Analyses and aggregation of domain behavior for email threat detection by a cyber security system
Abstract
A cyber security appliance to protect a domain associated with an organization or user and global domain intelligence data store for centralized storage of analytic results is described. The cyber security appliance features a communication module including one or more input/output (I/O) ports, an email module, and an autonomous response module. The email module comprises email report analytic logic to analyze content within an email authentication report, received via the one or more I/O ports, to detect an email suspected of being malicious when the email is directed to a computing device operating outside of the domain and a source address of the email falsely identifying the domain as part of the source email address. The autonomous response module is configured to cause a first set of autonomous actions to mitigate similar email dissemination over a network.
Claims
exact text as granted — not AI-modified1 . A cyber security appliance to protect a domain associated with an organization or user, comprising:
a communication module including one or more input/output (I/O) ports; an email module communicatively coupled to the communication module, the email module comprises email report analysis logic to analyze content within an email authentication report received via the one or more I/O ports to detect an email suspected of being malicious when the email is directed to a computing device operating outside of the domain and a source email address of the email falsely identifying the domain as part of the source email address; and an autonomous response module communicatively coupled to the email module, the autonomous response module is configured to cause a first set of autonomous actions to mitigate similar email dissemination over a network.
2 . The cyber security appliance of claim 1 , wherein the email module further comprises email authentication set-up logic configured to notify and assist domain administrators in response to the email report analysis logic identifying potential Domain Name System (DNS) sever misconfiguration based on the content of the email authentication report.
3 . The cyber security appliance of claim 2 , wherein the email authentication report corresponds to a Domain-based Message Authentication, Reporting and Conformance (DMARC) aggregate report includes content associated with emails that utilize the domain as part of its source address.
4 . The cyber security appliance of claim 3 , wherein the DMARC aggregate report includes content that identifies an email failing at least one of a plurality of authentications to categorize the email as malicious, the plurality of authentications include a Sender Policy Framework (SPF) authentication that confirms that the email is being sent from a mail server authorized to send emails on behalf of the domain and a DomainKeys Identified Mail (DKIM) authentication that confirms that the content of the email has not been modified during transit.
5 . The cyber security appliance of claim 4 , wherein the plurality of authentications include DMARC authentication that detects whether a misalignment between an actual email address of an email sender and the source email address included within a From header field of the email identifying the domain as part of the source email address.
6 . The cyber security appliance of claim 4 , wherein the autonomous response module configured to provide data to be rendered on a display to assist a domain administrator in configuring a DMARC record that adjusts the DMARC authentication or a SPF record that adjusts the SPF authentication.
7 . The cyber security appliance of claim 1 further comprising:
an inoculation module communicatively coupled to the email module, the inoculation module is configured to cause a second set of autonomous actions, wherein the second set of autonomous actions include one or more defensive actions including issuance of an alert or one or more offensive actions including issuance of a Denial of Service (DoS) attack on a malicious server from which the email originated.
8 . The cyber security appliance of claim 1 communicatively coupled to a global domain intelligence data store to provide results of the analysis of the content within the email authentication report along with the content of the email authentication report to assist in reconfiguration of a plurality of email authentications conducted during transmission of the email and global tracking of behavior of a source of the suspected malicious email.
9 . Implemented within a cyber security appliance, a non-transitory storage medium configured to store instructions in a format that, when executed, identifies malicious spoofing and phishing emails to protect a domain associated with an organization or user, the non-transitory storage medium comprising:
an email module including email report analysis logic to analyze content within an email authentication report received from an Internet Service Provider (ISP) to detect an email suspected of being malicious upon failure of an authentication process that detects when the email is directed to a computing device operating outside of the domain and a source address of the email falsely identifies the domain as part of the source email address; and an autonomous response module communicatively coupled to the email module, the autonomous response module is configured to cause a first set of autonomous actions to mitigate similar email dissemination over a network.
10 . The non-transitory storage medium of claim 9 , wherein the email module further comprises email authentication set-up logic configured to notify and assist domain administrators in response to the email report analysis logic identifying potential Domain Name System (DNS) sever misconfiguration based on the content of the email authentication report.
11 . The non-transitory storage medium of claim 10 , wherein the email authentication report corresponds to a Domain-based Message Authentication, Reporting and Conformance (DMARC) aggregate report includes content associated with emails that utilize the domain as part of its source address.
12 . The non-transitory storage medium of claim 11 , wherein the DMARC aggregate report includes content that identifies an email failing at least one of a plurality of authentications to categorize the email as malicious, the plurality of authentications include a Sender Policy Framework (SPF) authentication that confirms that the email is being sent from a mail server authorized to send emails on behalf of the domain and a DomainKeys Identified Mail (DKIM) authentication that confirms that the content of the email has not been modified during transit.
13 . The non-transitory storage medium of claim 12 , wherein the plurality of authentications include DMARC authentication that detects whether a misalignment between an actual email address of an email sender and the source email address included within a From header field of the email identifying the domain as part of the source email address.
14 . The non-transitory storage medium of claim 12 , wherein the autonomous response module configured to provide data to be rendered on a display to assist a domain administrator in configuring a DMARC record that adjusts the DMARC authentication or a SPF record that adjusts the SPF authentication.
15 . The non-transitory storage medium of claim 9 further comprising:
an inoculation module communicatively coupled to the email module, the inoculation module is configured to cause a second set of autonomous actions, wherein the second set of autonomous actions include one or more defensive actions including issuance of an alert or one or more offensive actions including issuance of a Denial of Service (DoS) attack on a malicious server from which the email originated.
16 . A method for a cyber security appliance to protect a domain associated with an organization or user, comprising:
analyzing content within an email authentication report received from a resource external to the domain to determine whether an email, observed as using the domain as part of its source email address, has failed at least one of a plurality of email authentication processes, wherein the plurality of email authentication processes include (i) a first authentication process configured to confirm that the email is being sent from a mail server authorized to send emails on behalf of the domain, (ii) a second authentication process configured to confirm that the content of the email has not been modified during transit, and (iii) a third authentication process configured to detect misalignment between an actual email address of an email sender and the source email address included within a From header field of the email identifying the domain as part of the source email address; determining whether the email corresponds to a suspected malicious email upon the email failing at least one of the plurality of email authentication processes; and performing a first set of autonomous actions to mitigate continued dissemination of emails over a network by a malicious actor originating the suspected malicious email.
17 . The method of claim 16 , wherein the first set of autonomous actions include (i) one or more defensive actions including issuance of an alert across to multiple cyber security appliances across multiple domains including the domain or (ii) one or more offensive actions including issuance of a Denial of Service (DoS) attack on a malicious server from which the suspected malicious email originated.
18 . The method of claim 16 , wherein the first email authentication process corresponds to a Sender Policy Framework (SPF) authentication that confirms that the email is being sent from a mail server authorized to send emails on behalf of the domain, the second email authentication process corresponds to a DomainKeys Identified Mail (DKIM) authentication that confirms that the content of the email have not been modified during transit, and the third email authentication process corresponds to a DMARC authentication that detects whether a misalignment between an actual email address of an email sender and the source email address included within a From header field of the email identifying the domain as part of the source email address.
19 . The method of claim 16 further comprising:
provide results of an analysis of the content within the email authentication report along with the content of the email authentication report to a global domain intelligence data store to (i) provide real-time access of the results and the content to an administrator to assist in reconfiguration of one or more of the plurality of email authentication processes and (ii) enable global tracking of behavior of the email sender of the suspected malicious email.Join the waitlist — get patent alerts
Track US2023403296A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.