IP Library Granted Patent US 12671699
Granted Patent B2
US 12671699 · App. 18/419,292 · Granted Jun 30, 2026

Campaign intelligence and visualization for combating cyberattacks

Inventors: Mihai Costea (Kirkland, WA); Michael Abraham Betser (Kirkland, WA); Ravi Kiran Reddy Poluri (Sammamish, WA); Hua Ding (Redmond, WA); Weisheng Li (Bothell, WA); Phanindra Pampati (Sammamish, WA); David Nicholas Yost (Redmond, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/1416H04L41/22H04L51/08H04L51/212H04L63/1425H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12671699
App. No.
18/419,292
Granted
Jun 30, 2026
Kind
B2
Abstract

Methods, systems, and computer storage media for providing a multi-attribute cluster-identifier that supports identifying malicious activity in computing environments. An instance of an activity having an attribute set can be assessed. The attribute set of the instance of the activity is analyzed to determine whether the instance of the activity is a malicious activity. The attribute set of the instance of the activity is compared to a plurality of multi-attribute cluster-identifiers of previous instances of the activity, such that, a determination that the instance of the activity is a malicious activity is made when the attribute set of the instance of the activity corresponds to an identified multi-attribute cluster-identifier. The identified multi-attribute cluster-identifier has a risk score and an attribute set that indicate a likelihood that the instance of the activity is a malicious activity. A visualization that identifies the instance of the activity as a malicious activity is generated.

Claims (75)

1 . A computer-implemented method, the computer-implemented method comprising:

generating, based on a plurality of email messages associated with a plurality of cyberattacks, a plurality of multi-attribute cluster-identifiers each associated with a corresponding clustering category of a plurality of clustering categories, wherein the plurality of multi-attribute cluster-identifiers are persistently maintained and updated;

assigning each multi-attribute cluster-identifier instance from the plurality of multi-attribute cluster-identifiers a corresponding risk-score from a plurality of risk-scores, a risk-score instance associated with each of: a suspicion score, an anomaly score, and an impact score generated by corresponding separate models;

generating, using a malicious activity model, corresponding composite risks score for the plurality of multi-attribute cluster-identifiers based on their corresponding risk-scores;

accessing an instance of an activity in a computing environment, wherein the instance of the activity comprises an attribute of the instance;

receiving the instance of the activity at the malicious activity model that comprises a multi-attribute cluster identifier associated with a previous instance of the activity, the multi-attribute cluster-identifier comprising a risk score and an attribute of the multi-attribute cluster-identifier,

wherein the risk score and the attribute of the multi-attribute cluster-identifier indicate a likelihood that the instance of the activity is malicious activity,

wherein the malicious activity model is a machine learning model that is trained based on the plurality of email messages associated with the plurality of cyberattacks,

wherein the plurality of email messages are in corresponding clusters is based on corresponding fingerprints of the plurality of emails;

determining, using the malicious activity model, that the instance of the activity is a malicious activity based on comparing the attribute of the instance of the activity to the attribute of the multi-attribute cluster-identifier,

wherein the attribute of the instance of the activity matches the attribute of the multi-attribute cluster-identifier,

wherein the instance of the activity is part of a campaign, the instance of the activity is associated with a campaign visualization that identifies a malicious email determined to belong to the campaign; and

executing a remediation action that is associated with the instance of the activity.

2 . The method of claim 1 , wherein the malicious activity model comprises a plurality of multi-attribute cluster identifiers each associated with corresponding previous instances of the activity, wherein the instance of the activity is an email message, wherein generating the malicious activity model for the plurality of email messages comprising:

clustering the plurality of email messages into two or more clusters based on metadata and attributes associated with the plurality email messages in the cluster; and

assigning risk scores to each of the two or more clusters based on historical information, attributes, and metadata associated with the plurality of email messages in the two or more clusters.

3 . The method of claim 2 , wherein clustering the plurality of email messages into the two or more clusters is based on:

identifying centroids with associated metadata attributes of the plurality of email messages, wherein the centroids are calculated based on the fingerprints of the plurality email messages; and

identifying common metadata attributes among the plurality of email messages.

4 . The method of claim 3 , wherein clustering the plurality of email messages into the two or more clusters is based on:

applying filters based on the common metadata attributes, wherein applying filters based on the common metadata attributes identifies two of more subsets of the plurality of email messages; and

generating campaign guides associated with each of the two or more subsets of the plurality of email messages, wherein a campaign guide links to the common metadata attributes corresponding to a subset of the plurality of email messages.

5 . The method of claim 1 , wherein the risk score is calculated based each of the following: the suspicion score, the anomaly score, and the impact score.

6 . The method of claim 5 , wherein generating the multi-attribute cluster-identifier is based on:

generating each of the suspicion score, the anomaly score, and the impact score for a corresponding cluster segment associated with a type of activity, wherein the type of activity is associated with an attribute;

based on the suspicion score, anomaly score, and the impact score, generating the risk score, wherein the risk score and the attribute indicate a likelihood that the instance of the activity is a malicious activity; and

generate the multi-attribute cluster-identifier comprising the risk score and an attribute set.

7 . The method of claim 1 , wherein the malicious activity model is configurable for processing a plurality of instances of the activity at a tenant level, a global level, or a combined tenant-global level.

8 . The method of claim 1 , the method further comprising generating a visualization of malicious activity operations data comprising the instance of the activity, wherein the visualization identifies the instance of the activity as the malicious activity, wherein the visualization of malicious activity operations data support on of: visually exploring a campaign associated with the instance of the activity, executing bulk actions on all emails in a campaign, identifying indicators of compromise, and identifying tenant policies.

9 . The method of claim 1 , wherein one or more remediation actions are executed based on a severity of the risk score, wherein risk score value corresponds to one of: high, medium, or low.

10 . A system comprising:

one or more computer processors; and computer memory storing computer-useable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations comprising:

generating, based on a plurality of email messages associated with a plurality of cyberattacks, a plurality of multi-attribute cluster-identifiers each associated with a corresponding clustering category of a plurality of clustering categories, wherein the plurality of multi-attribute cluster-identifiers are persistently maintained and updated;

assigning each multi-attribute cluster-identifier from the plurality of multi-attribute cluster-identifiers a corresponding risk-score from a plurality of risk-scores, a risk-score associated with each of: a suspicion score, an anomaly score, and an impact score generated by corresponding separate models;

generating, using a malicious activity model, corresponding composite risks score for the plurality of multi-attribute cluster-identifiers based on their corresponding risk-scores;

accessing an instance of an activity in a computing environment, wherein the instance of the activity comprises an attribute of the instance;

receiving the instance of the activity at a malicious activity model that comprises a multi-attribute cluster identifier associated with a previous instance of the activity, the multi-attribute cluster-identifier comprising a risk score and an attribute of the multi-attribute cluster-identifier,

wherein the risk score and the attribute of the multi-attribute cluster-identifier indicate a likelihood that the instance of the activity is a malicious activity,

wherein the malicious activity model is a machine learning model that is generated trained based on the plurality of email messages associated with the plurality of cyberattacks,

wherein the plurality of email messages are in corresponding clusters is based on corresponding fingerprints of the plurality of emails;

determining, using the malicious activity model, that the instance of the activity is a malicious activity based on comparing the attribute of the instance of the activity to the attribute of the multi-attribute cluster-identifier,

wherein the attribute of the instance of the activity matches the attribute of the multi-attribute cluster-identifier,

wherein the instance of the activity is part of a campaign, the instance of the activity is associated with a campaign visualization that identifies a malicious email determined to belong to the campaign; and

executing a remediation action that are associated with instance of the activity.

11 . The system of claim 10 , wherein the malicious activity model comprises a plurality of multi-attribute cluster identifiers each associated with corresponding previous instances of the activity, wherein the instance of the activity is an email message, wherein generating the malicious activity model for the plurality of email messages comprising:

clustering the plurality of email messages into two or more clusters based on metadata and attributes associated with the plurality email messages in the cluster; and

assigning risk scores to each of the two or more clusters based on historical information, attributes, and metadata associated with the plurality of email messages in the two or more clusters.

12 . The system of claim 11 , wherein clustering the plurality of email messages into the two or more clusters is based on:

identifying centroids with associated metadata attributes of the plurality of email messages, wherein the centroids are calculated based on the fingerprints of the plurality email messages; and

identifying common metadata attributes among the plurality of email messages.

13 . The system of claim 12 , wherein clustering the plurality of email messages into the two or more clusters is based on:

applying filters based on the common metadata attributes, wherein applying filters based on the common metadata attributes identifies two of more subsets of the plurality of email messages; and

generating campaign guides associated with each of the two or more subsets of the plurality of email messages, wherein a campaign guide links to the common metadata attributes corresponding to a subset of the plurality of email messages.

14 . The system of claim 10 , wherein the risk score is calculated based each of: the suspicion score, the anomaly score, and the impact score.

15 . The system of claim 14 , wherein generating the multi-attribute cluster-identifier is based on:

generating each of the suspicion score, the anomaly score, and the impact score for a corresponding cluster segment associated with a type of activity, wherein the type of activity is associated with an attribute;

based on the suspicion score, anomaly score, and the impact score, generating the risk score, wherein the risk score and the attribute indicate a likelihood that the instance of the activity is a malicious activity; and

generate the multi-attribute cluster-identifier comprising the risk score and an attribute set.

16 . The system of claim 10 , wherein one or more remediation actions are executed based on a severity of the risk score, wherein risk score value corresponds to one of: high, medium, or low.

17 . One or more hardware computer-storage media device having computer executable instructions embodied thereon that, when executed by a computing system having a processor and memory, cause the processor to execute operations comprising:

generating, based on a plurality of email messages associated with a plurality of cyberattacks, a plurality of multi-attribute cluster-identifiers each associated with a corresponding clustering category of a plurality of clustering categories, wherein the plurality of multi-attribute cluster-identifiers are persistently maintained and updated;

assigning each multi-attribute cluster-identifier from the plurality of multi-attribute cluster-identifiers a corresponding risk-score from a plurality of risk-scores, a risk-score associated with each of: a suspicion score, an anomaly score, and an impact score generated by corresponding separate models;

generating, using a malicious activity model, corresponding composite risks score for the plurality of multi-attribute cluster-identifiers based on their corresponding risk-scores;

accessing an instance of an activity in a computing environment, wherein the instance of the activity comprises an attribute of the instance;

receiving the instance of the activity at a malicious activity model that comprises a multi-attribute cluster identifier associated with a previous instance of the activity, the multi-attribute cluster-identifier comprising a risk score and an attribute of the multi-attribute cluster-identifier,

wherein the risk score and the attribute of the multi-attribute cluster-identifier indicate a likelihood that the instance of the activity is a malicious activity,

wherein the malicious activity model is a machine learning model that is generated trained based on the plurality of email messages associated with the plurality of cyberattacks,

wherein the plurality of email messages are in corresponding clusters is based on corresponding fingerprints of the plurality of emails;

determining, using the malicious activity model, that the instance of the activity is a malicious activity based on comparing the attribute of the instance of the activity to the attribute of the multi-attribute cluster-identifier,

wherein the attribute of the instance of the activity matches the attribute of the multi-attribute cluster-identifier,

wherein the instance of the activity is part of a campaign, the instance of the activity is associated with a campaign visualization that identifies a malicious email determined to belong to the campaign; and

executing a remediation action that is associated with instance of the activity.

18 . The media of claim 17 , the operations further comprising generating a visualization of malicious activity operations data comprising the instance of the activity, wherein the visualization identifies the instance of the activity as the malicious activity, wherein the visualization of malicious activity operations data support on of: visually exploring a campaign associated with the instance of the activity, executing bulk actions on all emails in a campaign, identifying indicators of compromise, and identifying tenant policies.

19 . The media of claim 17 , wherein the risk score is calculated based each of: the suspicion score, the anomaly score, and the impact score.

20 . The media of claim 17 , wherein one or more remediation actions are executed based on a severity of the risk score, wherein risk score value corresponds to one of: high, medium, or low.