IP Library Granted Patent US 11,146,575
Granted Patent B2
US 11,146,575 · App. 16/532,449 · Granted Oct 12, 2021

Suspicious message report processing and threat response

Inventors: Aaron Higbee (Leesburg, VA); Rohyt Belani (New York, NY); Scott Greaux (Glenmont, NY); William Galway (Scotch Plains, NJ); Douglas Hagen (Amherst, NY)
Assignee: Cofense Inc
H04L63/1416G06F16/35G06F21/00G06F21/554H04L51/12H04L63/1433H04L63/1483H04L63/1491H04L63/20H04L51/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,146,575
App. No.
16/532,449
Granted
Oct 12, 2021
Kind
B2
Abstract

The present invention relates to methods, network devices, and machine-readable media for an integrated environment for automated processing of reports of suspicious messages, and furthermore, to a network for distributing information about detected phishing attacks.

Claims (28)

1. A computerized method for suspicious message processing and incident response, comprising: providing computer-executable instructions for a messaging client, the computer-executable instructions for: receiving a user interface action by a user indicating that a message delivered in an account associated with an individual has been identified by the user as a potential security threat; determining whether the delivered message is a known simulated phishing attack based on an identifier or other message characteristic of the delivered message; if the delivered message is determined to be a known simulated phishing attack based upon the identifier or other message characteristic of the delivered message, then providing a graphically displayed feedback confirming that the delivered message was a simulated phishing attack; and if the delivered message is determined not to be a known simulated phishing attack based upon the identifier or other message characteristic of the delivered message, then transmitting a copy of the delivered message to a detection platform; providing computer-executable instructions for a threat detection platform, the computer-executable instructions for: receiving the transmitted copy of the message at the threat detection platform; electronically storing a pattern as a rule for determining whether a body of the received message or an attachment of the received message contains a defined textual or binary pattern associated with a security threat; processing the received message according to the electronically stored rule to determine whether the body of the received message or an attachment of the received message contains the defined textual or binary pattern associated with the security threat; assigning a further processing action to the received message based upon the determination of whether the received message contains the defined textual or binary pattern; associating the received message with a message group, the message group being defined by having at least the defined textual or binary pattern in common with the received message; displaying a graphical representation of the message group, each of the group of messages displayed having been determined not to be a known simulated phishing attack based on the identifier or other message characteristic of the delivered message; and further comprising removing one or more previously delivered messages from messaging accounts associated with multiple users based on a matching of at least a portion of header information of the delivered message or at least a portion of metadata of the delivered message with the one or more previously delivered messages from the messaging accounts associated with the multiple users.

2. The method of claim 1 , further comprising enabling access to a message server for removing messages from messaging accounts associated with multiple users.

3. The method of claim 2 , further comprising generating a command to remove the received message from a user inbox.

4. The method of claim 1 , further comprising executing a remedial action on a network device based on the comparison of the delivered message against stored rules for determining whether message or attachment data contains a pre-defined textual or a pre-defined binary pattern.

5. The method of claim 1 , further comprising configuring an inbound mail sever to generate a command to remove one or more messages to render the delivered message inaccessible to the user.

6. The method of claim 1 , further comprising performing an operation on one or more messages in the message group, wherein the operation comprises one of deleting the message from a user inbox, quarantining the message from a user inbox, classifying the message, and responding to the message.

7. The method of claim 1 , wherein each message group is displayed as an active link which, when selected, displays additional information about the selected message group.

8. The method of claim 1 , wherein the delivered message is classified as malicious if the delivered message is assigned to a message group having a threshold number of messages.

9. The method of claim 1 , wherein the delivered message is classified as non-malicious based on a determination that the message group to which the delivered message is assigned is non-malicious.

10. The method of claim 1 , further comprising executing an integration, wherein the integration comprises one or more of opening a link contained in the delivered message data in a simulated environment, opening attachment data in a simulated environment, and scanning the delivered message for malicious content, and querying a database of known threat activity with data extracted from the delivered message.

11. The method of claim 1 , wherein at least a portion of a message body of the delivered message or at least a portion of header information of the delivered message or at least a portion of metadata of the delivered message is communicated for threat processing.

12. The method of claim 1 , further comprising providing an interface for creating a set of executable instructions based on at least one characteristic of at least one message from a corresponding message group.

13. The method of claim 1 , further comprising providing an interface for specifying one or more rules for automatically responding to a notification by a pre-configured response message.

14. The method of claim 1 , wherein if the delivered message is determined to be a known simulated phishing attack, providing feedback to the individual confirming that the delivered message was a simulated phishing attack.

15. The method of claim 1 , further comprising: labeling as suspicious messages that are not cleared by initial rules pattern matching processing; and grouping the messages labeled as suspicious in a group of suspicious messages.

16. The method of claim 1 , further comprising automatically responding to a user with a message indicating that the delivered message is legitimate, and removing the delivered message from display in a management console.

17. The method of claim 1 , wherein the at least one characteristic in common with the delivered message includes a domain of a Uniform Resource Locator in the body of the received message or a hash of an attachment to received message.

18. A computerized system for suspicious message processing and incident response, comprising: a processor configured for executing instructions at a messaging client, the computer-executable instructions for: receiving a user interface action by a user indicating that a message delivered in an account associated with an individual has been identified by the user as a potential security threat; determining whether the delivered message is a known simulated phishing attack based on an identifier or other message characteristic of the delivered message; if the delivered message is determined to be a known simulated phishing attack based upon the identifier or other message characteristic of the delivered message, then providing a graphically feedback confirming that the delivered message was a simulated phishing attack; and if the delivered message is determined not to be a known simulated phishing attack based upon the identifier or other message characteristic of the delivered message, then transmitting a copy of the delivered message to a detection platform; a processor configured for executing instructions at a threat detection platform, the computer-executable instructions for: receiving the transmitted copy of the message at the threat detection platform; electronically storing a pattern as a rule for determining whether a body of the received message or an attachment of the received message contains a defined textual or binary pattern associated with a security threat; processing the received message according to the electronically stored rule to determine whether the body of the received message or an attachment of the received message contains the defined textual or binary pattern associated with a security threat; assigning a further processing action to the received message based upon the determination of whether the received message contains the defined textual or binary pattern; associating the received message with a message group, the group being defined by having at least the defined textual or binary pattern in common with the received message; displaying a graphical representation of the message group, each of the group of messages displayed having been determined not to be a known simulated phishing attack based on the identifier or other message characteristic of the delivered message; and further comprising removing one or more previously delivered messages from messaging accounts associated with multiple users based on a matching of at least a portion of header information of the delivered message or at least a portion of metadata of the delivered message with the one or more previously delivered messages from the messaging accounts associated with the multiple users.

19. The system of claim 18 , further comprising enabling access to a message server for removing messages from messaging accounts associated with multiple users.

20. The system of claim 19 , further comprising generating a command to remove the received message from a user inbox.

21. The system of claim 18 , further comprising executing a remedial action on a network device based on the comparison of the delivered message against stored rules for determining whether message or attachment data contains a pre-defined textual or a pre-defined binary pattern.

22. The system of claim 18 , further comprising configuring an inbound mail sever to generate a command to remove one or more messages to render the delivered message inaccessible to the user.

23. The system of claim 18 , further comprising performing an operation on one or more messages in the message group, wherein the operation comprises one of deleting the message from a user inbox, quarantining the message from a user inbox, classifying the message, and responding to the message.

24. The system of claim 18 , wherein each message group is displayed as an active link which, when selected, displays additional information about the selected message group.

25. The system of claim 18 , wherein the delivered message is classified as malicious if the delivered message is assigned to a message group having a threshold number of messages.

26. The system of claim 18 , wherein the delivered message is classified as non-malicious based on a determination that the message group to which the delivered message is assigned is non-malicious.

27. The system of claim 18 , further comprising executing an integration, wherein the integration comprises one or more of opening a link contained in the delivered message data in a simulated environment, opening attachment data in a simulated environment, and scanning the delivered message for malicious content, and querying a database of known threat activity with data extracted from the delivered message.

28. The system of claim 18 , wherein at least a portion of a message body of the delivered message or at least a portion of header information of the delivered message or at least a portion of metadata of the delivered message is communicated for threat processing.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE NEWLY MERGED ENTITY'S NEW NAME PREVIOUSLY RECORDED AT REEL: 059248 FRAME: 0921. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 7, 2023
From: PHISHME INC; POSEIDON MERGER SUB 2 INC
To: COFENSE INC
Reel/Frame 063888/0606 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE BLUE TORCH FINANCE LLC PREVIOUSLY RECORDED ON REEL 059800 FRAME 0834. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded May 5, 2023
From: COFENSE INC.
To: BLUE TORCH FINANCE LLC
Reel/Frame 064381/0245 →
RELEASE OF SECURITY INTEREST Recorded May 6, 2022
From: ORIX GROWTH CAPITAL, LLC
To: COFENSE INC.; COFENSE BIDCO CORPORATION
Reel/Frame 059864/0955 →
SECURITY INTEREST Recorded May 3, 2022
From: COFENSE INC.
To: BLUE TORCH CAPITAL LP
Reel/Frame 059800/0834 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2022
From: HIGBEE, AARON; BELANI, ROHYT; GREAUX, SCOTT; GALWAY, WILLIAM; HAGEN, DOUGLAS
To: PHISHME INC
Reel/Frame 059248/0904 →
MERGER AND CHANGE OF NAME Recorded Mar 13, 2022
From: PHISHME INC; POSEIDON MERGER SUB 2 INC; COFENSE INC
To: 02/23/2018
Reel/Frame 059248/0921 →
SECURITY INTEREST Recorded Oct 4, 2021
From: COFENSE BIDCO CORPORATION; COFENSE INC.
To: ORIX GROWTH CAPITAL, LLC, AS ADMINSTRATIVE AGENT
Reel/Frame 057692/0722 →
Continuity (6)
Continuation 16418973 · May 21, 2019
Continuation 15905784 · Feb 26, 2018
Continuation In Part 15584002 · May 1, 2017
Continuation 14986515 · Dec 31, 2015
Provisional Application 62145778 · Apr 10, 2015
Related Publication 20190364061A1 · Nov 28, 2019
Cited By (2)
US 12,244,553 US 12,328,324