IP Library Granted Patent US 11,019,076
Granted Patent B1
US 11,019,076 · App. 15/958,648 · Granted May 25, 2021

Message security assessment using sender identity profiles

Inventors: Bjorn Markus Jakobsson (Portola Valley, CA); John M. Wilson, III (Mountain View, CA)
Assignee: Agari Data, Inc.
H04L63/123H04L51/22H04L63/0236H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,019,076
App. No.
15/958,648
Granted
May 25, 2021
Kind
B1
Abstract

An identity profile of a user is tracked using previous message communications of the user. A message identified as potentially from the user is received. The identity profile of the user is identified and obtained. Information is extracted from a header of the received message. A security risk assessment of the received message is determined at least in part by comparing the extracted information with one or more corresponding entries of the identity profile of the user. A security action is performed based on the determined security risk assessment.

Claims (40)

1. A method, comprising:

tracking an identity profile of a user using previous message communications of the user;

receiving a message identified as potentially from the user;

identifying and obtaining the identity profile of the user;

extracting information from a header of the received message;

determining a security risk assessment of the received message at least in part by comparing the extracted information with one or more corresponding entries of the identity profile of the user including by detecting a change between at least a portion of the extracted information and at least one entry of the identity profile of the user and evaluating the detected change based on a likelihood-of-change probability associated with a likelihood that the at least one entry of the identity profile would change over time, wherein the likelihood-of-change probability is determined using previously detected changes over time in the previous message communications of the user including by computing a measurement of a distribution of a frequency of changes between different types of mail user agents used by the user; and

performing a security action based on the determined security risk assessment.

2. The method of claim 1 , wherein the likelihood-of-change probability is determined not using the detected change but only using the previously detected changes over time in the previous message communications of the user.

3. The method of claim 1 , wherein the extracted information includes information identifying an operating system used by a sender of the received message.

4. The method of claim 1 , wherein the extracted information includes information identifying a computer network used by a sender of the received message.

5. The method of claim 1 , wherein the extracted information includes information identifying a script used by a sender of the received message.

6. The method of claim 1 , wherein identifying and obtaining the identity profile of the user includes identifying the identity profile of the user with a display name of a sender of the received message.

7. The method of claim 1 , wherein determining the security risk assessment includes determining that the user of the identity profile is likely not a sender of the received message.

8. The method of claim 1 , wherein comparing the extracted information with the one or more corresponding entries of the identity profile of the user includes determining that although a mail user agent utilized by the received message does not exactly match a mail user agent specified in the identity profile, the mail user agent utilized by the received message is a newer version of the mail user agent utilized specified in the identity profile.

9. The method of claim 1 , wherein determining the security risk assessment of the received message includes determining that the message has likely been compromised by a phishing attack at least in part by determining that a sender message account of the received message matches an entry in the identity profile as a trusted message account but a device identifier extracted from the received message does not match a trusted device identifier in the identity profile and a network utilized to send the received message does not match a trusted network specified in the identity profile.

10. The method of claim 1 , wherein determining the security risk assessment of the received message includes determining that the received message is likely a part of a display name deception attack at least in part by determining that a sender message account of the received message does not match an entry in the identity profile but a sender display name of the received message matches an entry in the identity profile and a device identifier extracted from the received message does not match a trusted device identifier in the identity profile and a network utilized to send the received message does not match a trusted network specified in the identity profile.

11. The method of claim 1 , wherein determining the security risk assessment of the received message includes determining that the received message was sent by malware at least in part by determining that the received message was sent using automation but the identity profile does not identify the user as being trusted to send messages using automation.

12. The method of claim 1 , wherein determining the security risk assessment of the received message includes determining that the received message was sent by the user despite a network utilized to send the received message not matching a trusted network specified in the identity profile at least in part because a sender message account of the message matches an entry in the identity profile as a trusted message account and a device identifier extracted from the message matches a trusted device identifier in the identity profile.

13. The method of claim 1 , wherein performing the security action includes updating the identity profile based on the extracted information of the received message.

14. The method of claim 1 , wherein performing the security action includes adding a device identifier to the identity profile of the user based on a determination that a sufficient number of messages have been received with the device identifier from a trusted account and via a trusted network.

15. The method of claim 1 , wherein performing the security action includes adding a new message account identifier of a new account to the identity profile of the user based on a determination that a sufficient number of messages have been received from the new account specifying a trusted device identifier and a trusted network.

16. The method of claim 1 , wherein performing the security action includes modifying a display name of a sender of the message prior to allowing an intended recipient of the received message to access the received message.

17. The method of claim 1 , wherein performing the security action includes performing one or more of the following: sending a verification challenge to an alternative contact of a sender of the received message; performing additional analysis of the received message; quarantining the received message; blocking the received message; executing an executable included in the received message in a sandbox or a virtual machine; adding a warning to the received message; and moving the received message to a different folder.

18. A system, comprising:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to:

track an identity profile of a user using previous message communications of the user;

receive a message identified as potentially from the user;

identify and obtaining the identity profile of the user;

extract information from a header of the received message;

determine a security risk assessment of the received message at least in part by comparing the extracted information with one or more corresponding entries of the identity profile of the user, including by being configured to detect a change between at least a portion of the extracted information and at least one entry of the identity profile of the user and evaluate the detected change based on a likelihood-of-change probability associated with a likelihood that the at least one entry of the identity profile would change over time, wherein the likelihood-of-change probability is determined using previously detected changes over time in the previous message communications of the user including by computing a measurement of a distribution of a frequency of changes between different types of mail user agents used by the user; and

perform a security action based on the determined security risk assessment.

19. The system of claim 18 , wherein determining the security risk assessment includes determining that the user of the identity profile is likely not a sender of the received message.

20. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

tracking an identity profile of a user using previous message communications of the user;

receiving a message identified as potentially from the user;

identifying and obtaining the identity profile of the user;

extracting information from a header of the received message;

determining a security risk assessment of the received message at least in part by comparing the extracted information with one or more corresponding entries of the identity profile of the user including by detecting a change between at least a portion of the extracted information and at least one entry of the identity profile of the user and evaluating the detected change based on a likelihood-of-change probability associated with a likelihood that the at least one entry of the identity profile would change over time, wherein the likelihood-of-change probability is determined using previously detected changes over time in the previous message communications of the user including by computing a measurement of a distribution of a frequency of changes between different types of mail user agents used by the user; and

performing a security action based on the determined security risk assessment.

Assignments (7)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 57157/0206 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: AGARI DATA, INC.
Reel/Frame 073769/0945 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 57157/0265 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: AGARI DATA, INC.
Reel/Frame 073662/0811 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 10, 2021
From: AGARI DATA, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 057157/0265 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 10, 2021
From: AGARI DATA, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 057157/0206 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SECOND INVENTOR'S NAME PREVIOUSLY RECORDED AT REEL: 046375 FRAME: 0685. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 14, 2018
From: JAKOBSSON, BJORN MARKUS; WILSON, JOHN M., III
To: AGARI DATA, INC.
Reel/Frame 046822/0960 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2018
From: JAKOBSSON, BJORN MARKUS; WILSON, JOHN M.
To: AGARI DATA, INC.
Reel/Frame 046375/0685 →
Continuity (2)
Provisional Application 62490309 · Apr 26, 2017
Provisional Application 62647528 · Mar 23, 2018
Cited By (16)
US 12,218,948 US 12,223,077 US 12,231,453 US 12,250,283 US 12,255,915 US 12,284,193 US 12,309,186 US 12,309,204 US 12,335,288 US 12,401,656 US 12,438,863 US 12,470,599 US 12,500,927 US 12,531,888 US 12,537,833 US 12,556,550