Zero-Day URL Protection via Secure Conversion and Periodic Diagnosis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current email security systems are limited in their ability to detect and block zero-day URL attacks, particularly those without reputation information, as they cannot effectively inspect URLs within email message bodies or attached files, and lack protection against malicious URLs embedded in the message body.

Innovation Solution

A device and method that collect and inspect email information, convert potentially malicious zero-day URLs into secure URLs, and periodically diagnose whether these URLs are malicious, ensuring safe connection only when the URL is determined to be secure through a security inspection process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current email security systems inspect URLs using reputation information, then known malicious URLs can be blocked, but zero-day URLs without reputation information cannot be detected

Engineering Contradiction:
ImproveURL security inspection capabilityVSAvoidDetection capability for unknown/zero-day URLs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary inspection of URLs before they are accessed, extracting URLs from email message bodies and attached files, and routing them through a security inspection process. This preliminary action allows the system to identify zero-day URLs before they can cause harm, even without prior reputation information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security inspection process that sits between the email system and URL access. This intermediary component extracts, inspects, and validates URLs before allowing access, enabling detection of zero-day URLs through the inspection process rather than relying solely on reputation databases.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system inspects all URLs in email message bodies and attached files, then security coverage is improved, but processing complexity increases

Engineering Contradiction:
ImproveSecurity coverageVSAvoidURL inspection process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the URL inspection process into distinct components: URL extraction from message bodies and attached files, security inspection through intermediate processes, and access control decisions. This segmentation allows complex security coverage to be achieved through modular processing stages rather than a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240015182A1Device for providing protective service against email security-based zero-day URL attack and method for operating same
Publication Date: 2024.01.11 KIWONTECH
  • US20240015182A1 patent drawing
  • US20240015182A1 patent drawing
  • US20240015182A1 patent drawing

AI summary

A method for operating a device for providing a protective service against a mail security-based zero-day uniform resource locator (URL) attack, according to an embodiment of the present invention, comprises: a collection step of collecting email information transmitted and received between one or more user terminals; a security threat inspection step of, when a URL is included in the email information, inspecting the URL by means of a email security process according to a preset security threat architecture and storing and managing URL inspection information according to the inspection result; a zero-day URL conversion step of, when the URL is determined as a zero-day URL having a potential zero-day attack risk, converting the zero-day URL into a preset secure URL on the basis of the URL inspection information; and a zero-day URL diagnosis step of periodically diagnosing whether the zero-day URL is a malicious URL.