EP4490633A4 - System zur erkennung bösartiger e-mails und e-mailkampagnen - Google Patents

System zur erkennung bösartiger e-mails und e-mailkampagnen

Info

Publication number
EP4490633A4
EP4490633A4 EP23767336.3A EP23767336A EP4490633A4 EP 4490633 A4 EP4490633 A4 EP 4490633A4 EP 23767336 A EP23767336 A EP 23767336A EP 4490633 A4 EP4490633 A4 EP 4490633A4
Authority
EP
European Patent Office
Prior art keywords
email
detection system
malicious
campaign detection
campaign
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP23767336.3A
Other languages
English (en)
French (fr)
Other versions
EP4490633A1 (de
Inventor
Steven Haworth
Antony Lawson
Stephen Pickman
Matt Dunn
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Darktrace Holdings Ltd
Original Assignee
Darktrace Holdings Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Darktrace Holdings Ltd filed Critical Darktrace Holdings Ltd
Publication of EP4490633A1 publication Critical patent/EP4490633A1/de
Publication of EP4490633A4 publication Critical patent/EP4490633A4/de
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/554Detecting local intrusion or implementing counter-measures involving event detection and direct action
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06NCOMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
    • G06N20/00Machine learning
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06NCOMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
    • G06N3/00Computing arrangements based on biological models
    • G06N3/02Neural networks
    • G06N3/08Learning methods
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1483Countermeasures against malicious traffic service impersonation, e.g. phishing, pharming or web spoofing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1466Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Computer Hardware Design (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Signal Processing (AREA)
  • Artificial Intelligence (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Health & Medical Sciences (AREA)
  • Mathematical Physics (AREA)
  • Data Mining & Analysis (AREA)
  • Evolutionary Computation (AREA)
  • General Health & Medical Sciences (AREA)
  • Life Sciences & Earth Sciences (AREA)
  • Molecular Biology (AREA)
  • Computational Linguistics (AREA)
  • Biophysics (AREA)
  • Biomedical Technology (AREA)
  • Virology (AREA)
  • Computer Vision & Pattern Recognition (AREA)
  • Medical Informatics (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Information Transfer Between Computers (AREA)
EP23767336.3A 2022-03-07 2023-03-03 System zur erkennung bösartiger e-mails und e-mailkampagnen Pending EP4490633A4 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US202263317157P 2022-03-07 2022-03-07
PCT/US2023/014539 WO2023172462A1 (en) 2022-03-07 2023-03-03 A system to detect malicious emails and email campaigns

Publications (2)

Publication Number Publication Date
EP4490633A1 EP4490633A1 (de) 2025-01-15
EP4490633A4 true EP4490633A4 (de) 2025-08-20

Family

ID=87935811

Family Applications (1)

Application Number Title Priority Date Filing Date
EP23767336.3A Pending EP4490633A4 (de) 2022-03-07 2023-03-03 System zur erkennung bösartiger e-mails und e-mailkampagnen

Country Status (3)

Country Link
EP (1) EP4490633A4 (de)
AU (1) AU2023232004A1 (de)
WO (1) WO2023172462A1 (de)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN117633659B (zh) * 2024-01-25 2024-04-26 成都工业职业技术学院 一种基于计算机的邮件分类方法及装置
CN119766494B (zh) * 2024-12-03 2025-10-31 天翼云科技有限公司 目标邮件检测方法、装置、计算机设备和存储介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20190306192A1 (en) * 2018-03-28 2019-10-03 Fortinet, Inc. Detecting email sender impersonation
US20210136089A1 (en) * 2019-11-03 2021-05-06 Microsoft Technology Licensing, Llc Campaign intelligence and visualization for combating cyberattacks
US20210168161A1 (en) * 2018-02-20 2021-06-03 Darktrace Limited Cyber threat defense system protecting email networks with machine learning models using a range of metadata from observed email communications

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2547202B (en) 2016-02-09 2022-04-20 Darktrace Ltd An anomaly alert system for cyber threat detection
US11962552B2 (en) * 2018-02-20 2024-04-16 Darktrace Holdings Limited Endpoint agent extension of a machine learning cyber defense system for email
US10986121B2 (en) 2019-01-24 2021-04-20 Darktrace Limited Multivariate network structure anomaly detector
US12069073B2 (en) 2020-02-28 2024-08-20 Darktrace Holdings Limited Cyber threat defense system and method

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20210168161A1 (en) * 2018-02-20 2021-06-03 Darktrace Limited Cyber threat defense system protecting email networks with machine learning models using a range of metadata from observed email communications
US20190306192A1 (en) * 2018-03-28 2019-10-03 Fortinet, Inc. Detecting email sender impersonation
US20210136089A1 (en) * 2019-11-03 2021-05-06 Microsoft Technology Licensing, Llc Campaign intelligence and visualization for combating cyberattacks

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
MARKUS BREUNIG ET AL: "LOF: Identifying Density-Based Local Outliers", SIGMOD '00 PROCEEDINGS OF THE 2000 ACM SIGMOD INTERNATIONAL CONFERENCE ON MANAGEMENT OF DATA, 16 May 2000 (2000-05-16), NEW YORK, NY, US, pages 93 - 104, XP055226141, ISBN: 978-1-58113-217-5, DOI: 10.1145/342009.335388 *
See also references of WO2023172462A1 *

Also Published As

Publication number Publication date
WO2023172462A1 (en) 2023-09-14
EP4490633A1 (de) 2025-01-15
AU2023232004A1 (en) 2024-09-05

Similar Documents

Publication Publication Date Title
EP3718015A4 (de) Kommunikationsverarbeitung für nachrichtenübermittlungsplattform unter verwendung von nachrichtenclusterdetektion und -kategorisierung
EP3973398A4 (de) Systeme und verfahren zur erkennung und verminderung von cybersicherheitsbedrohungen
DE112020001597A5 (de) Automatische Erkennung und Klassifizierung von Adversarial Attacks
EP4375698A4 (de) Signalverarbeitungsverfahren und detektionsverfahren für lidar und lidar
EP4057238C0 (de) Informationsverarbeitungssystem und informationsverarbeitungsverfahren
EP4285258A4 (de) Automatisierte extraktion und klassifizierung bösartiger indikatoren
EP4369058A4 (de) Inspektionssystem und -verfahren
EP3960688A4 (de) Kraninspektionssystem und kran
EP4261804A4 (de) Informationsverarbeitungsverfahren und informationsverarbeitungssystem
EP3953884A4 (de) Registrierte verschlüsselte elektronische nachricht und redaktiertes antwortsystem
EP3964723A4 (de) Parallellager und rotorsystem
EP4162377A4 (de) Betrugserkennungssystem und -verfahren
EP4218167A4 (de) Eindringungsüberwachungssystem, verfahren und zugehörige produkte
EP4369053A4 (de) Inspektionssystem und -verfahren
EP4258852A4 (de) Pflanzendetektions- und -anzeigesystem
EP4368977A4 (de) Inspektionssystem und -verfahren
EP3835171A4 (de) Informationsverarbeitungssystem und informationsverarbeitungsverfahren
EP4368957A4 (de) Inspektionssystem und inspektionsverfahren
EP3929460C0 (de) Anomaliedetektionssystem und anomaliedetektionsverfahren
EP4345509A4 (de) Inspektionssystem und -verfahren
EP3937094A4 (de) Informationsverarbeitungsverfahren und informationsverarbeitungssystem
EP4317404A4 (de) Inspektionssystem und inspektionsverfahren
EP4338377A4 (de) Erkennung und abschwächung von bluetooth-basierten angriffen
EP4307311A4 (de) Informationsverarbeitungssystem und informationsverarbeitungsverfahren
EP4224452A4 (de) Informationsverarbeitungssystem und informationsverarbeitungsverfahren

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20240821

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR

DAV Request for validation of the european patent (deleted)
DAX Request for extension of the european patent (deleted)
REG Reference to a national code

Ref country code: DE

Ref legal event code: R079

Free format text: PREVIOUS MAIN CLASS: G06F0021500000

Ipc: H04L0009400000

A4 Supplementary search report drawn up and despatched

Effective date: 20250722

RIC1 Information provided on ipc code assigned before grant

Ipc: H04L 9/40 20220101AFI20250716BHEP

Ipc: G06N 20/00 20190101ALI20250716BHEP

Ipc: G06F 21/55 20130101ALI20250716BHEP

Ipc: G06F 21/56 20130101ALI20250716BHEP

Ipc: G06N 3/08 20230101ALN20250716BHEP