IP Library Granted Patent US 10,419,478
Granted Patent B2
US 10,419,478 · App. 15/642,018 · Granted Sep 17, 2019

Identifying malicious messages based on received message data of the sender

Inventors: Philip Syme (Ellicott City, MD); Oren Falkowitz (Redwood City, CA); Michael Flester (Highland, MD)
Assignee: Area 1 Security, Inc.
H04L63/1483H04L51/12H04L63/126H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,419,478
App. No.
15/642,018
Granted
Sep 17, 2019
Kind
B2
Abstract

Systems and methods for providing an improvement to computer security relating to electronic digital messages are provided. In an embodiment, a computing device receives an electronic digital message that is sent to a receiving account. The computing device identifies a sending account associated with the electronic digital message and from which the electronic digital message was sent. The computing device obtains metadata relating to the sending account, the metadata including received message data that is related to a number of messages that have been received by the sending account. The computing device determines that the sending account satisfies a received message criteria based, at least in part, on the received message data and, in response, performs a responsive action relating to the electronic digital message.

Claims (64)

1. A data processing method providing an improvement in computer security and comprising:

receiving, at a security computing device executing one or more message security applications, an electronic digital message that is directed to a receiving account;

using the security computing device, identifying a sending account associated with the electronic digital message and from which the electronic digital message was sent;

transmitting, to a message server, a request to obtain a count of messages received by any of a plurality of primary recipient accounts from a plurality of secondary sending accounts where the sending account was a secondary recipient, and receiving the count of messages in response to the request;

using the security computing device, determining that the sending account satisfies one or more received message criteria by determining that the count of messages is less than a threshold number of messages;

in response to the determining, using the security computing device, performing a responsive action relating to the electronic digital message.

2. The method of claim 1 , further comprising identifying one or more spam messages received by the sending account;

wherein the determining that the count of messages is less than the threshold number of messages is performed based only on messages that do not include the one or more spam messages.

3. The method of claim 1 , further comprising:

identifying a provider of the sending account;

transmitting, to the provider of the sending account, a request for the metadata;

receiving, from the provider of the sending account, data identifying a number of messages received by the sending account;

determining that the sending account satisfies the received message criteria based, at least in part, on the data identifying the number of messages received by the sending account.

4. The method of claim 1 , further comprising:

transmitting, to a recipient account data source, a request for data identifying a plurality of recipient accounts;

receiving, from the recipient account data source, data identifying the plurality of recipient accounts;

determining that the sending account is not identified in the data identifying a plurality of recipient accounts and, in response, determining that the sending account satisfies the received message criteria.

5. The method of claim 1 , the responsive action comprising causing the electronic digital message to be quarantined.

6. The method of claim 1 , the responsive action comprising identifying the sending account as a potential phishing account.

7. The method of claim 1 , the responsive action comprising increasing a value identifying a likelihood that the sending account is a phishing account.

8. The method of claim 1 , the responsive action comprising analyzing one or more hyperlinks in the electronic digital message.

9. The method of claim 1 , the responsive action comprising causing scanning one or more attachments in the electronic digital message for viruses.

10. A data processing method providing an improvement in computer security and comprising:

receiving, at a security computing device implemented to execute one or more message security applications an e-mail message that is directed to a receiving account;

identifying, by the security computing device, a sending account associated with the e-mail message and from which the e-mail message was sent;

transmitting, to a host computer of the sending account, a request to obtain a count of messages received by any of a plurality of primary recipient accounts from a plurality of secondary sending accounts where the sending account was a secondary recipient, and receiving the count of messages in response to the request;

using the security computing device, in response to determining that the count of messages is less than a specified number, performing a responsive action relating to the e-mail message, the responsive action comprising one or more of:

causing the e-mail message to be quarantined;

marking the sending account as a potential phishing account;

increasing a value identifying a likelihood that the sending account is a phishing account;

analyzing one or more hyperlinks in the e-mail message;

scanning one or more attachments in the e-mail message for viruses;

dropping and not delivering the e-mail message to the receiving account;

transmitting one or more notifications or alerts relating to the e-mail message.

11. The method of claim 10 , further comprising:

identifying one or more spam messages received by the sending account;

modifying the count of messages received by the sending account, as received in response to the request, by decrementing the one or more spam messages from the count.

12. The method of claim 10 , further comprising:

receiving data identifying a plurality of recipient accounts;

determining that the sending account is not identified in the data identifying a plurality of recipient accounts and, in response, performing the responsive action.

13. A system comprising:

one or more processors;

a memory communicatively coupled to the one or more processors storing instructions which, when executed by the one or more processors, cause performance of:

receiving an electronic digital message that is directed to a receiving account;

identifying a sending account associated with the electronic digital message and from which the electronic digital message was sent;

transmitting, to a message server, a request to obtain a count of messages received by any of a plurality of primary recipient accounts from a plurality of secondary sending accounts where the sending account was a secondary recipient, and receiving the count of messages in response to the request;

determining that the sending account satisfies one or more received message criteria by determining that the count of messages is less than a threshold number of messages;

in response to the determining, performing a responsive action relating to the electronic digital message.

14. The system of claim 13 , wherein the instructions, when executed by the one or more processors, further cause performance of identifying one or more spam messages received by the sending account;

wherein the determining that the count of messages is less than the threshold number of messages is performed based only on messages that do not include the one or more spam messages.

15. The system of claim 13 , wherein the instructions, when executed by the one or more processors, further cause performance of:

identifying a provider of the sending account;

transmitting, to the provider of the sending account, a request for the metadata;

receiving, from the provider of the sending account, data identifying a number of messages received by the sending account;

determining that the sending account satisfies the received message criteria based, at least in part, on the data identifying the number of messages received by the sending account.

16. The system of claim 13 , wherein the instructions, when executed by the one or more processors, further cause performance of:

transmitting, to a recipient account data source, a request for data identifying a plurality of recipient accounts;

receiving, from the recipient account data source, data identifying the plurality of recipient accounts;

determining that the sending account is not identified in the data identifying a plurality of recipient accounts and, in response, determining that the sending account satisfies the received message criteria.

17. The system of claim 13 , the responsive action comprising causing the electronic digital message to be quarantined.

18. The system of claim 13 , the responsive action comprising identifying the sending account as a potential phishing account.

19. The system of claim 13 , the responsive action comprising increasing a value identifying a likelihood that the sending account is a phishing account.

20. The system of claim 13 , the responsive action comprising analyzing one or more hyperlinks in the electronic digital message.

21. The system of claim 13 , the responsive action comprising causing scanning one or more attachments in the electronic digital message for viruses.

Assignments (5)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2022
From: AREA 1 SECURITY, LLC
To: CLOUDFLARE, INC.
Reel/Frame 059615/0665 →
MERGER Recorded Apr 11, 2022
From: AREA 1 SECURITY, INC.
To: ANGLER MERGER SUB II, LLC
Reel/Frame 059565/0414 →
CHANGE OF NAME Recorded Apr 11, 2022
From: ANGLER MERGER SUB II, LLC
To: AREA 1 SECURITY, LLC
Reel/Frame 059565/0653 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2017
From: SYME, PHILIP; FALKOWITZ, OREN; FLESTER, MICHAEL
To: AREA 1 SECURITY, INC.
Reel/Frame 042990/0057 →
Continuity (1)
Related Publication 20190014143A1 · Jan 10, 2019
Cited By (1)
US 12,348,471