IP Library Granted Patent US 11,995,541
Granted Patent B2
US 11,995,541 · App. 16/271,013 · Granted May 28, 2024

Systems and methods for location threat monitoring

Inventors: Harold Nguyen (San Carlos, CA); Michael Lee (Aptos, CA); Daniel Oshiro Nadir (Carlsbad, CA)
Assignee: PROOFPOINT, INC.
G06N3/08G06F40/30G06N5/04G06N7/01G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,995,541
App. No.
16/271,013
Granted
May 28, 2024
Kind
B2
Abstract

Disclosed is a new location threat monitoring solution that leverages deep learning (DL) to process data from data sources on the Internet, including social media and the dark web. Data containing textual information relating to a brand is fed to a DL model having a DL neural network trained to recognize or infer whether a piece of natural language input data from a data source references an address or location of interest to the brand, regardless of whether the piece of natural language input data actually contains the address or location. A DL module can determine, based on an outcome from the neural network, whether the data is to be classified for potential location threats. If so, the data is provided to location threat classifiers for identifying a location threat with respect to the address or location referenced in the data from the data source.

Claims (59)

1. A method, comprising:

obtaining or receiving, from a data source, first data containing textual information relating to an address, the obtaining or receiving performed by a location threat monitoring system operating on a computer, the location threat monitoring system configured to detect potential threats relating to addresses or locations of interest to the brand;

obtaining or receiving, from the data source, concurrently with the first data, second data containing textual information relating to a brand, the obtaining or receiving performed by the location threat monitoring system;

providing the textual information relating to the brand to a deep learning (DL) model specifically trained and tuned to analyze input data from the data source, the DL model comprising an artificial neural network (ANN), wherein the ANN is trained, through supervised learning using sample data sets from the data source, to determine a likelihood that a piece of natural language input data from the data source relates to an address or location of interest to the brand, regardless of whether the piece of natural language input data actually contains the address or location, wherein the data from the data source has no specific address or location;

determining, by the location threat monitoring system, whether the first data from the data source is to be classified for potential location threats;

determining, by the location threat monitoring system, by comparing an outcome from the ANN with a threshold, whether the second data from the data source is to be classified for potential location threats, the outcome from the ANN comprising the probability score that the data from the data source references an address or location of interest to the brand;

responsive to the first data being classified for potential location threats, providing the first data from the data source to location threat classifiers, wherein the location threat classifiers are operable to identify location threats with respect to any address or location relating to an address or location of interest to the brand; and

responsive to the probability score from the ANN meeting or exceeding the threshold, concurrently with the first data being provided to the location threat classifiers, providing the second data from the data source to the location threat classifiers, wherein the location threat classifiers are operable to identify location threats with respect to any address or location relating to an address or location of interest to the brand.

2. The method according to claim 1 , further comprising:

receiving, over a network from a user device communicatively connected to the location threat monitoring system, a request for brand protection, the request containing a label, a name, a domain, or a search term for the brand.

3. The method according to claim 1 , wherein the data from the data source is pushed to the location threat monitoring system or pulled by the location threat monitoring system on demand or on a periodic basis.

4. The method according to claim 1 , wherein the ANN comprises a deep NN (DNN) or a recurrent neural NN (RNN).

5. The method according to claim 1 , further comprising:

preparing the data from the data source as input to the ANN; or

preparing the data from the data source as input to the location threat classifiers.

6. The method according to claim 1 , wherein each of the location threat classifiers comprises a natural language processing (NLP) model specially trained to identify a type of location threat.

7. A location threat monitoring system configured to detect potential threats relating to addresses or locations of interest to brands, comprising:

a processor;

a non-transitory computer-readable medium; and

stored instructions translatable by the processor for:

obtaining or receiving, from a data source, first data containing textual information relating to an address;

obtaining or receiving, from the data source, concurrently with the first data, second data containing textual information relating to a brand;

providing the textual information relating to the brand to a deep learning (DL) model specifically trained and tuned to analyze input data from the data source, the DL model comprising an artificial neural network (ANN), wherein the ANN is trained, through supervised learning using sample data sets from the data source, to determine a likelihood that a piece of natural language input data from the data source relates to an address or location of interest to the brand, regardless of whether the piece of natural language input data actually contains the address or location, wherein the data from the data source has no specific address or location;

determining, by a location threat monitoring system, whether the first data from the data source is to be classified for potential location threats;

determining, by the location threat monitoring system, by comparing an outcome from the ANN with a threshold, whether the second data from the data source is to be classified for potential location threats, the outcome from the ANN comprising the probability score that the data from the data source references an address or location of interest to the brand;

responsive to the first data being classified for potential location threats, providing the first data from the data source to location threat classifiers, wherein the location threat classifiers are operable to identify location threats with respect to any address or location relating to an address or location of interest to the brand; and

responsive to the probability score from the ANN meeting or exceeding the threshold, concurrently with the first data being provided to the location threat classifiers, providing the second data from the data source to the location threat classifiers, wherein the location threat classifiers are operable to identify location threats with respect to any address or location relating to an address or location of interest to the brand.

8. The location threat monitoring system of claim 7 , wherein the stored instructions are further translatable by the processor for:

receiving, over a network from a user device communicatively connected to the location threat monitoring system, a request for brand protection, the request containing a label, a name, a domain, or a search term for the brand.

9. The location threat monitoring system of claim 7 , wherein the data from the data source is pushed to the location threat monitoring system or pulled by the location threat monitoring system on demand or on a periodic basis.

10. The location threat monitoring system of claim 7 , wherein the ANN comprises a deep NN (DNN) or a recurrent neural NN (RNN).

11. The location threat monitoring system of claim 7 , wherein the stored instructions are further translatable by the processor for:

preparing the data from the data source as input to the ANN; or

preparing the data from the data source as input to the location threat classifiers.

12. The location threat monitoring system of claim 7 , wherein each of the location threat classifiers comprises a natural language processing (NLP) model specially trained to identify a type of location threat.

13. A computer program product for location threat monitoring, the computer program product comprising a non-transitory computer-readable medium storing instructions translatable by a processor for:

obtaining or receiving, from a data source, first data containing textual information relating to an address;

obtaining or receiving, from the data source, concurrently with the first data, second data containing textual information relating to a brand;

providing the textual information relating to the brand to a deep learning (DL) model specifically trained and tuned to analyze input data from the data source, the DL model comprising an artificial neural network (ANN), wherein the ANN is trained, through supervised learning using sample data sets from the data source, to determine a likelihood that a piece of natural language input data from the data source relates to an address or location of interest to the brand, regardless of whether the piece of natural language input data actually contains the address or location, wherein the data from the data source has no specific address or location;

determining, by a location threat monitoring system, whether the first data from the data source is to be classified for potential location threats;

determining, by the location threat monitoring system configured to detect potential threats relating to addresses or locations of interest to the brand, by comparing an outcome from the ANN with a threshold, whether the second data from the data source is to be classified for potential location threats, the outcome from the ANN comprising the probability score that the data from the data source references an address or location of interest to the brand;

responsive to the first data being classified for potential location threats, providing the first data from the data source to location threat classifiers, wherein the location threat classifiers are operable to identify location threats with respect to any address or location relating to an address or location of interest to the brand; and

responsive to the probability score from the ANN meeting or exceeding the threshold, concurrently with the first data being provided to the location threat classifiers, providing the second data from the data source to the location threat classifiers, wherein the location threat classifiers are operable to identify location threats with respect to any address or location relating to an address or location of interest to the brand.

14. The computer program product of claim 13 , wherein the instructions are further translatable by the processor for:

receiving, over a network from a user device, a request for brand protection, the request containing a label, a name, a domain, or a search term for the brand.

15. The computer program product of claim 13 , wherein the data from the data source is pushed to the location threat monitoring system or pulled by the location threat monitoring system on demand or on a periodic basis.

16. The computer program product of claim 13 , wherein the ANN comprises a deep NN (DNN) or a recurrent neural NN (RNN).

17. The computer program product of claim 13 , wherein the instructions are further translatable by the processor for:

preparing the data from the data source as input to the ANN; or

preparing the data from the data source as input to the location threat classifiers.

18. The method according to claim 1 , further comprising:

responsive to identifying a location threat with respect to an address or location relating to an address or location of interest to the brand, generating an alert; and

communicating the alert to a client device.

19. The location threat monitoring system of claim 7 , further comprising:

responsive to identifying a location threat with respect to an address or location relating to an address or location of interest to the brand, generating an alert; and

communicating the alert to a client device.

20. The computer program product of claim 13 , further comprising:

responsive to identifying a location threat with respect to an address or location relating to an address or location of interest to the brand, generating an alert; and

communicating the alert to a client device.

Assignments (6)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Mar 21, 2024
From: GOLDMAN SACHS BANK USA, AS AGENT
To: PROOFPOINT, INC.
Reel/Frame 066865/0648 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0615 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0642 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY PREVIOUSLY RECORDED AT REEL: 048279 FRAME: 0467. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 25, 2019
From: NGUYEN, HAROLD; LEE, MICHAEL; NADIR, DANIEL OSHIRO
To: PROOFPOINT, INC.
Reel/Frame 048422/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2019
From: NGUYEN, HAROLD; NGUYEN, MICHAEL; NADIR, DANIEL OSHIRO
To: PROOFPOINT, INC.
Reel/Frame 048279/0467 →