IP Library › Granted Patent US 12,549,570
Granted Patent B2
US 12,549,570 · App. 18/571,702 · Granted Feb 10, 2026

Email security system for blocking and responding to targeted email attacks, and operation method thereof

Inventor: Chung Han Kim (Seoul, KR)
Assignee: KIWONTECH CO., LTD.
H04L63/1416H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,570
App. No.
18/571,702
Granted
Feb 10, 2026
Kind
B2
Abstract

An operation method of an email security system comprises the steps of: configuring security threat information synchronization data by synchronizing targeted email security threat information configured by performing a targeted email security threat inspection on an inbound mail with targeted email security threat information configured by performing a targeted email security threat inspection on an outbound mail; performing a targeted email security threat inspection corresponding to a new inbound mail or a new outbound mail using the security threat information synchronization data; and performing a targeted email security threat response process according to the targeted email security threat inspection of the new inbound mail or the new outbound mail.

Claims (16)

1 . An operation method of an email security system, the method comprising:

configuring security threat information synchronization data by synchronizing first targeted email security threat information configured by performing a first targeted email security threat inspection on an inbound email with targeted email security threat information configured by performing a second targeted email security threat inspection on an outbound email, wherein the first targeted email security threat information and the second targeted security threat information are based on prior inspection results of one or more emails received at a user terminal via a service providing device;

performing a targeted email security threat inspection, at the service providing device, corresponding to a new inbound email received at the user terminal or a new outbound email transmitted from the user terminal using the security threat information synchronization data; and

performing a targeted email security threat response process according to the targeted email security threat inspection of the new inbound email or the new outbound email, wherein

the targeted email security threat inspection corresponding to the new inbound mail or the new outbound mail includes at least one among a spam attack threat inspection targeting a specific email account using the security threat information synchronization data, a malware email attack threat inspection on unidentified or uniform resource locator (URL) malware, a social engineering email attack threat inspection including inspection of header or look-alike domains, and an email information leakage threat inspection, and

wherein performing the targeted email security threat inspection corresponding to the new inbound email or the new outbound email includes:

performing the security threat inspection on a link included in the new outbound email associated with a large file to be attached to be converted into a general attached file and attached to the new outbound email according to a mail policy using the security threat information synchronization data in performing the targeted email security threat inspection corresponding to the new outbound email, wherein the large attached file is a first file having a first size greater than a predetermined size and the general attached file is a second file having a second size less than or equal to the predetermined size, and wherein the large file is converted into the general attached file based on whether the new outbound email is approved according to the mail policy, and

wherein when a receiver of the outbound email is classified as a fraudulent similar mail address, performing a targeted email security threat response process comprising automatically blocking transmission of the new outbound email or warning a sender.

2 . The method according to claim 1 , further comprising updating the security threat information synchronization data according to a result of the targeted email security threat inspection of the new inbound email or the new outbound email.

3 . The method according to claim 1 , wherein the security threat information synchronization data includes URL final destination tracking inspection information for inspecting a malware email attack threat.

4 . The method according to claim 1 , wherein the security threat information synchronization data includes at least one among header forgery and alteration inspection information, look-alike domain inspection information, and account takeover inspection information for inspecting a social engineering attack threat.

5 . The method according to claim 1 , wherein the security threat information synchronization data includes at least one among intentional information leakage inspection information and unintentional information leakage inspection information for inspecting an email information leakage.

6 . The method according to claim 5 , wherein performing the targeted email security threat inspection corresponding to the new inbound email or the new outbound email includes:

determining whether the receiver of the new outbound email is classified as a fraudulent similar mail address using the security threat information synchronization data in performing the targeted email security threat inspection corresponding to the new outbound email.

7 . The method according to claim 1 , wherein the performing the targeted email security threat response process further includes:

approving conversion of the large attached file to be converted to the general attached file according to the security threat inspection of the link.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2023
From: KIM, CHUNG HAN
To: KIWONTECH CO., LTD.
Reel/Frame 065903/0075 →
Priority Claims (4)
KR 10-2022-0097174 · Aug 4, 2022 · national
KR 10-2022-0151267 · Nov 14, 2022 · national
KR 10-2022-0151268 · Nov 14, 2022 · national
KR 10-2022-0166583 · Dec 2, 2022 · national
Continuity (1)
Related Publication 20250088518A1 · Mar 13, 2025
References Cited (17)
US 11392691B1 · Wright · 2022 [cited by applicant]
US 20020199095A1 · Bandini · 2002 [cited by examiner]
US 20100161748A1 · Kojima et al. · 2010 [cited by applicant]
US 20120060221A1 · Gerber · 2012 [cited by examiner]
US 20170078321A1 · Maylor · 2017 [cited by examiner]
US 20200204572A1 · Jeyakumar et al. · 2020 [cited by applicant]
US 20210014198A1 · Amoudi · 2021 [cited by examiner]
US 20210126944A1 · Lesperance · 2021 [cited by examiner]
KR 101117866B1 · 2012 [cited by applicant]
KR 101533506B1 · 2015 [cited by applicant]
KR 101600864B1 · 2016 [cited by applicant]
KR 102247617B1 · 2021 [cited by applicant]
KR 1020220089459A · 2022 [cited by applicant]
KR 1020220098316A · 2022 [cited by applicant]
International Search Report & Written Opinion for PCT/KR2022/019497 by Korean Intellectual Property Office dated Apr. 24, 2023. [cited by applicant]
Office Action for KR 10-2022-0151268 by Korean Intellectual Property Office dated Dec. 14, 2023. [cited by applicant]
Office Action for JP 2023-578183 by Japan Patent Office dated Sep. 17, 2024. [cited by applicant]