Mailprotector

Autonomous Breach Detection and Response System | Mailprotector Patents

Mailprotector's Autonomous Breach Detection and Response System uses strategically placed honeypot email addresses as digital canaries to monitor outbound email traffic for signs of compromise, triggering automated remedial actions such as blocking messages, locking accounts, or running security scans to detect and respond to breaches before damage occurs, with support for complex distributed email infrastructures.

Skip to main content

  1. 1.Technology
  2. 2./
  3. 3.Autonomous Breach Detection and Response System

Email Alias Management and Security PlatformAdvanced Email Behavior Analytics Platform

Prev

Patent 08 Pending

Autonomous Breach Detection and Response System

Deploys honeypot email addresses as digital canaries that detect breaches before they cause damage.

Shield

How It Works

The system creates bait email addresses, publishes them in strategic locations, and then monitors outbound email traffic from the organization’s message servers. If a message server attempts to send an outbound email to one of these bait addresses, it means the server—or an account on it—has been compromised. An attacker who harvested the bait address is now trying to use it, revealing the breach.

When a bait address is detected in outbound traffic, the system takes remedial action from a set of responses: block the message, lock the account, run a security scan, authenticate the sender, validate the message, or generate a warning—in any combination. The system also tracks the number of attempts and total email volume to trigger escalating responses.

The architecture supports multiple gateway systems across the sender and recipient infrastructure, enabling detection across complex, distributed email environments.

What Makes It Different

  • Outbound monitoring: watches messages leaving the organization rather than incoming traffic, catching compromised accounts and servers from the inside.
  • Bait-and-detect methodology: publishes bait addresses where only an attacker would find them, creating tripwires that reveal unauthorized access.
  • Autonomous remediation: takes immediate action (block, lock, scan, authenticate, validate, warn) without waiting for human intervention.
  • Threshold-based escalation: tracks attempt counts and email volume to escalate responses as the threat intensifies.

Why It Matters

The average data breach takes months to detect through traditional monitoring. This technology can detect compromised accounts almost immediately—by watching for outbound messages to addresses that should never appear in legitimate traffic. When a bait address shows up in outgoing mail, the system knows the sending account or server has been breached and acts instantly.

Patent Details

Official TitleComputerized System for Autonomous Detection of Unauthorized Access According to Outbound Addresses

Application Number US 18/230,647

Date FiledAugust 6, 2023

Publication DateFebruary 15, 2024

Status Pending

CategoryThreat Detection & Analysis

Next

See the innovation in action.

Our patents aren't just legal documents—they're the technology powering the products MSPs trust every day to protect their clients.

Schedule a demo Contact sales