DETECTION ARCHITECTURE & METHODOLOGY
PIPELINE LATENCY SLA: <140MSHow ScamShield works
A multi-layered threat evaluation pipeline designed to explain phishing verdicts with clear evidence, not opaque black-box scores.
Visual Threat Analysis Pipeline
STAGE 1 / 7 Ingested URL / Message Preprocessing
Algorithms & Parsers
RFC 3986 Lexer, MIME stream reader, Base64 & Unicode sanitizer
Target Threat Signals
Zero width characters, hidden protocol schemes, nested URI encodings, payload size anomalies
Security Guarantee
Strict static parse tree only. Zero headless browser instantiation; payloads never touch V8 runtime.
{"raw_scheme":"https", "tokens_extracted":8, "obfuscation_flag":false, "bytes":64}Layered Detection Philosophy
Single-source defenses routinely fail against zero-day phishing kits and deceptive lookalike domains. Modern adversaries routinely spin up throwaway subdomains, cycle through dynamic DNS providers within hours, and bypass basic blocklists.
Static Blocklists
Blind to attacks created less than 4 hours ago. Cannot defend against instant homoglyphs or fast-flux networks.
ScamShield Synthesis
Cross-validates 24 structural indicators, MX/SPF posture, WHOIS age delta, and semantic brand mimicry.
Why Explanations Matter
Security analysts and employees cannot act effectively on a naked confidence percentage (i.e. Score: 0.87). Unexplained scores generate alert fatigue and distrust. ScamShield decomposes risk into plain language forensic narratives.
- Lookalike domain target: Mimics trusted banking brand using Cyrillic homoglyph (a vs а).
- Suspicious redirect chain: 3 chained hops through newly registered ephemeral dynamic DNS gateways.
- Domain Age: Registered 18 minutes prior to inspection via anonymous registrar.