IP Library Granted Patent US 10,181,957
Granted Patent B2
US 10,181,957 · App. 15/605,137 · Granted Jan 15, 2019

Systems and methods for detecting and/or handling targeted attacks in the email channel

Inventor: Manoj Kumar Srivastava (Reston, VA)
Assignee: GraphUS, Inc.
H04L12/14G06Q10/107H04L12/58H04L12/585H04L51/12H04L63/126H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,181,957
App. No.
15/605,137
Granted
Jan 15, 2019
Kind
B2
Abstract

Techniques for detecting and/or handling target attacks in an enterprise's email channel are provided. The techniques include receiving aspects of an incoming email message addressed to a first email account holder, selecting a recipient interaction profile and/or a sender profile from a plurality of predetermined profiles stored in a memory based upon the received properties, determining a message trust rating associated with the incoming email message based upon the incoming email message and the selected recipient interaction profile and/or the sender profile; and generating an alert identifying the incoming email message as including a security risk based upon the determined message trust rating. The recipient interaction profile includes information associating the first email account holder and a plurality of email senders from whom email messages have previously been received for the first email account holder, and the sender profile includes information associating a sender of the incoming email message with characteristics determined from a plurality of email messages previously received from the sender.

Claims (36)

1. A method of processing incoming email messages, comprising:

receiving aspects of an incoming email message addressed to a first email account holder, the aspects including properties of the incoming email message;

selecting, from a plurality of predetermined profiles stored in a memory, a recipient interaction profile and/or a sender profile based upon the received properties, wherein the recipient interaction profile includes information associating the first email account holder and a plurality of email senders from whom email messages have previously been received for the first email account holder, and wherein the sender profile includes information associating a sender of the incoming email message with characteristics determined from a plurality of email messages previously received from the sender;

based upon the incoming email message and the selected recipient interaction profile and/or the sender profile, determining a message trust rating associated with the incoming email message, wherein the determining a message trust rating comprises:

accessing an email relationship graph in the memory in which the selected recipient interaction profile and the sender profile correspond to a first graph node and a second graph node respectively, and a graph edge from the second graph node to the first graph node is associated with a metadata of one or more previously received email messages from the sender to the first email account holder, the graph edge being further associated with a domain of the sender and a message transfer agent of the sender: and

calculating the message trust rating based at least upon respective predetermined trust ratings associated with the sender profile, the domain of the sender and the message transfer agent of the sender; and

based upon the determined message trust rating, generating an alert identifying the incoming email message as including a security risk; and

updating the email relationship graph in accordance with the incoming email message, wherein the updating comprises updating a disposition attribute associated with the selected recipient interaction profile or the graph edge with a response of the user to the generated alert.

2. The method according to claim 1 , wherein the calculating the message trust rating is further based on whether the sender is identified in an external threat database.

3. The method according to claim 1 , wherein the calculating the message trust rating is further based on a recipient interaction score based upon the selected recipient interaction profile.

4. The method according to claim 3 , wherein the recipient interaction score is based upon a disposition of one or more previously received messages as indicated in the selected recipient interaction profile or the graph edge.

5. The method according to claim 1 , further comprising updating the email relationship graph in accordance with the incoming email message.

6. The method according to claim 5 , wherein the updating comprises updating a disposition attribute associated with the selected recipient interaction profile or the graph edge with a response of the user to the generated alert.

7. The method according to claim 1 , wherein the accessing the email relationship graph and the calculating is performed by a predictive analyzer without access to the incoming email message and based only on aspects of the incoming email message provided to the predictive analyzer by another process.

8. The method according to claim 1 , wherein the domain of the sender and the message transfer agent of the sender are represented as respective special nodes in a memory data structure representation of the email relationship graph, the respective special nodes being associated in said memory with the graph edge and/or the second graph node.

9. The method according to claim 1 , further comprising updating, in the memory, at least one of the selected recipient interaction profile, the selected sender profile, or a data structure corresponding to a message from the sender to the first account holder, to record at least a portion of the received aspects and information regarding the determined message trust rating.

10. The method according to claim 1 , wherein the graph edge and each of the graph nodes have a respective set of immutable attributes and a respective set of derived attributes, wherein the immutable attributes are determined based upon a corresponding email message, and wherein the derived attributes are determined using (1) calculations using corresponding one or more email messages, and (2) information from a continuously updated external cyber threat intelligence resource, and (3) IP Address to Geo-location mapping information from one or more external databases.

11. A system, comprising:

at least one network interface;

a memory; and

at least one processor configured to perform operations comprising:

receiving aspects of an incoming email message addressed to a first email account holder, the aspects including properties of the incoming email message;

selecting, from a plurality of predetermined profiles stored in a memory, a recipient interaction profile and/or a sender profile based upon the received properties, wherein the recipient interaction profile includes information associating the first email account holder and a plurality of email senders from whom email messages have previously been received for the first email account holder, and wherein the sender profile includes information associating a sender of the incoming email message with characteristics determined from a plurality of email messages previously received from the sender;

based upon the incoming email message and the selected recipient interaction profile and/or the sender profile, determining a message trust rating associated with the incoming email message, wherein the determining a message trust rating comprises:

accessing an email relationship graph in which the selected recipient interaction profile and the sender profile correspond to a first graph node and a second graph node respectively, and a graph edge from the second graph node to the first graph node is associated with a metadata of one or more previously received email messages from the sender to the first email account holder, the graph edge being further associated with a domain of the sender and a message transfer agent of the sender; and

calculating the message trust rating based at least upon respective predetermined trust ratings associated with the sender profile, the domain of the sender and the message transfer agent of the sender; and

based upon the determined message trust rating, generating an alert identifying the incoming email message as including a security risk; and

updating the email relationship graph in accordance with the incoming email message, wherein the updating comprises updating a disposition attribute associated with the selected recipient interaction profile or the graph edge with a response of the user to the generated alert.

12. A non-transitory computer readable storage medium storing program code which, when executed by a processor of a computing device having a memory and at least one network interface, causes the computing device to perform operations comprising:

receiving aspects of an incoming email message addressed to a first email account holder, the aspects including properties of the incoming email message;

selecting, from a plurality of predetermined profiles stored in a memory, a recipient interaction profile and/or a sender profile based upon the received properties, wherein the recipient interaction profile includes information associating the first email account holder and a plurality of email senders from whom email messages have previously been received for the first email account holder, and wherein the sender profile includes information associating a sender of the incoming email message with characteristics determined from a plurality of email messages previously received from the sender;

based upon the incoming email message and the selected recipient interaction profile and/or the sender profile, determining a message trust rating associated with the incoming email message, wherein the determining a message trust rating comprises:

accessing an email relationship graph in which the selected recipient interaction profile and the sender profile correspond to a first graph node and a second graph node respectively, and a graph edge from the second graph node to the first graph node is associated with a metadata of one or more previously received email messages from the sender to the first email account holder, the graph edge being further associated with a domain of the sender and a message transfer agent of the sender; and

calculating the message trust rating based at least upon respective predetermined trust ratings associated with the sender profile, the domain of the sender and the message transfer agent of the sender; and

based upon the determined message trust rating, generating an alert identifying the incoming email message as including a security risk; and

updating the email relationship graph in accordance with the incoming email message, wherein the updating comprises updating a disposition attribute associated with the selected recipient interaction profile or the graph edge with a response of the user to the generated alert.

Assignments (8)
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Mar 24, 2025
From: KASEYA US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS SECOND LIEN COLLATERAL AGENT
Reel/Frame 070608/0192 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Mar 21, 2025
From: KASEYA US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 070586/0834 →
CHANGE OF NAME Recorded Oct 27, 2023
From: DATTO, INC.
To: DATTO, LLC
Reel/Frame 065385/0256 →
RELEASE OF SECURITY INTEREST (PATENTS) Recorded Aug 25, 2022
From: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
To: KASEYA US LLC
Reel/Frame 061272/0360 →
SECURITY INTEREST Recorded Aug 5, 2020
From: KASEYA US LLC
To: GOLUB CAPITAL MARKETS LLC
Reel/Frame 053408/0473 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYANCE TYPE TO MERGER PREVIOUSLY RECORDED ON REEL 053235 FRAME 0927. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Jul 30, 2020
From: GRAPHUS, INC.
To: KASEYA US LLC
Reel/Frame 053370/0369 →
CHANGE OF NAME Recorded Jul 17, 2020
From: GRAPHUS, INC.
To: KASEYA US LLC
Reel/Frame 053235/0927 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 20, 2018
From: SRIVASTAVA, MANOJ KUMAR
To: GRAPHUS, INC.
Reel/Frame 046924/0455 →
Continuity (4)
Continuation 14709460 · May 11, 2015
Provisional Application 62116856 · Feb 16, 2015
Provisional Application 61991854 · May 12, 2014
Related Publication 20170324767A1 · Nov 9, 2017
Cited By (12)
US 12,231,510 US 12,278,875 US 12,301,683 US 12,309,237 US 12,505,409 US 12,519,867 US 12,530,661 US 12,531,934 US 12,563,077 US 12,579,429 US 12,675,773 US 12,701,095