IP Library Granted Patent US 10,819,744
Granted Patent B1
US 10,819,744 · App. 16/253,196 · Granted Oct 27, 2020

Collaborative phishing attack detection

Inventors: Aaron Higbee (Leesburg, VA); Rohyt Belani (New York, NY); Scott Greaux (Glenmont, NY)
Assignee: Cofense Inc
H04L63/1483H04L51/22H04L63/1416H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,819,744
App. No.
16/253,196
Granted
Oct 27, 2020
Kind
B1
Abstract

Described herein are methods, network devices and machine-readable storage media for detecting whether a message is a phishing attack based on the collective responses from one or more individuals who have received that message. The individuals may flag the message as a possible phishing attack, and/or may provide a numerical ranking indicating the likelihood that the message is a possible phishing attack. As responses from different individuals may have a different degree of reliability, each response from an individual may be weighted with a corresponding trustworthiness level of that individual, in an overall determination as to whether a message is a phishing attack. A trustworthiness level of an individual may indicate a degree to which the response of that individual can be trusted and/or relied upon, and may be determined by how well that individual recognized simulated phishing attacks.

Claims (41)

1. A method for enhancing the security of a computing environment, the method comprising:

generating a simulated phishing email at a networked computing system, wherein:

the simulated phishing email comprises specified identifying header information, and wherein the specified identifying header information is stored in a header of the simulated phishing email;

the simulated phishing email is a non-malicious email that resembles a phishing attack;

the simulated phishing email includes content attempting to lure an individual into performing a target action on a computing device;

when the individual performs the target action on the computing device, performance of the target action does not compromise the computing device or personal information of the individual;

transmitting the simulated phishing email from the networked computing system over a communications network so that it can be delivered in an email account associated with a user;

providing computer-executable instructions for an email client computer program, wherein the instructions provide a user-interface element in the email client for a user interaction in the form of identifying an email received in the email account associated with the user as a suspected phishing email or a simulated phishing email;

providing computer-executable instructions for the email client computer program for receiving a user interaction with the user-interface element displayed to the user while the email received in the email account associated with the user is displayed to the user;

providing computer-executable instructions for the email client computer program for determining when the received email is the simulated phishing email generated by the networked computing system by comparing the specified identifying header information to header information of the received email, wherein when the header information of the received email matches the specified identifying header information, then the received email is indicated as the simulated phishing email generated by the networked computing system;

when the received email is determined to be the simulated phishing email generated by the networked computing system based on the comparing of the header information, then the user interaction with the user interface element causes the computer program to identify the received email in the email account associated with the user as being a simulated phishing email;

when the received email is determined to not be a simulated phishing email generated by the networked computing system based on the comparing of header information, then the user interaction with the user interface element causes the computer program to identify the received email in the email account associated with the user as being a suspected phishing email;

recording data in volatile or non-volatile computer memory indicating whether the received email was identified as a simulated phishing email; and

providing computer-executable instructions for the email client computer program, upon determining that the received email is not a simulated phishing email, causing the received email to be transmitted for analysis as to whether or not it is malicious.

2. The method of claim 1 , wherein the simulated phishing email comprises at least one embedded hyperlink or attachment.

3. The method of claim 1 , wherein the computer-executable instructions are provided for an email client of the email system, and further wherein the email client is web-based or is cloud-based.

4. The method of claim 1 , wherein the user-interface element is a graphical user-interface element comprising a button that, when selected, automatically sends a notification of the user identification to the networked computing system.

5. The method of claim 1 , wherein transmitting the received email for analysis further comprises sending the received email in its entirety.

6. The method of claim 1 , wherein the email system comprises a web-based email client, an email client installed on a remote computing device, or an email server.

7. The method of claim 1 , wherein the specified identifying header information stored in the header of the simulated phishing email functions to identify a sender.

8. A system for enhancing the security of a computing environment, the system comprising a processor and data store with computer-executable instructions for:

generating a simulated phishing email at a networked computing system, wherein:

the simulated phishing email comprises specified identifying header information, and wherein the specified identifying header information is stored in a header of the simulated phishing email;

the simulated phishing email is a non-malicious email that resembles a phishing attack;

the simulated phishing email includes content attempting to lure an individual into performing a target action on a computing device;

when the individual performs the target action on the computing device, performance of the target action does not compromise the computing device or personal information of the individual;

transmitting the simulated phishing email from the networked computing system over a communications network so that it can be delivered in an email account associated with a user;

an email client computer program with computer-executable instructions for:

a user-interface element in the email client for a user interaction in the form of identifying an email received in the email account associated with the user as a suspected phishing email or a simulated phishing email;

receiving a user interaction with the user-interface element displayed to the user while the email received in the email account associated with the user is displayed to the user;

determining when the received email is the simulated phishing email generated by the networked computing system by comparing the specified identifying header information to header information of the received email, wherein when the header information of the received email matches the specified identifying header information, then the received email is indicated as the simulated phishing email generated by the networked computing system;

when the received email is determined to be the simulated phishing email generated by the networked computing system based on the comparing of the header information, then the user interaction with the user interface element causes the computer program to identify the received email in the email account associated with the user as being a simulated phishing email;

when the received email is determined to not be a simulated phishing email generated by the networked computing system based on the comparing of header information, then the user interaction with the user interface element causes the computer program to identify the received email in the email account associated with the user as being a suspected phishing email;

recording data in volatile or non-volatile computer memory indicating whether the received email was identified as a simulated phishing email; and

upon determining that the received email is not a simulated phishing email, causing the received email to be transmitted for analysis as to whether or not it is malicious.

9. The system of claim 8 , wherein the simulated phishing email comprises at least one embedded hyperlink or attachment.

10. The system of claim 8 , wherein the computer-executable instructions are provided for an email client of the email system, and further wherein the email client is web-based or is cloud-based.

11. The system of claim 8 , wherein the user-interface element is a graphical user-interface element comprising a button that, when selected, automatically sends a notification of the user identification to the networked computing system.

12. The system of claim 8 , wherein transmitting the received email for analysis further comprises sending the received email in its entirety.

13. The system of claim 8 , wherein the email system comprises a web-based email client, an email client installed on a remote computing device, or an email server.

14. The system of claim 8 , wherein the specified identifying header information stored in the header of the simulated phishing email functions to identify a sender.

Assignments (6)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE BLUE TORCH FINANCE LLC PREVIOUSLY RECORDED ON REEL 059800 FRAME 0834. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded May 5, 2023
From: COFENSE INC.
To: BLUE TORCH FINANCE LLC
Reel/Frame 064381/0245 →
RELEASE OF SECURITY INTEREST Recorded May 6, 2022
From: ORIX GROWTH CAPITAL, LLC
To: COFENSE INC.; COFENSE BIDCO CORPORATION
Reel/Frame 059864/0955 →
SECURITY INTEREST Recorded May 3, 2022
From: COFENSE INC.
To: BLUE TORCH CAPITAL LP
Reel/Frame 059800/0834 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2022
From: GREAUX, SCOTT; BELANI, ROHYT; HIGBEE, AARON
To: PHISHME, INC.
Reel/Frame 059249/0079 →
MERGER AND CHANGE OF NAME Recorded Mar 13, 2022
From: PHISHME INC; POSEIDON MERGER SUB 2 INC; COFENSE INC
To: COFENSE INC
Reel/Frame 059249/0093 →
SECURITY INTEREST Recorded Oct 4, 2021
From: COFENSE BIDCO CORPORATION; COFENSE INC.
To: ORIX GROWTH CAPITAL, LLC, AS ADMINSTRATIVE AGENT
Reel/Frame 057692/0722 →
Continuity (8)
Continuation 15583970 · May 1, 2017
Continuation 15418709 · Jan 28, 2017
Continuation 15138188 · Apr 25, 2016
Continuation 14620245 · Feb 12, 2015
Continuation 13958480 · Aug 2, 2013
Continuation In Part 13918702 · Jun 14, 2013
Continuation In Part 13785252 · Mar 5, 2013
Continuation 13763538 · Feb 8, 2013
Cited By (1)
US 12,641,117