ACCELERATED DETECTION OF SPEAR PHISHING DURING EMAIL MALWARE DETECTION ON ENTERPRISE NETWORKS
개요
발명자
Haitao Li; Lisheng Ryan Sun
IPC 분류
CPC 분류
Emails suspected to include a spear phishing attack are identified from the stream of incoming emails using a Related Anomaly Score (RAS). The RAS is calculated by identifying feature vectors from the stream of incoming emails associated with a sender of the email and a link of the email. The suspicious spear phishing emails are mapped by feature vectors and prioritizing according to map position. For reliability, in one case, relative distances are calculated between suspicious emails, and if a relative distance between the specific email and prioritized suspicious emails exceeds a predetermined distance threshold, take a security action based on spear phishing rules on the filtered highest suspicious emails, and if the relative distance does not exceed the predetermined distance threshold, take a second security action including forwarding the specific email for standard phishing analysis.
원문 (중국어)
Emails suspected to include a spear phishing attack are identified from the stream of incoming emails using a Related Anomaly Score (RAS). The RAS is calculated by identifying feature vectors from the stream of incoming emails associated with a sender of the email and a link of the email. The suspicious spear phishing emails are mapped by feature vectors and prioritizing according to map position. For reliability, in one case, relative distances are calculated between suspicious emails, and if a relative distance between the specific email and prioritized suspicious emails exceeds a predetermined distance threshold, take a security action based on spear phishing rules on the filtered highest suspicious emails, and if the relative distance does not exceed the predetermined distance threshold, take a second security action including forwarding the specific email for standard phishing analysis.