Mandiant, Inc.
System and method for detecting repetitive cybersecurity attacks constituting an email campaign

Last updated:

Abstract:

According to one embodiment, a system for detecting an email campaign includes feature extraction logic, pre-processing logic, campaign analysis logic and a reporting engine. The feature extraction logic obtains features from each of a plurality of malicious email messages received for analysis while the pre-processing logic generates a plurality of email representations that are arranged in an ordered sequence and correspond to the plurality of malicious email message. The campaign analysis logic determines the presence of an email campaign in response to a prescribed number of successive email representations being correlated to each other, where the results of the email campaign detection are provided to a security administrator via the reporting engine.

Status:
Grant
Type:

Utility

Filling date:

27 Jun 2018

Issue date:

27 Jul 2021