identity authentication is not implemented, then email processing is fast, but compromised accounts can be leveraged to send unwanted messages
Solution Approach 1:
The system performs preliminary stylometric analysis on incoming emails to authenticate sender identity before full processing. By conducting authorship verification in advance, the system ensures reliability of sender authentication while maintaining productivity through early detection and filtering of compromised accounts, avoiding unnecessary processing of malicious messages.
3Measurement precision
If stylometric analysis is performed on all messages, then sender authentication accuracy is improved, but computational complexity increases
Solution Approach 1:
The system applies stylometric analysis selectively rather than uniformly to all messages. By focusing computational resources on messages that require authentication or exhibit suspicious characteristics, the system improves measurement precision for sender authentication while reducing overall computational complexity through localized application of the analysis.
Data Source
AI summary
Technologies are described for authenticating a sender identity of an online message. For example, an online message having a purported sender identity can be obtained. Various features can then be extracted from the message, including stylometric features, origin location features, attached file features for any files attached to the message, and embedded URL features. The extracted features can then be compared to a sender profile for a known sender identity matching the purported sender identity, or to one or more sender profiles for recognized suspicious senders if the purported sender identity does not match a known sender identity. The sender profile for a given sender identity can include features extracted from one or more messages previously sent by the sender identity. A global risk score for the message indicating a likelihood that the purported sender identity is inauthentic can be determined based at least in part upon the comparison.


