IP Library Granted Patent US 12664269
Granted Patent B2
US 12664269 · App. 18/610,402 · Granted Jun 23, 2026

Detecting and protecting against cybersecurity attacks using unprintable tracking characters

Inventor: Thomas Lee (Kensington, CA)
Assignee: Proofpoint, Inc.
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12664269
App. No.
18/610,402
Granted
Jun 23, 2026
Kind
B2
Abstract

Aspects of the disclosure relate to detecting and protecting against cybersecurity attacks using unprintable tracking characters. A computing platform may receive a character-limited message sent to a user device. Subsequently, the computing platform may detect that the character-limited message sent to the user device includes suspicious content. Then, the computing platform may generate a modified character-limited message by inserting one or more special characters into the character-limited message and cause transmission of the modified character-limited message to the user device. Next, the computing platform may receive, from the user device, a spam report that includes the modified character-limited message. Then, the computing platform may identify a presence of the one or more special characters included in the modified character-limited message and adjust one or more filters based on the identification.

Claims (62)

1 . A computing platform, comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive, via the communication interface, a character-limited message sent to a user device;

scan the character-limited message to evaluate the character-limited message for suspicious content;

detect, based on the scan, that the character-limited message sent to the user device comprises suspicious content;

responsive to detecting that the character-limited message sent to the user device comprises the suspicious content, generate a modified character-limited message by selecting and inserting one or more unprintable characters into the character-limited message, wherein:

selecting and inserting the one or more unprintable characters into the character-limited message includes detecting a length of the character-limited message and inserting the one or more unprintable characters based on a number of available unused characters in the character-limited message,

the one or more unprintable characters are configured to track the character-limited message comprising the suspicious content and identify a confidence level, indicative of a confidence that the suspicious content is suspicious, and

the one or more unprintable characters include different unprintable characters indicating different confidence levels; and

cause transmission of the modified character-limited message to the user device.

2 . The computing platform of claim 1 , wherein the one or more unprintable characters indicate a type of messaging associated with the character-limited message sent to the user device.

3 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

prior to detecting that the character-limited message sent to the user device comprises the suspicious content, classify the character-limited message based on message type.

4 . The computing platform of claim 1 , wherein generating the modified character-limited message by inserting the one or more unprintable characters into the character-limited message further comprises:

prioritizing the one or more unprintable characters for insertion based on one or more criteria; and

inserting the one or more unprintable characters based on the prioritization.

5 . The computing platform of claim 1 , wherein the character-limited message comprises at least one of a short message service (SMS) message or a multimedia messaging service (MMS) message.

6 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

detect a presence of the one or more unprintable characters included in the modified character-limited message; and

adjust one or more filters based on detecting the presence of the one or more unprintable characters included in the modified character-limited message.

7 . The computing platform of claim 6 , wherein adjusting the one or more filters comprises modifying one or more filter criteria based on an aggregate of character-limited messages identified as comprising actually suspicious content.

8 . The computing platform of claim 6 , wherein adjusting the one or more filters comprises allowing more character-limited messages to pass through to the user device.

9 . The computing platform of claim 6 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive, via the communication interface, an additional character-limited message sent to the user device;

based on the adjusted one or more filters, detect that the additional character-limited message sent to the user device comprises the suspicious content; and

based on detecting that the additional character-limited message sent to the user device comprises the suspicious content, execute one or more security actions.

10 . The computing platform of claim 9 , wherein executing the one or more security actions comprises blocking the additional character-limited message or inserting a warning message into the additional character-limited message.

11 . A method, comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

receiving, by the at least one processor, a character-limited message sent to a user device;

scanning, by the at least one processor, the character-limited message to evaluate the character-limited message for suspicious content;

detecting, by the at least one processor and based on the scanning, that the character-limited message sent to the user device comprises suspicious content;

responsive to detecting that the character-limited message sent to the user device comprises the suspicious content, generating, by the at least one processor, a modified character-limited message by selecting and inserting one or more unprintable characters into the character-limited message, wherein:

selecting and inserting the one or more unprintable characters into the character-limited message includes detecting a length of the character-limited message and inserting the one or more unprintable characters based on a number of available unused characters in the character-limited message,

the one or more unprintable characters are configured to track the character-limited message comprising the suspicious content and identify a confidence level indicative of a confidence that the suspicious content is suspicious, and

the one or more unprintable characters include different unprintable characters indicating different confidence levels; and

causing, by the at least one processor, transmission of the modified character-limited message to the user device.

12 . The method of claim 11 , wherein the one or more unprintable characters indicate a type of messaging associated with the character-limited message sent to the user device.

13 . The method of claim 11 , further including:

prior to detecting that the character-limited message sent to the user device comprises the suspicious content, classifying the character-limited message based on message type.

14 . The method of claim 11 , wherein generating the modified character-limited message by inserting the one or more unprintable characters into the character-limited message further comprises:

prioritizing, by the at least one processor, the one or more unprintable characters for insertion based on one or more criteria; and

inserting, by the at least one processor, the one or more unprintable characters based on the prioritization.

15 . The method of claim 11 , further including:

detecting, by the at least one processor, a presence of the one or more unprintable characters included in the modified character-limited message; and

adjusting, by the at least one processor, one or more filters based on detecting the presence of the one or more unprintable characters included in the modified character-limited message.

16 . The method of claim 15 , wherein adjusting the one or more filters comprises modifying one or more filter criteria based on an aggregate of character-limited messages identified as comprising actually suspicious content.

17 . The method of claim 15 , wherein adjusting the one or more filters comprises allowing more character-limited messages to pass through to the user device.

18 . One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

receive, via the communication interface, a character-limited message sent to a user device;

scan the character-limited message to evaluate the character-limited message for suspicious content;

detect, based on the scan, that the character-limited message sent to the user device comprises suspicious content;

responsive to detecting that the character-limited message sent to the user device comprises the suspicious content, generate a modified character-limited message by selecting and inserting one or more unprintable characters into the character-limited message, wherein:

selecting and inserting the one or more unprintable characters into the character-limited message includes detecting a length of the character-limited message and inserting the one or more unprintable characters based on a number of available unused characters in the character-limited message,

the one or more unprintable characters are configured to track the character-limited message comprising the suspicious content and identify a confidence level indicative of a confidence that the suspicious content is suspicious, and

the one or more unprintable characters include different unprintable characters indicating different confidence levels; and

cause transmission of the modified character-limited message to the user device.

19 . The one or more non-transitory computer-readable media of claim 18 , wherein the one or more unprintable characters indicate a type of messaging associated with the character-limited message sent to the user device.

20 . The one or more non-transitory computer-readable media of claim 18 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

prior to detecting that the character-limited message sent to the user device comprises the suspicious content, classify the character-limited message based on message type.