Unprintable Tracking Characters for Spam Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity measures struggle to effectively detect and protect against advanced spam and phishing threats in electronic communications, particularly in text messaging, due to the sophistication of these threats and the limitations of current filtering technologies.

Innovation Solution

The implementation of a system that inserts unprintable tracking characters into character-limited messages, allowing for the detection of suspicious content and the adjustment of filters based on user reports, thereby enhancing the detection and protection against cybersecurity threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If advanced spam filtering techniques are used to detect suspicious messages, then detection accuracy is improved, but spammers can circumvent these filters using more sophisticated techniques

Engineering Contradiction:
Improvedetection accuracyVSAvoidfilter circumvention capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary action by inserting unprintable tracking characters into messages before they are sent. This proactive measure allows the system to track and identify spam messages later, even when they attempt to circumvent filters. The tracking characters are embedded in advance, creating a detection mechanism that operates independently of traditional filtering accuracy.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If traditional spam filtering is used, then device complexity is kept low, but the ability to track and identify suspicious messages is insufficient

Engineering Contradiction:
Improvefiltering system complexityVSAvoidtracking capability
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The system introduces an intermediary element - unprintable tracking characters - that are inserted into messages. These characters serve as a mediator between the sending system and the receiving system, enabling tracking capability without requiring complex filtering infrastructure. The tracking characters are invisible to users but detectable by the system, providing enhanced tracking while maintaining simple filter architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If message character limits are enforced, then communication efficiency is maintained, but the ability to include tracking information is limited

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidtracking information capacity
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The system applies parameter changes by utilizing unprintable characters that occupy character space without consuming visible message content. These characters change the structural parameter of the message (adding tracking data) while maintaining the visual and functional parameters within character limits. This allows tracking information to be embedded without reducing communication efficiency or exceeding message length constraints.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3993360B1Detecting and protecting against cybersecurity attacks using unprintable tracking characters
Publication Date: 2025.05.14 PROOFPOINT INC
  • EP3993360B1 patent drawingFigure 1
  • EP3993360B1 patent drawingFigure 2A~2B
  • EP3993360B1 patent drawingFigure 3A

AI summary

Aspects of the disclosure relate to detecting and protecting against cybersecurity attacks using unprintable tracking characters. A computing platform may receive (605) a character-limited message sent to a user device. Subsequently, the computing platform may detect (610) that the character-limited message sent to the user device includes suspicious content. Then, the computing platform may generate (615) a modified character-limited message by inserting one or more special characters into the character-limited message and cause (620) transmission of the modified character-limited message to the user device. Next, the computing platform may receive (625), from the user device, a spam report that includes the modified character-limited message. Then, the computing platform may identify (630) a presence of the one or more special characters included in the modified character-limited message and adjust (635) one or more filters based on the identification.