IP Library Granted Patent US 11,356,482
Granted Patent B2
US 11,356,482 · App. 16/201,977 · Granted Jun 7, 2022

Message validation using machine-learned user models

Inventors: Chetan Anand (Mountain View, CA); Arjun Sambamoorthy (Mountain View, CA); Anand Raghavan (Cupertino, CA); Dhananjay Sampath (Sunnyvale, CA)
Assignee: ArmorBlox, Inc.
H04L63/20G06F16/27G06N20/00H04L51/046H04L51/12H04L63/102H04L63/123H04L63/126H04L67/10H04L63/168H04L67/02H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,356,482
App. No.
16/201,977
Granted
Jun 7, 2022
Kind
B2
Abstract

A cloud security service receives an electronic message sent by a purported sending user to a receiving user. The cloud security service retrieves a user model and a user identity associated with the purported sending user, the user identity including a set of feature values describing messages from the purported sending user. The cloud security service applies the user model to the received electronic message to identify a set of feature values describing the electronic message. The cloud security service compares the set of feature values describing the electronic message to the set of feature values describing messages from the purported sending user included in the user identity. The cloud security service determines, based on the comparison, whether the received electronic message was sent by the purported sending user. The cloud security service performs a security action based on the determination.

Claims (83)

1. A method of providing network security, comprising:

receiving, via a computer network, a target electronic message sent by a purported sending user to a receiving user;

retrieving, from a remote data store, a user identity associated with the purported sending user and comprising a verification set of feature values describing electronic messages previously sent by the purported sending user;

retrieving, from the remote data store, a user model comprising a machine- learned model for evaluating electronic messages for a set of prominent features of the purported sending user and trained with electronic messages previously sent by the purported sending user to the receiving user, the set of prominent features characterized by feature values, for the purported user, differing from average feature values, for a user population, by more than a threshold value;

applying the user model to the target electronic message to identify a target set of feature values describing the target electronic message;

detecting a difference between the target set of feature values} describing the target electronic message, and the verification set of feature values, contained in the user identity and describing electronic messages previously sent by the purported sending user; and

based on the difference:

predicting transmission of the target electronic message by a user different from the purported sending user; and

performing a security action responsive to the target electronic message.

2. The method of claim 1 , further comprising:

training the machine-learned model based on electronic messages previously sent by the purported sending user to the receiving user;

storing the machine-learned mode;

generating the user identity, associated with the purported sending user, according to the generated user model; and

storing the user model and the user identity in the remote data store accessible by a receiving enterprise associated with the receiving user.

3. The method of claim 1 , further comprising:

obfuscating the set of verification feature values with a feature map to create a set of obfuscated features; and

populating the user identity with the set of obfuscated features representing the set of verification features.

4. The method of claim 1 :

further comprising, by a sending enterprise associated with the sending user, storing the user model and the user identity on a distributed ledger; and

wherein retrieving the user model and retrieving the user identity comprises,

by the receiving enterprise, retrieving the user model and user identity from the distributed ledger.

5. The method of claim 1 , wherein retrieving the user model and retrieving the user identity comprises, a receiving enterprise associated with the receiving user, decrypting the user model and the user identity with a digital key associated with a sending enterprise associated with the sending user.

6. The method of claim 1 , wherein performing the security action comprises blocking the electronic message from reaching the receiving user.

7. The method of claim 1 , wherein performing the security action comprises:

reporting receipt of the electronic message, not sent by the purported sending user, to an administrator of a receiving enterprise associated with the receiving user;

receiving a selection of the security action for the electronic message from the administrator; and

performing the security action in response to receiving the selection from the administrator.

8. The system of claim 1 , further comprising:

accessing electronic messages previously sent by the sending user;

detecting the set of prominent features, representative and distinctive of communication behavior of the sending user, in electronic messages previously sent by the sending user to the receiving user; and

applying a privacy-preserving one-way hash to the set of prominent features to generate the user identity for the sending user.

9. The system of claim 1 , further comprising:

accessing electronic messages previously sent by the sending user;

detecting a first feature value, of a first feature type, differing from a first average value of the first feature type for the user population, by greater than the threshold value;

storing the first feature value, of the first feature type, in the set of prominent features for the sending user; and

representing the set of prominent features in the user identity for the sending user.

10. A non-transitory computer-readable storage medium storing computer program instructions executable by a processor to perform operations for providing network security, the operations comprising:

receiving, via a computer network, a target electronic message sent by a purported sending user to a receiving user;

retrieving, from a remote data store, a user identity associated with the purported sending user and comprising a verification set of feature values describing electronic messages previously sent by the purported sending user;

retrieving, from the remote data store, a user model comprising a machine-learned model for evaluating electronic messages for a set of prominent features of the purported sending user and trained with electronic messages previously sent by the purported sending user to the receiving user, the set of prominent features characterized by feature values, for the purported user, differing from average feature values, for a user population, by more than a threshold value;

applying the user model to the target electronic message to identify a target set of feature values describing the target electronic message;

detecting a difference between the target set of feature values} describing the target electronic message, and the verification set of feature values, contained in the user identity and describing electronic messages previously sent by the purported sending user; and

based on the difference:

predicting transmission of the target electronic message by a user different from the purported sending user; and

performing a security action responsive to the target electronic message.

11. The non-transitory computer-readable storage medium of claim 10 , further comprising:

training the machine-learned model based on electronic messages previously sent by the purported sending user to the receiving user;

storing the machine-learned mode;

generating the user identity, associated with the purported sending user, according to the generated user model; and

storing the user model and the user identity in the remote data store accessible by a receiving enterprise associated with the receiving user.

12. The non-transitory computer-readable storage medium of claim 10 , further comprising:

obfuscating the set of verification feature values with a feature map to create a set of obfuscated features; and

populating the user identity with the set of obfuscated features representing the set of verification features.

13. The non-transitory computer-readable storage medium of claim 10 :

further comprising, by a sending enterprise associated with the sending user, storing the user model and the user identity on a distributed ledger; and

wherein retrieving the user model and retrieving the user identity comprises, by the receiving enterprise, retrieving the user model and user identity from the distributed ledger.

14. The non-transitory computer-readable storage medium of claim 10 , wherein retrieving the user model and retrieving the user identity comprises, by a receiving enterprise associated with the receiving user, decrypting the user model and the user identity with a digital key associated with a sending enterprise associated with the sending user.

15. The non-transitory computer-readable storage medium of claim 10 , wherein performing the security action comprises:

reporting receipt of the electronic message, not sent by the purported sending user, to an administrator of a receiving enterprise associated with the receiving user;

receiving a selection of the security action for the electronic message from the administrator; and

performing the security action in response to receiving the selection from the administrator.

16. A system, comprising:

a processor for executing computer program instructions; and

a non-transitory computer-readable storage medium storing computer program instructions executable by the processor to perform operations for providing network security, the operations comprising:

receiving, via a computer network, a target electronic message sent by a purported sending user to a receiving user;

retrieving, from a remote data store, a user identity associated with the purported sending user and comprising a verification set of feature values describing electronic messages previously sent by the purported sending user;

retrieving, from the remote data store, a user model comprising a machine- learned model for evaluating electronic messages for a set of prominent features of the purported sending user and trained with electronic messages previously sent by the purported sending user to the receiving user, the set of prominent features characterized by feature values, for the purported user, differing from average feature values, for a user population, by more than a threshold value;

applying the user model to the target electronic message to identify a target set of feature values describing the target electronic message;

detecting a difference between the target set of feature values} describing the target electronic message, and the verification set of feature values, contained in the user identity and describing electronic messages previously sent by the purported sending user; and

based on the difference:

predicting transmission of the target electronic message by a user different from the purported sending user; and

performing a security action responsive to the target electronic message.

17. The system of claim 16 , further comprising:

training the machine-learned model based on electronic messages previously sent by the purported sending user to the receiving user;

storing the machine-learned mode; generating the user identity, associated with the purported sending user, according to the generated user model; and

storing the user model and the user identity in the remote data store accessible by a receiving enterprise associated with the receiving user.

18. The system of claim 16 , further comprising:

obfuscating the set of verification feature values with a feature map to create a set of obfuscated features; and

populating the user identity with the set of obfuscated features representing the set of verification features.

19. The system of claim 16 :

further comprising, by a sending enterprise associated with the sending user, storing the user model and the user identity on a distributed ledger; and

wherein retrieving the user model and retrieving the user identity comprises, by the receiving enterprise, retrieving the user model and user identity from the distributed ledger.

20. The system of claim 16 , wherein retrieving the user model and retrieving the user identity comprises, by a receiving enterprise associated with the receiving user, decrypting the user model and the user identity with a digital key associated with a sending enterprise associated with the sending user.

Assignments (2)
CHANGE OF NAME Recorded Oct 13, 2023
From: ARMORBLOX, INC.
To: ARMORBLOX LLC
Reel/Frame 065238/0215 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2020
From: ANAND, CHETAN; SAMBAMOORTHY, ARJUN; RAGHAVAN, ANAND; SAMPATH, DHANANJAY
To: ARMORBLOX, INC.
Reel/Frame 051472/0265 →
Continuity (2)
Provisional Application 62591150 · Nov 27, 2017
Related Publication 20190166162A1 · May 30, 2019