IP Library Granted Patent US 11,343,276
Granted Patent B2
US 11,343,276 · App. 16/031,347 · Granted May 24, 2022

Systems and methods for discovering and alerting users of potentially hazardous messages

Inventors: Benjamin Edwards (Palm Harbor, FL); Alin Irimie (Clearwater, FL); Greg Kras (Dunedin, FL)
Assignee: KnowBe4, Inc.
H04L63/1483H04L51/12H04L51/18H04L51/22H04L63/0245H04L51/08H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,343,276
App. No.
16/031,347
Granted
May 24, 2022
Kind
B2
Abstract

This disclosure generally revolves around providing users with advance warning that a message that they have received may be suspicious. The user may not be aware of known threats, may not recognize threats in real time, or may not be aware of new threats, and therefore may unintentionally interact with a hazardous message. A security awareness system, on the other hand, is aware of known threats and may become aware of new threats more quickly than users can be trained to identify them. The system may notify the user when one of these threats are found in their messages. The disclosure further provides systems and methods for updating the security awareness training for users for new threats that appear.

Claims (29)

1. A method for determining an email is a suspected phishing email prior to displaying the email, the method comprising:

(a) intercepting, by an agent executing on a client device, an email to be displayed on a display of the client device in response to detecting a process for the email instantiated by a messaging application responsive to an action of a user, the agent comprising a plug-in to the messaging application;

(b) pausing, by the plug-in of the agent, the process prior to displaying the intercepted email;

(c) identifying, by the plug-in of the agent prior to the intercepted email being displayed, content of the intercepted email;

(d) determining, by the plug-in responsive to one or more rules of the agent prior to the intercepted email being displayed, that the content of the intercepted email has one or more attributes associated with a phishing email; and

(e) modifying, by the plug-in of the agent prior to the intercepted email being displayed, the intercepted email to provide one or more notifications to be displayed with the intercepted email to identify that the intercepted email is a suspected phishing email.

2. The method of claim 1 , wherein the one or more notifications are displayed with the intercepted email responsive to a user one of previewing or opening the email.

3. The method of claim 1 , wherein (d) further comprises applying, by the agent, the one or more rules to the content of the intercepted email.

4. The method of claim 1 , wherein (d) further comprises transmitting, by the agent, portions of the content of the intercepted email to a server to determine by the server whether the intercepted email is a suspected phishing email.

5. The method of claim 4 , further comprising receiving, by the agent from the server, an indication that the content of the intercepted email is associated with the phishing email.

6. The method of claim 5 , further comprising receiving, by the agent from the server, one of identification of or information on the one or more attributes of the content of the intercepted email associated with the phishing email.

7. The method of claim 5 , further comprising receiving, from the server, an identification of whether the portion of the content has an attribute associated with one or more phishing emails, the indication received by the server from a second server.

8. The method of claim 5 , further comprising receiving, from the server, a determination from the portion of the content of the intercepted email that a reply-to-address of the intercepted email does not correspond to a sender of the intercepted email.

9. The method of claim 1 , wherein (d) further comprises determining, by the agent, that a link in the content of the intercepted email has a number of subdomains exceeding a predetermined threshold.

10. The method of claim 1 , wherein the one or more notifications comprises one of the following: a text box between a header of the intercepted email and a body of the intercepted email, a pop-up box displaying a warning to a user or modification of one of a format or the content of the intercepted email to provide the one or more notifications.

11. A system for determining an email is a suspected phishing email prior to displaying the email, the system comprising:

an agent executing on a processor, coupled to memory, of a client device, wherein the agent comprises a plug-in to a messaging application and the plug-in is configured to:

intercept an email to be displayed on a display of the client device in response to detecting a process for the email instantiated by the messaging application responsive to an action of a user;

pause the process prior to displaying the intercepted email;

identify, prior to the intercepted email being displayed, content of the intercepted email;

determine, responsive to one or more rules of the agent prior to the intercepted email being displayed, that the content of the intercepted email has one or more attributes associated with a phishing email; and

modify, prior to the intercepted email being displayed, the intercepted email to provide one or more notifications to be displayed with the intercepted email to identify that the intercepted email is a suspected phishing email.

12. The system of claim 11 , wherein the one or more notifications are displayed with the intercepted email responsive to a user one of previewing or opening the intercepted email.

13. The system of claim 11 , wherein the agent is further configured to transmit portions of the content of the intercepted email to a server to determine by the server whether the intercepted email is a suspected phishing email.

14. The system of claim 13 , wherein the agent is further configured to receive from the server an indication that the content of the intercepted email is associated with the phishing email.

15. The system of claim 13 , wherein the agent is further configured to receive from the server one of identification of or information on the one or more attributes of the content of the intercepted email associated with the phishing email.

16. The system of claim 13 , wherein the agent is further configured to receive, from the server, an identification of whether portion of the content of the intercepted email has an attribute associated with one or more phishing emails, the indication received by the server from a second server.

17. The system of claim 11 , wherein the agent is further configured to receive, from the server, a determination from the portion of the content of the intercepted email that a reply-to-address of the intercepted email does not correspond to a sender of the intercepted email.

18. The system of claim 11 , wherein the agent is further configured to determine that a link in the content of the intercepted email has a number of subdomains exceeding a predetermined threshold.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2018
From: EDWARDS, BENJAMIN; IRIMIE, ALIN; KRAS, GREG
To: KNOWBE4, INC.
Reel/Frame 046306/0733 →
Continuity (2)
Provisional Application 62532285 · Jul 13, 2017
Related Publication 20190020682A1 · Jan 17, 2019
Cited By (1)
US 12,244,553