IP Library Granted Patent US 10,979,393
Granted Patent B2
US 10,979,393 · App. 16/214,716 · Granted Apr 13, 2021

Identity-based messaging security

Inventor: Paul Everton (Chicago, IL)
Assignee: Mimecast North America, Inc.
H04L63/0245G06F16/2379H04L51/12H04L51/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,979,393
App. No.
16/214,716
Granted
Apr 13, 2021
Kind
B2
Abstract

A system comprising email processing circuitry, web server circuitry, third-party interface circuitry, and a database, wherein the database stores information about a plurality of users. The system receives, via a network, a first email message and generates a modified first email message by insertion of a link to remotely-hosted content in the received email message. The system transmits, via a network interface, the modified first email message. The system receives, via a network, a request for the remotely-hosted content, and updates the database based on information contained in the request for the remotely-hosted content. The system receives, via a network, information about activity on a third-party system, and updates the database based on the information about activity on the third-party system. The system receives a second email message, determines an action to take on the second email message based on information in the database, and takes the action.

Claims (57)

1. A system comprising:

email processing circuitry, web server circuitry, third-party interface circuitry, and a database, wherein:

the database stores information about a plurality of users;

the email processing circuitry is operable to:

receive, via a network, a first email message;

generate a modified first email message by insertion of a link to remotely-hosted content in the received email message; and

transmit, via a network interface, the modified first email message;

the web server circuitry is operable to:

receive, via a network, a request for the remotely-hosted content; and

update the database based on information contained in the request for the remotely-hosted content;

the third-party interface circuitry is operable to:

receive, via a network, information about activity on a third-party system; and

update the database based on the information about activity on the third-party system; and

the email processing circuitry is operable to:

receive a second email message;

determine an action to take on the second email message based on information stored in the database; and

perform the determined action on the second email message.

2. The system of claim 1 , wherein the determined action comprises one or more of:

insertion of text into the body of the second email message;

deletion of the second email message;

delaying delivery of the second email message;

redirection of the second email message;

delivery of the second email message to a quarantine;

delivery of the second email message to a spam folder; and

delivery of the second email message to an inbox.

3. The system of claim 1 , wherein:

the update of the database based on information contained in the request for the remotely-hosted content comprises an update of one or more access locations associated with one or more of the plurality of users; and

the update of the database based on the information about activity on a third-party system comprises an update of one or more access locations associated with one or more of the plurality of users.

4. The system of claim 3 , wherein the determined action is based on one or more access locations associated in the database with a sender and/or recipient of the second email message.

5. The system of claim 4 , comprising notification circuitry operable to:

detect that a third-party system account associated with a sender or recipient of the second email message was accessed from a suspicious location; and

take the determined action on the second email address based on the detection that the third-party system account was accessed from a suspicious location.

6. The system of claim 3 , comprising notification generation circuitry operable to generate an alert email message based on one or more access locations associated in the database with a sender and/or recipient of the first email message.

7. The system of claim 6 , wherein the notification circuitry is operable to detect that the first email message was accessed from a suspicious location and generate the alert based on the detection.

8. The system of claim 1 , wherein:

the update of the database based on information contained in the request for the remotely-hosted content comprises an update of one or more relationships associated with one or more of the plurality of users; and

the update of the database based the information about activity on the third-party system comprises an update of one or more relationships associated with one or more of the plurality of users.

9. The system of claim 8 , wherein the determined action is based on one or more relationships associated in the database with a sender of the second email message and/or a recipient of the second email message.

10. The system of claim 9 , wherein the one or more relationships identify one or both of:

people or domains to which the sender and/or recipient of the second email message previously sent an email message; and

people or domains from which the sender and/or recipient of the second email message previously received an email message.

11. The system of claim 9 , wherein the one or more relationships identify one or both of:

people or domains to which the sender and/or recipient of the second email message previously sent a message on the third-party system; and

people or domains from which the sender and/or recipient of the second email message previously received a message on the third-party system.

12. The system of claim 8 , comprising notification generation circuitry operable to generate an alert email message based on one or more relationships associated in the database with a sender and/or a recipient of the second email message.

13. The system of claim 12 , wherein the one or more relationships identify one or both of:

people or domains to which the sender and/or recipient of the second email message previously sent an email message; and

people or domains from which the sender and/or recipient of the second email message previously received an email message.

14. The system of claim 12 , wherein the one or more relationships identify one or both of:

people or domains to which the sender and/or recipient of the second email message previously sent a message on the third-party system; and

people or domains from which the sender and/or recipient of the second email message previously received a message on the third-party system.

15. The system of claim 1 , comprising notification generation circuitry operable to:

detect, based on the information contained in the request for the remotely-hosted content and the information about activity on the third-party system, that an email account associated with one of the plurality of users and a messaging system account associated with the one of the plurality of users are or were accessed from different locations within a determined time period; and

generate an alert message in response to the detection.

16. The system of claim 1 , wherein the third-party system interface circuitry is operable to send a command to the third-party system to restrict access of one of the plurality of users on the third-party system in response to detection of suspicious activity on an email account associated with the one of the plurality of users.

17. The system of claim 1 , wherein the email processing circuitry is operable to restrict access to an email account associated with one of the plurality of users in response to receiving, via the third-party system interface, a notice of suspicious activity on a third-party system account associated with the one of the plurality of users.

18. The system of claim 1 , wherein the third-party system is a non-email messaging system.

Assignments (5)
SECURITY INTEREST Recorded May 20, 2022
From: MIMECAST NORTH AMERICA, INC.; MIMECAST SERVICES LIMITED
To: ARES CAPITAL CORPORATION
Reel/Frame 060132/0429 →
RELEASE OF SECURITY INTEREST Recorded May 19, 2022
From: JPMORGAN CHASE BANK, N.A.
To: MIMECAST SERVICES LTD.; ETORCH INC.
Reel/Frame 059962/0294 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2020
From: ETORCH, INC.
To: MIMECAST NORTH AMERICA, INC.
Reel/Frame 054709/0116 →
SECURITY AGREEMENT Recorded Oct 2, 2020
From: ETORCH INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 053970/0131 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2020
From: EVERTON, PAUL; GILLES, CHAD; MILLS, ERIC
To: ETORCH INC
Reel/Frame 052626/0558 →
Continuity (19)
Continuation In Part 15824100 · Nov 28, 2017
Continuation In Part 15872078 · Jan 16, 2018
Continuation In Part 16214716
Continuation In Part 15849806 · Dec 21, 2017
Continuation 15378259 · Dec 14, 2016
Continuation 14992194 · Jan 11, 2016
Continuation 16214716
Continuation In Part 15810695 · Nov 13, 2017
Continuation 15670169 · Aug 7, 2017
Continuation 16214716
Continuation In Part 15613343 · Jun 7, 2017
Continuation 15285797 · Oct 5, 2016
Continuation 16214716
Continuation In Part 15418275 · Jan 27, 2017
Provisional Application 62442165 · Jan 4, 2017
Provisional Application 62459863 · Feb 16, 2017
Provisional Application 62484444 · Apr 12, 2017
Provisional Application 62289219 · Jan 30, 2016
Related Publication 20200007502A1 · Jan 2, 2020