IP Library Granted Patent US 10,516,567
Granted Patent B2
US 10,516,567 · App. 15/207,052 · Granted Dec 24, 2019

Identification of vulnerability to social phishing

Inventors: James Foster (Baltimore, MD); Evan Blair (Baltimore, MD); Christopher B. Cullison (Westminster, MD); Robert Francis (Baltimore, MD)
Assignee: ZeroFOX, Inc.
H04L41/0686H04L43/062H04L63/1433H04L67/02H04L67/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,516,567
App. No.
15/207,052
Granted
Dec 24, 2019
Kind
B2
Abstract

A computer-implemented method includes generating, by one or more processors, a hyperlink targeting a Uniform Resource Locator (URL), detecting a selection of the generated hyperlink by one or more social entities across one or more social networks, generating a report, wherein the generated report includes analytical details regarding the selection of the generated hyperlink by the one or more social entities, and providing the generated report to a user associated with a protected social entity.

Claims (61)

1. A computer-implemented method comprising:

generating, by a phishing engine of a vulnerability management platform, a hyperlink targeting a Uniform Resource Locator (URL);

communicating, by the phishing engine, the generated hyperlink to one or more social entities;

detecting, by the phishing engine, a selection of the generated hyperlink by a subset of the one or more social entities across one or more social networks;

generating, by a report generator, a report that includes analytical details regarding the selection of the generated hyperlink by the subset of the one or more social entities;

determining, by the phishing engine, a vulnerability score for a protected social entity, that reflects a probability of the protected social entity selecting the generated hyperlink, wherein the vulnerability score for the protected social entity is a weighted average of one or more vulnerability assessment ratings;

comparing the vulnerability score for the protected social entity to a vulnerability threshold;

based on comparing the vulnerability score to the vulnerability threshold, determining that the vulnerability score exceeds the vulnerability threshold;

based on determining that the vulnerability score exceeds the threshold, generating an alert; and

providing, by the phishing engine, for output through the vulnerability management platform, the alert to a user associated with the protected social entity;

wherein the vulnerability management platform further comprises:

a security analysis engine configured to identify profiles that have been generated to impersonate the profile of the protected social entity;

a predictive risk protection module configured to proactively identify cyber threats by determining a social risk score for social entities before they attempt to connect with the user associated with the protected social entity; and

an active risk protection module configured to:

identify immediate security risks by determining a social risk score for unknown social entities that attempt to connect with the user associated with the protected social entity; and

initiate a security action based on the social risk score.

2. The method of claim 1 further comprising scanning data that is maintained on the one or more social networks, wherein scanning data that is maintained on the one or more social networks comprises identifying, by one or more processors, data that is associated with the one or more social entities.

3. The method of claim 2 wherein scanning data that is maintained on the one or more social networks is performed on a continuous basis, without user initiation.

4. The method of claim 2 wherein the selection of the generated hyperlink by the subset of the one or more social entities is detected during scanning.

5. The method of claim 1 wherein the text of the hyperlink is associated with a hashtag.

6. The method of claim 1 wherein, the protected social entity is an organization.

7. The method of claim 1 wherein the protected social entity is an individual.

8. The method of claim 1 wherein the resource targeted by the generated hyperlink provides fictitious information.

9. The method of claim 1 wherein the resource targeted by the generated hyperlink solicits information from the one or more social entities.

10. The method of claim 1 wherein the resource targeted by the generated URL indicates that it is related to a trusted social entity.

11. A system comprising:

one or more processing devices; and

one or more non-transitory computer-readable media coupled to the one or more processing devices having instructions stored thereon which, when executed by the one or more processing devices, cause the one or more processing devices to perform operations comprising: generating, by a phishing engine, a hyperlink targeting a Uniform Resource Locator (URL);

communicating, by the phishing engine of a vulnerability management platform, the generated hyperlink to one or more social entities;

detecting, by the phishing engine, a selection of the generated hyperlink by a subset of the one or more social entities across one or more social networks;

generating, by a report generator, a report that includes analytical details regarding the selection of the generated hyperlink by the subset of the one or more social entities;

determining, by the phishing engine, a vulnerability score for a protected social entity, that reflects a probability of the protected social entity selecting the generated hyperlink, wherein the vulnerability score for the protected social entity is a weighted average of one or more vulnerability assessment ratings;

comparing the vulnerability score for the protected social entity to a vulnerability threshold;

based on comparing the vulnerability score to the vulnerability threshold, determining that the vulnerability score exceeds the vulnerability threshold;

based on determining that the vulnerability score exceeds the threshold, generating an alert; and

providing, by the phishing engine, for output through the vulnerability management platform, the alert to a user associated with the protected social entity;

wherein the vulnerability management platform further comprises:

a security analysis engine configured to identify profiles that have been generated to impersonate the profile of the protected social entity;

a predictive risk protection module configured to proactively identify cyber threats by determining a social risk score for social entities before they attempt to connect with the user associated with the protected social entity; and

an active risk protection module configured to:

identify immediate security risks by determining a social risk score for unknown social entities that attempt to connect with the user associated with the protected social entity, and

initiate a security action based on the social risk score.

12. The system of claim 11 further comprising scanning data that is maintained on one or more social networks, wherein scanning data that is maintained on one or more social networks comprises identifying, by one or more processors, data that is associated with the one or more social entities.

13. The system of claim 12 wherein scanning data that is maintained on the one or more social networks is performed on a continuous basis, without user initiation.

14. The system of claim 12 wherein the selection of the generated hyperlink by the subset of the one or more social entities is detected during scanning.

15. A non-transitory computer-readable storage medium encoded with a computer program, the program comprising instructions that when executed by a data processing apparatus cause the data processing apparatus to perform operations comprising:

generating, by a phishing engine of a vulnerability management platform, a hyperlink targeting a Uniform Resource Locator (URL);

communicating, by the phishing engine, the generated hyperlink to one or more social entities;

detecting, by the phishing engine, a selection of the generated hyperlink by a subset of the one or more social entities across one or more social networks;

generating, by a report generator, a report that includes analytical details regarding the selection of the generated hyperlink by the subset of the one or more social entities;

determining, by the phishing engine, a vulnerability score for a protected social entity, that reflects a probability of the protected social entity selecting the generated hyperlink, wherein the vulnerability score for the protected social entity is a weighted average of one or more vulnerability assessment ratings;

comparing the vulnerability score for the protected social entity to a vulnerability threshold;

based on comparing the vulnerability score to the vulnerability threshold, determining that the vulnerability score exceeds the vulnerability threshold;

based on determining that the vulnerability score exceeds the threshold, generating an alert; and

providing, by the phishing engine, for output through the vulnerability management platform, the alert to a user associated with the protected social entity;

wherein the vulnerability management platform further comprises:

a security analysis engine configured to identify profiles that have been generated to impersonate the profile of the protected social entity;

a predictive risk protection module configured to proactively identify cyber threats by determining a social risk score for social entities before they attempt to connect with the user associated with the protected social entity; and

an active risk protection module configured to:

identify immediate security risks by determining a social risk score for unknown social entities that attempt to connect with the user associated with the protected social entity, and

initiate a security action based on the social risk score.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded May 16, 2024
From: STIFEL BANK
To: ZEROFOX, INC.
Reel/Frame 067429/0328 →
SECURITY INTEREST Recorded May 13, 2024
From: ZEROFOX, INC.; LOOKINGGLASS CYBER SOLUTIONS, LLC; IDENTITY THEFT GUARD SOLUTIONS, INC.
To: MONROE CAPITAL MANAGEMENT ADVISORS, LLC
Reel/Frame 067396/0304 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2022
From: ORIX GROWTH CAPITAL, LLC
To: VIGILANTEATI, INC.
Reel/Frame 060821/0137 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2022
From: ORIX GROWTH CAPITAL, LLC
To: ZEROFOX, INC.
Reel/Frame 060821/0173 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR AND ASSIGNEE'S INFORMATION ON THE COVER SHEET PREVIOUSLY RECORDED AT REEL: 054878 FRAME: 0117. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Jan 6, 2022
From: HERCULES CAPITAL, INC.
To: ZEROFOX, INC.
Reel/Frame 058652/0754 →
SECURITY INTEREST Recorded Jan 28, 2021
From: ZEROFOX, INC.
To: STIFEL BANK
Reel/Frame 055066/0916 →
SECURITY INTEREST Recorded Jan 13, 2021
From: ZEROFOX, INC.
To: ORIX GROWTH CAPITAL, LLC
Reel/Frame 054906/0449 →
RELEASE OF SECURITY INTEREST Recorded Jan 11, 2021
From: ZEROFOX, INC.
To: HERCULES CAPITAL, INC.
Reel/Frame 054878/0117 →
RELEASE OF SECURITY INTEREST Recorded Jun 27, 2019
From: SILVER LAKE WATERMAN FUND II, L.P.
To: ZEROFOX, INC.
Reel/Frame 049607/0961 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 26, 2019
From: ZEROFOX, INC.
To: HERCULES CAPITAL, INC., AS AGENT
Reel/Frame 049602/0173 →
SECURITY INTEREST Recorded Jun 1, 2017
From: ZEROFOX, INC.
To: SILVER LAKE WATERMAN FUND II, L.P., AS AGENT
Reel/Frame 042568/0264 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2016
From: FOSTER, JAMES; BLAIR, EVAN; CULLISON, CHRISTOPHER B.; FRANCIS, ROBERT
To: ZEROFOX, INC.
Reel/Frame 039308/0970 →
Continuity (2)
Provisional Application 62191117 · Jul 10, 2015
Related Publication 20170013014A1 · Jan 12, 2017