白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Message platform for automated threat simulation, reporting, detection, and remediation

專利號
US11997115B1
公開日期
2024-05-28
申請人
Cofense Inc.(US VA Leesburg)
發(fā)明人
Aaron Higbee; David Chamberlain; Vineetha Philip
IPC分類
H04L9/40; G06F16/35; G06F21/00; G06F21/55; H04L51/212; H04L51/08
技術(shù)領域
message,phishing,email,messages,be,or,emails,in,user,cluster
地域: VA VA Leesburg

摘要

Methods, network devices, and machine-readable media for an integrated environment and platform for automated processing of reports of suspicious messages, and further including automated threat simulation, reporting, detection, and remediation, including rapid quarantine and restore functions.

說明書

Header Keys

Related phishing emails will contain similar Header Keys when delivered to targets within an organization, as they will have traversed similar mail infrastructure and deliver paths. Even if Received Path or other Headers have been forged, legitimate mail infrastructure will add valid headers to the email. This can be used to compute a phishing similarity indicator.

To create a lowercased raw key value the Header Keys are sorted and appended into a single string and an SSDeep hash is computed for the header key block. This hash is then used to compute a similarity score with other emails.

Sender

Related phishing emails can contain a similar Sender by either using the same domain to send emails or generating similar sender email addresses. This can be used to calculate a domain and/or Sender phishing similarity indicator.

Two lowercased indicator values are created for the Sender; one for the sender domain and one for the overall sender email address.

Domain similarity is calculated by doing a bigram comparison of the sender domain with the TLD removed.

Sender similarity is calculated by doing a bigram comparison of both senders.

Delivery Time

Phishing emails delivered to a target organization within close proximity can be used as a phishing similarity indicator. The time drift in hours is calculated between emails and used to calculate a similarity score.

The following values can be used in testing based on the number of hours drift between delivery times.

權(quán)利要求

1
微信群二維碼
意見反饋

    <p id="ep9rg"><li id="ep9rg"></li></p>
    <sup id="ep9rg"><input id="ep9rg"></input></sup>

    <abbr id="ep9rg"></abbr>
    <blockquote id="ep9rg"><p id="ep9rg"></p></blockquote><style id="ep9rg"><rp id="ep9rg"></rp></style>