IP Library Granted Patent US 10,326,735
Granted Patent B2
US 10,326,735 · App. 15/723,524 · Granted Jun 18, 2019

Mitigating communication risk by detecting similarity to a trusted message contact

Inventors: Bjorn Markus Jakobsson (Portola Valley, CA); Theodore C. Loder (Durham, NC); Jacob R. Rideout (Raleigh, NC); Arthur Kwan Jakobsson (Portola Valley, CA); Michael L. Jones (Livermore, CA)
Assignee: Agari Data, Inc.
H04L63/0263H04L63/0245H04L63/0254H04L63/1433H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,326,735
App. No.
15/723,524
Granted
Jun 18, 2019
Kind
B2
Abstract

A measure of similarity between an identifier of a sender of the message and each identifier of one or more identifiers of each trusted contact of a plurality of trusted contacts of a recipient of the message is determined. In the event the sender of the message is not any of the trusted contacts but at least one of the measure of similarity between the identifier of the sender of the message and a selected identifier of a selected trusted contact of the plurality of trusted contacts meets a threshold, the message is modified, if applicable, to alter content of a data field that includes an identification of the sender of the message. The data field is one of a plurality of data fields included in a header of the message.

Claims (40)

1. A method, comprising:

determining a measure of trust associated with a sender of a message;

determining a measure of similarity between an identifier of the sender of the message and each identifier of one or more identifiers of each trusted contact of a plurality of trusted contacts of a recipient of the message;

determining a measure of spoofing risk associated with the sender;

combining, at a system that includes one or more servers, the measure of similarity with at least one of the measure of trust or the measure of spoofing risk to determine a combined measure of risk associated with the message, wherein the sender of the message is not any of the trusted contacts but at least one of the measure of similarity between the identifier of the sender of the message and a selected identifier of a selected trusted contact of the plurality of trusted contacts meets a threshold; and

based at least in part on the combined measure of risk associated with the message, modifying, at the system that includes the one or more servers, the message to alter content of a data field that includes an identification of the sender of the message, wherein the data field is one of a plurality of data fields included in a header of the message.

2. The method of claim 1 , wherein modifying the message to alter the content of the data field that includes the identification of the sender includes modifying a sender email address or a reply-to address of the message.

3. The method of claim 1 , wherein modifying the message to alter the content of the data field that includes the identification of the sender includes modifying a display name of the sender of the message.

4. The method of claim 1 , wherein modifying the message to alter the content of the data field that includes the identification of the sender includes modifying a phone number or a link to an image of the sender of the message.

5. The method of claim 1 , wherein the data field is a “From:” field of the header of the message.

6. The method of claim 1 , wherein modifying the message to alter the content of the data field that includes the identification of the sender includes deleting the identification of the sender of the message prior to delivering the message to the recipient of the message.

7. The method of claim 1 , wherein determining the measure of similarity includes sorting elements of the identifier of the sender and sorting elements of the selected identifier of the selected trusted contact.

8. The method of claim 1 , wherein determining the measure of similarity includes determining a string similarity measure between the identifier of the sender and the selected identifier of the selected trusted contact.

9. The method of claim 1 , wherein determining the measure of similarity includes detecting substitution characters in the identifier of the sender.

10. The method of claim 1 , wherein the identifier of the sender includes an email address or a display name of the sender and the selected identifier of the selected trusted contact includes an email address or a display name of the selected trusted contact.

11. The method of claim 1 , wherein the plurality of trusted contacts of the recipient was identified at least in part by the recipient of the message.

12. The method of claim 1 , wherein the plurality of trusted contacts of the recipient was identified at least in part based on contacts included an address book of the recipient of the message.

13. The method of claim 1 , wherein the plurality of trusted contacts of the recipient was automatically identified at least in part by analyzing previous messages sent and received by the recipient.

14. The method of claim 1 , wherein the plurality of trusted contacts of the recipient was identified at least in part by analyzing previous messages sent and received by a plurality of different message accounts of a same network domain of the recipient.

15. The method of claim 1 , wherein the selected identifier of the selected trusted contact was obtained from a subject field of the message.

16. The method of claim 1 , further comprising:

determining a first measure of reputation associated with the sender;

determining a second measure of reputation associated with the sender, wherein the first measure of reputation is associated with a longer timer period than the second measure of reputation; and

detecting a change in the second measure of reputation in light of the first measure of reputation, wherein the message is filtered based at least in part on the detected change.

17. The method of claim 1 , further comprising determining a measure of control of a network domain of the sender the message, wherein the message is filtered based at least in part on the measure of control of the network domain.

18. The method of claim 1 , wherein the spoofing risk is based at least in part a message validation policy associated with a network domain of the sender.

19. A system, comprising:

a processor configured to:

determine a measure of trust associated with a sender of a message;

determine a measure of similarity between an identifier of the sender of the message and each identifier of one or more identifiers of each trusted contact of a plurality of trusted contacts of a recipient of the message;

determine a measure of spoofing risk associated with the sender;

combine the measure of similarity with at least one of the measure of trust or the measure of spoofing risk to determine a combined measure of risk associated with the message, wherein the sender of the message is not any of the trusted contacts but at least one of the measure of similarity between the identifier of the sender of the message and a selected identifier of a selected trusted contact of the plurality of trusted contacts meets a threshold; and

based at least in part on the combined measure of risk associated with the message, modify, at the system that includes the one or more servers, the message to alter content of a data field that includes an identification of the sender of the message, wherein the data field is one of a plurality of data fields included in a header of the message; and

a memory coupled to the processor and configured to provide the processor with instructions.

20. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

determining a measure of trust associated with a sender of a message;

determining a measure of similarity between an identifier of the sender of the message and each identifier of one or more identifiers of each trusted contact of a plurality of trusted contacts of a recipient of the message;

determining a measure of spoofing risk associated with the sender;

combining the measure of similarity with at least one of the measure of trust or the measure of spoofing risk to determine a combined measure of risk associated with the message, wherein the sender of the message is not any of the trusted contacts but at least one of the measure of similarity between the identifier of the sender of the message and a selected identifier of a selected trusted contact of the plurality of trusted contacts meets a threshold; and

based at least in part on the combined measure of risk associated with the message, modifying, at the system that includes the one or more servers, the message to alter content of a data field that includes an identification of the sender of the message, wherein the data field is one of a plurality of data fields included in a header of the message.

Assignments (6)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 57157/0206 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: AGARI DATA, INC.
Reel/Frame 073769/0945 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 57157/0265 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: AGARI DATA, INC.
Reel/Frame 073662/0811 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 10, 2021
From: AGARI DATA, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 057157/0206 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 10, 2021
From: AGARI DATA, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 057157/0265 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2021
From: JAKOBSSON, BJORN MARKUS; LODER, THEODORE C.; RIDEOUT, JACOB R.; JAKOBSSON, ARTHUR KWAN; JONES, MICHAEL L.
To: AGARI DATA, INC.
Reel/Frame 056012/0944 →
Continuity (3)
Continuation 15453737 · Mar 8, 2017
Provisional Application 62399821 · Sep 26, 2016
Related Publication 20180091476A1 · Mar 29, 2018
Cited By (1)
US 12,506,747