IP Library Granted Patent US 11,044,267
Granted Patent B2
US 11,044,267 · App. 16/219,284 · Granted Jun 22, 2021

Using a measure of influence of sender in determining a security risk associated with an electronic message

Inventors: Bjorn Markus Jakobsson (Portola Valley, CA); Siobhán McNamara (Mountain View, CA); Patrick Richard Peterson (San Francisco, CA); Jacob Rudee Rideout (Raleigh, NC)
Assignee: Agari Data, Inc.
H04L63/1433H04L63/123H04L63/1483H04L51/00H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,044,267
App. No.
16/219,284
Granted
Jun 22, 2021
Kind
B2
Abstract

A measure of influence of a sender entity is determined for a message receiving entity based at least in part on an analysis of previous electronic messages sent by the sender entity. An electronic message associated with the sender entity is received. The measure of influence of the sender entity is utilized to determine a security risk associated with the received electronic message.

Claims (34)

1. A method for electronic message security risk analysis, comprising:

determining a measure of influence of a sender entity for a message receiving entity based at least in part on an analysis of previous electronic messages sent by the sender entity;

receiving an electronic message associated with the sender entity;

utilizing the measure of influence of the sender entity to determine using a processor a security risk associated with the received electronic message, wherein the measure of influence is based on a numerical magnitude value quantifying a magnitude of a specific relationship role based at least in part on an organizational reporting relationship between the specific message receiving entity of the message and the specific sender entity according to an organizational reporting hierarchy and utilizing the measure of influence of the sender entity to determine the security risk associated with the received electronic message includes attributing an additional increase to the security risk of the received electronic message in response to a determination that the measure of influence based on the magnitude of the specific relationship role between the specific message receiving entity and the specific sender entity exceeds a threshold associated with the organizational reporting hierarchy; and

in response to attributing the additional increased risk to the received electronic message due to the measure of influence, triggering a security action based on the additional increased security risk, wherein the security action includes one or more of the following: sending a verification challenge to an alternative contact of the sender entity, performing additional analysis of the received electronic message, quarantining the received electronic message, blocking the received electronic message, executing an executable included in the received electronic message in a sandbox or a virtual machine, adding a warning to the received electronic message, or moving the received electronic message to a different folder.

2. The method of claim 1 , wherein the measure of influence is based at least in part on a role of the sender entity within an organization.

3. The method of claim 1 , wherein the measure of influence is based at least in part on a role of the message receiving entity within an organization.

4. The method of claim 1 , wherein the measure of influence is based at least in part on a number of electronic messages included in a volume of the previous electronic messages sent by the sender entity to the message receiving entity within a specified period of time.

5. The method of claim 1 , wherein the measure of influence is based at least in part on a number of different message recipients in a volume of the previous electronic messages sent by the sender entity.

6. The method of claim 1 , wherein the measure of influence is based at least in part on one or more identified keywords in the previous electronic messages sent by the sender entity to the message receiving entity.

7. The method of claim 1 , wherein the message receiving entity includes a plurality of individual recipients belonging to a common organization.

8. The method of claim 1 , wherein the message receiving entity is an individual message recipient, the measure of influence quantifies a determined influence of the sender entity on the individual message recipient, the measure of influence is one of a plurality of measures of influence of the sender entity, and each of the plurality of measures of influence of the sender entity corresponds to a different individual message recipient.

9. The method of claim 1 , wherein the measure of influence is based at least in part on a user provided specification of a relationship between the sender entity and the message receiving entity.

10. The method of claim 1 , wherein determining the security risk associated with the received electronic message includes scaling an impersonation risk score based on the measure of influence, and the impersonation risk score is determined including by determining whether the electronic message appears as having been sent from the sender entity but is actually sent from a source not trusted to be associated with the sender entity.

11. The method of claim 10 , wherein the electronic message appears as having been sent from the sender entity due to a similarity between a sender display name identified in the electronic message and a known display name of the sender entity.

12. The method of claim 10 , wherein the electronic message is identified as having been sent from the source not trusted to be associated with the sender entity including by determining that a sender email address identified in the electronic message is not known to be associated with the sender entity.

13. The method of claim 1 , wherein determining the security risk associated with the received electronic message includes determining whether the electronic message was sent from a message account belonging to a list of message accounts trusted to be associated with the sender entity.

14. The method of claim 13 , wherein the list of message accounts trusted to be associated with the sender entity is at least in part identified by a user.

15. The method of claim 13 , wherein the list of message accounts trusted to be associated with the sender entity is at least in part automatically identified based on the previous electronic messages sent by the sender entity.

16. The method of claim 13 , wherein the list of message accounts trusted to be associated with the sender entity is at least in part automatically identified based on an identification of a service identified as being utilized by the sender entity and known to send electronic messages on behalf of the sender entity.

17. The method of claim 1 , wherein determining the security risk includes determining a plurality of risk component scores and combining the plurality of risk component scores to determine an overall risk score of the security risk and at least one of the plurality of risk component scores is based at least in part on the measure of influence.

18. A system for electronic message security risk analysis, comprising:

a hardware processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to:

determine a measure of influence of a sender entity for a message receiving entity based at least in part on an analysis of previous electronic messages sent by the sender entity;

receive an electronic message associated with the sender entity;

utilize the measure of influence of the sender entity to determine a security risk associated with the received electronic message, wherein the measure of influence is based on a numerical magnitude value quantifying a magnitude of a specific relationship role based at least in part on an organizational reporting relationship between the specific message receiving entity of the message and the specific sender entity according to an organizational reporting hierarchy and utilizing the measure of influence of the sender entity to determine the security risk associated with the received electronic message includes attributing an additional increase to the security risk of the received electronic message in response to a determination that the measure of influence based on the magnitude of the specific relationship role between the specific message receiving entity and the specific sender entity exceeds a threshold associated with the organizational reporting hierarchy; and

in response to attributing the additional increased risk to the received electronic message due to the measure of influence, trigger a security action based on the additional increased security risk, wherein the security action includes one or more of the following: sending a verification challenge to an alternative contact of the sender entity, performing additional analysis of the received electronic message, quarantining the received electronic message, blocking the received electronic message, executing an executable included in the received electronic message in a sandbox or a virtual machine, adding a warning to the received electronic message, or moving the received electronic message to a different folder.

19. The system of claim 18 , wherein the message receiving entity is an individual message recipient, the measure of influence quantifies a determined influence of the sender entity on the individual message recipient, the measure of influence is one of a plurality of measures of influence of the sender entity, and each of the plurality of measures of influence of the sender entity corresponds to a different individual message recipient.

20. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium for electronic message security risk analysis and comprising computer instructions for:

determining a measure of influence of a sender entity for a message receiving entity based at least in part on an analysis of previous electronic messages sent by the sender entity;

receiving an electronic message associated with the sender entity;

utilizing the measure of influence of the sender entity to determine a security risk associated with the received electronic message, wherein the measure of influence is based on a numerical magnitude value quantifying a magnitude of a specific relationship role based at least in part on an organizational reporting relationship between the specific message receiving entity of the message and the specific sender entity according to an organizational reporting hierarchy and utilizing the measure of influence of the sender entity to determine the security risk associated with the received electronic message includes attributing an additional increase to the security risk of the received electronic message in response to a determination that the measure of influence based on the magnitude of the specific relationship role between the specific message receiving entity and the specific sender entity exceeds a threshold associated with the organizational reporting hierarchy; and

in response to attributing the additional increased risk to the received electronic message due to the measure of influence, triggering a security action based on the additional increased security risk, wherein the security action includes one or more of the following: sending a verification challenge to an alternative contact of the sender entity, performing additional analysis of the received electronic message, quarantining the received electronic message, blocking the received electronic message, executing an executable included in the received electronic message in a sandbox or a virtual machine, adding a warning to the received electronic message, or moving the received electronic message to a different folder.

Assignments (6)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 57157/0206 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: AGARI DATA, INC.
Reel/Frame 073769/0945 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 57157/0265 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: AGARI DATA, INC.
Reel/Frame 073662/0811 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 10, 2021
From: AGARI DATA, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 057157/0206 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 10, 2021
From: AGARI DATA, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 057157/0265 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2019
From: JAKOBSSON, BJORN MARKUS; MCNAMARA, SIOBHÁN; PETERSON, PATRICK RICHARD; RIDEOUT, JACOB RUDEE
To: AGARI DATA, INC.
Reel/Frame 048590/0390 →
Continuity (5)
Continuation In Part 15823196 · Nov 27, 2017
Provisional Application 62428328 · Nov 30, 2016
Provisional Application 62490309 · Apr 26, 2017
Provisional Application 62599475 · Dec 15, 2017
Related Publication 20190199745A1 · Jun 27, 2019
Cited By (34)
US 50,335 US 12,200,132 US 12,212,584 US 12,212,596 US 12,223,455 US 12,248,545 US 12,270,915 US 12,273,383 US 12,284,172 US 12,299,093 US 12,301,558 US 12,309,190 US 12,333,250 US 12,339,832 US 12,347,095 US 12,348,471 US 12,352,869 US 12,355,789 US 12,381,904 US 12,401,650 US 12,438,863 US 12,443,748 US 12,452,826 US 12,470,552 US 12,499,209 US 12,519,806 US 12,519,815 US 12,568,114 US 12,579,260 US 12,591,667 US 12,609,966 US 12,613,971 US 12,627,708 US 12,641,117