Not every scam email contains a malicious attachment or dodgy link. Especially when it comes to business email compromise (BEC) or CxO fraud, attackers prefer to rely on language to persuade and coerce their victims. They may request a bank transfer, provide new banking details, or seek to pressure recipients into bypassing established approval processes. With Retarus Deep Content Analysis, we have now extended our BEC and CxO fraud detection efforts to include precisely those emails containing minimal or no payloads.
Using content and context to detect fraud attempts
The challenge was always that messages like these are usually inconspicuous from a technical perspective. The threat is primarily posed by their content or even simply due to their context. Attackers send messages impersonating executives, business partners, or other trusted individuals. They then put recipients under time pressure, demand secrecy, or instruct victims to log back into an account using their credentials. And while the modus operandi is now widely known, this by no means eliminates the danger.
That’s why Deep Content Analysis doesn’t only evaluate individual technical characteristics. Instead, it employs rule-based, weighted analysis to combine information regarding the recipient’s context, the subject line, and the content of the message with security and authentication signals. More specifically, this may include indicators such as references to login and payment data, or wording that demands urgency or secrecy. Factors such as SPF, DKIM, and DMARC statuses, the use of Unicode and homoglyph characters, in addition to the sender’s reputation, can also play important roles in the evaluation.
Intelligently combining multiple indicators
Combining a range of indicators is crucial in determining whether a message is fraudulent. Not every message requesting you to log in is necessarily a scam. However, when a request to log in is compounded by a request for bank details and a sense of urgency, the resulting overall impression is far more telling than any of the indicators on its own.
The assessment is transparent throughout. Each of the rules and signals applied can be matched to specific triggers and found in the Threat Details. This allows security teams to better understand exactly why a message has been flagged.
Data protection and configuration
Depending on your needs and specific risk profile, the feature can be customized at the customer, domain, or user levels. Notwithstanding the depth of the analysis, data protection of course remains a top priority at Retarus. The safeguarding of data remained a core principle throughout the design and development of Deep Content Analysis. Should you wish to benefit from these new features in your Email Security solution, please feel free to contact your Retarus representative.

Submit a comment