IP Library Patent Application 14861846
Patent Application
App. No. 14/861,846

DETECTING AND THWARTING SPEAR PHISHING ATTACKS IN ELECTRONIC MESSAGES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/861,846
Abstract

A computer-implemented method may comprise receiving an electronic message from a purported known sender; accessing a database of known senders and determining whether the sender matches one of the known senders. The degree of similarity of the sender to at least one of the known senders may then be quantified. The received message may then be determined to be legitimate when the purported known sender is determined to match one of the known senders. The received electronic message may be flagged as being suspect when the purported known sender does not match one of the plurality of known senders and the quantified degree of similarity of the purported known sender to one of the known senders is greater than a threshold value. A perceptible cue may then be generated when the received message has been flagged as being suspect, to alert the recipient that the flagged message is likely illegitimate.

Claims (48)

1 . A computer-implemented method, comprising:

receiving an electronic message from a purported known sender over a computer network;

accessing a database configured to store a plurality of known senders of electronic messages and determining whether the purported known sender of the electronic message matches one of the plurality of known senders of electronic messages in the database of known senders;

quantifying a degree of similarity of the purported known sender of the electronic message to at least one of the plurality of known senders of electronic messages stored in the database;

determining the received electronic message to be legitimate when the purported known sender is determined to match one of the plurality of known senders in the database of known senders;

flagging the received electronic message as being suspect when:

the purported known sender does not match one of the plurality of known senders in the database of known senders; and

the quantified degree of similarity of the purported known sender of the electronic message to one of the plurality of known senders of electronic messages is greater than a threshold value; and

generating at least a visual cue when the received electronic message has been flagged as being suspect, to alert a recipient thereof that the flagged electronic message is likely illegitimate.

2 . The computer-implemented method of claim 1 , wherein the electronic message comprises an email.

3 . The computer-implemented method of claim 1 , wherein quantifying comprises calculating a string metric of a difference between the purported sender and one of the plurality of known senders in the database of known senders.

4 . The computer-implemented method of claim 1 , wherein quantifying comprises calculating a Levenshtein distance between the purported sender and one of the plurality of known senders in the database of known senders.

5 . The computer-implemented method of claim 1 , further comprising prompting for a decision confirming the flagged electronic message is suspect or a decision denying that the flagged electronic message is suspect.

6 . The computer-implemented method of claim 5 , further comprising dropping the flagged electronic message when the prompted decision is to confirm that the flagged electronic message is suspect and delivering the flagged electronic message when the prompted decision is to deny that the flagged electronic message is suspect.

7 . The computer-implemented method of claim 1 , wherein accessing also accesses a database of blacklisted senders of electronic messages and dropping the received electronic message if a sender of the received electronic matches an entry in the database of blacklisted senders of electronic messages.

8 . A computing device configured to determine whether a received electronic message comprises a spear phishing attack, comprising:

at least one processor;

at least one data storage device coupled to the at least one processor;

a plurality of processes spawned by said at least one processor, the processes including processing logic for:

receiving an electronic message from a purported known sender over a computer network;

accessing a database configured to store a plurality of known senders of electronic messages and determining whether the purported known sender of the electronic message matches one of the plurality of known senders of electronic messages in the database of known senders;

quantifying a degree of similarity of the purported known sender of the electronic message to at least one of the plurality of known senders of electronic messages stored in the database;

determining the received electronic message to be legitimate when the purported known sender is determined to match one of the plurality of known senders in the database of known senders;

flagging the received electronic message as being suspect when:

the purported known sender does not match one of the plurality of known senders in the database of known senders; and

the quantified degree of similarity of the purported known sender of the electronic message to one of the plurality of known senders of electronic messages is greater than a threshold value; and

generating at least a visual cue when the received electronic message has been flagged as being suspect, to alert a recipient thereof that the flagged electronic message is likely illegitimate

9 . The computing device of claim 8 , wherein the electronic message comprises an email.

10 . The computing device of claim 8 , wherein quantifying comprises calculating a string metric of a difference between the purported sender and one of the plurality of known senders in the database of known senders.

11 . The computing device of claim 8 , wherein quantifying comprises calculating a Levenshtein distance between the purported sender and one of the plurality of known senders in the database of known senders.

12 . The computing device of claim 8 , wherein the processes further comprise processing logic for prompting for a decision confirming the flagged electronic message is suspect or a decision denying that the flagged electronic message is suspect.

13 . The computing device of claim 12 , wherein the processes further comprise processing logic for dropping the flagged electronic message when the prompted decision is to confirm that the flagged electronic message is suspect and for delivering the flagged electronic message when the prompted decision is to deny that the flagged electronic message is suspect.

14 . The computing device of claim 8 , wherein the processes further comprise processing logic for accessing a database of blacklisted senders of electronic messages and dropping the received electronic message if a sender of the received electronic matches an entry in the database of blacklisted senders of electronic messages.

15 . A tangible, non-transitory machine-readable data storage device having data stored thereon representing sequences of instructions which, when executed by a computing device, cause the computing device to:

receive an electronic message from a purported known sender over a computer network;

access a database configured to store a plurality of known senders of electronic messages and determine whether the purported known sender of the electronic message matches one of the plurality of known senders of electronic messages in the database of known senders;

quantify a degree of similarity of the purported known sender of the electronic message to at least one of the plurality of known senders of electronic messages stored in the database;

determine the received electronic message to be legitimate when the purported known sender is determined to match one of the plurality of known senders in the database of known senders;

flag the received electronic message as being suspect when:

the purported known sender does not match one of the plurality of known senders in the database of known senders; and

the quantified degree of similarity of the purported known sender of the electronic message to one of the plurality of known senders of electronic messages is greater than a threshold value; and

generate at least a visual cue when the received electronic message has been flagged as being suspect, to alert a recipient thereof that the flagged electronic message is likely illegitimate.

16 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein the electronic message comprises an email.

17 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein quantifying comprises calculating a string metric of a difference between the purported sender and one of the plurality of known senders in the database of known senders.

18 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein quantifying comprises calculating a Levenshtein distance between the purported sender and one of the plurality of known senders in the database of known senders.

19 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein the stored sequences of instructions further comprise prompting for a decision confirming the flagged electronic message is suspect or a decision denying that the flagged electronic message is suspect.

20 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein the stored sequences of instructions further comprise dropping the flagged electronic message when the prompted decision is to confirm that the flagged electronic message is suspect and delivering the flagged electronic message when the prompted decision is to deny that the flagged electronic message is suspect.

21 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein the stored sequences of instructions further comprise accessing a database of blacklisted senders of electronic messages and dropping the received electronic message if a sender of the received electronic matches an entry in the database of blacklisted senders of electronic messages.

Assignments (4)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 059510, FRAME 0419 Recorded Feb 22, 2024
From: TIKEHAU ACE CAPITAL
To: VADE USA INCORPORATED
Reel/Frame 066647/0152 →
SECURITY INTEREST Recorded Apr 15, 2022
From: VADE USA INCORPORATED
To: TIKEHAU ACE CAPITAL
Reel/Frame 059610/0419 →
CHANGE OF NAME Recorded Oct 17, 2018
From: VADE RETRO TECHNOLOGY, INCORPORATED
To: VADE SECURE, INCORPORATED
Reel/Frame 047196/0317 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2015
From: GOUTAL, SEBASTIEN
To: VADE RETRO TECHNOLOGY INC.
Reel/Frame 036626/0414 →