IP Library Granted Patent US 12689631
Granted Patent B2
US 12689631 · App. 17/012,731 · Granted Jul 21, 2026

Using message context to evaluate security of requested data

Inventors: Bjorn Markus Jakobsson (Portola Valley, CA); Scot Free Kennedy (San Francisco, CA); Patrick Richard Peterson (San Francisco, CA)
Assignee: AGARI DATA, INC.
H04L63/126G06F16/955G06F21/554H04L51/212H04L51/23H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12689631
App. No.
17/012,731
Granted
Jul 21, 2026
Kind
B2
Abstract

Information of an electronic message to be delivered to an intended recipient is received. For an original resource identifier included in the electronic message, a corresponding alternative resource identifier that can be at least in part used to obtain the original resource identifier and obtain context information associated with the electronic message is determined. The original resource identifier included in the electronic message is replaced with the alternative resource identifier to generate a modified electronic message. The modified electronic message with the alternative resource identifier is allowed to be delivered to the intended recipient instead of the electronic message with the original resource identifier. A request made using the alternative resource identifier in the modified message triggers a security action based at least in part on the context information associated with the electronic message.

Claims (42)

1 . A method for handling electronic messages by a recipient system, the method comprising:

determining for an original resource identifier included in an electronic message to be delivered to an intended recipient, a corresponding alternative resource identifier that is based on both the specific intended recipient and the original resource identifier and at least in part used to obtain the original resource identifier;

performing domain-based authentication on the electronic message to determine that a sending domain of the electronic message fails the domain-based authentication;

in response to determining that the sending domain of the electronic message fails the domain-based authentication, after receiving the electronic message, prior to performing a content-based security analysis associated with the original resource identifier that is delayed until a user requests content using the corresponding alternative resource identifier on the electronic message and the original resource identifier within the electronic message, and prior to delivering the electronic message to the intended recipient, replacing the original resource identifier included in the electronic message with the corresponding alternative resource identifier to generate a modified electronic message;

allowing the modified electronic message with the corresponding alternative resource identifier to be delivered to the intended recipient instead of the electronic message with the original resource identifier; and

upon receiving a request using the corresponding alternative resource identifier, performing the content-based security analysis.

2 . The method of claim 1 , wherein an interaction associated with the original resource identifier is tracked using the corresponding alternative resource identifier including by storing for the original resource identifier in a data structure, an entry that includes interaction information and associated context information for a request made using the corresponding alternative resource identifier, and wherein the method further comprises:

obtaining from the data structure storing the interaction information and the associated context information, entries for the original resource identifier to determine a scoring associated with the original resource identifier; and

performing an action based on a determination that the scoring meets a threshold criteria, wherein performing the action includes performing one or more of the following: blocking access to content referenced by the original resource identifier, providing a security warning, providing a modified version of the content referenced by the original resource identifier with modified functionality, logging an event associated with the request made using the corresponding alternative resource identifier, or performing an auditing operation.

3 . The method of claim 2 , wherein the interaction associated with the original resource identifier is tracked including by receiving a notification of the request made using the corresponding alternative resource identifier, wherein logging the information associated with the request includes recording a time associated with when the request was made.

4 . The method of claim 2 , wherein performing the action includes performing an analysis based at least in part on the tracked interaction.

5 . The method of claim 4 , wherein performing the analysis includes determining a statistic associated with a likelihood a message recipient will request a content of the original resource identifier.

6 . The method of claim 4 , wherein performing the analysis includes determining a list of message recipients that requested the content of the original resource identifier.

7 . The method of claim 6 , further comprising performing a security action for each of the message recipients in the list of message recipients.

8 . The method of claim 1 , wherein the original resource identifier is a URL hyperlink included in a body content of the electronic message, and the corresponding alternative resource identifier is generated specifically for the intended recipient of the electronic message.

9 . The method of claim 1 , wherein the electronic message is to be delivered to a plurality of different intended recipients and a different corresponding alternative resource identifier for the same original resource identifier is generated for each of the different intended recipients.

10 . The method of claim 1 , wherein a plurality of different interactions associated with the original resource identifier by different recipients of the electronic message is tracked.

11 . The method of claim 1 , wherein determining the corresponding alternative resource identifier includes searching a data structure using the original resource identifier.

12 . The method of claim 1 , wherein the recipient system includes one or more of the following: a mail transfer agent device, a mail relay device, a gateway device, a cloud security device, or a local security appliance.

13 . The method of claim 1 , wherein the corresponding alternative resource identifier includes a domain name associated with a security service, wherein the domain name associated with the security service is not included in the original resource identifier.

14 . The method of claim 1 , wherein determining the corresponding alternative resource identifier includes determining a handle value corresponding to at least the original resource identifier and including the handle value in the corresponding alternative resource identifier.

15 . The method of claim 14 , wherein the entry that includes the interaction information and associated context information corresponds to the handle value.

16 . The method of claim 1 , wherein determining the corresponding alternative resource identifier includes encrypting at least the original resource identifier to generate an encrypted value and including the encrypted value in the corresponding alternative resource identifier.

17 . The method of claim 1 , further comprising:

generating a handle value by cryptographically encoding at least the original resource identifier and an identifier of the intended recipient;

generating the corresponding alternative resource identifier to include the handle value and a domain name associated with a security service that is different from a domain name of the original resource identifier;

storing, in a data structure, a mapping from the handle value to the original resource identifier; and

upon receiving a request using the corresponding alternative resource identifier, retrieving the original resource identifier by dereferencing the handle value in the data structure.

18 . A system, comprising:

a communication interface; and

a processor coupled with the communication interface and configured to:

determine for an original resource identifier included in an electronic message to be delivered to an intended recipient, a corresponding alternative resource identifier that is based on both the specific intended recipient and the original resource identifier and at least in part used to obtain the original resource identifier;

perform domain-based authentication on the electronic message to determine that a sending domain of the electronic message fails the domain-based authentication;

in response to determining that the sending domain of the electronic message fails the domain-based authentication, after receiving the electronic message, prior to performing a content-based security analysis associated with the original resource identifier that is delayed until a user requests content using the corresponding alternative resource identifier on the electronic message and the original resource identifier within the electronic message, and prior to delivering the electronic message to the intended recipient, replace the original resource identifier included in the electronic message with the corresponding alternative resource identifier to generate a modified electronic message;

allow the modified electronic message with the corresponding alternative resource identifier to be delivered to the intended recipient instead of the electronic message with the original resource identifier; and

upon receiving a request using the corresponding alternative resource identifier, perform the content-based security analysis.

19 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

determining for an original resource identifier included in an electronic message to be delivered to an intended recipient, a corresponding alternative resource identifier that is based on both the specific intended recipient and the original resource identifier and at least in part used to obtain the original resource identifier;

performing domain-based authentication on the electronic message to determine that a sending domain of the electronic message fails the domain-based authentication;

in response to determining that the sending domain of the electronic message fails the domain-based authentication, after receiving the electronic message, prior to performing a content-based security analysis associated with the original resource identifier that is delayed until a user requests content using the corresponding alternative resource identifier on the electronic message and the original resource identifier within the electronic message, and prior to delivering the electronic message to the intended recipient, replacing the original resource identifier included in the electronic message with the corresponding alternative resource identifier to generate a modified electronic message; allowing the modified electronic message with the corresponding alternative resource identifier to be delivered to the intended recipient instead of the electronic message with the original resource identifier; and

upon receiving a request using the corresponding alternative resource identifier, performing the content-based security analysis.

20 . The system of claim 19 , wherein performing the action includes performing an analysis based at least in part on the tracked interaction.