IP Library Granted Patent US 12,438,909
Granted Patent B2
US 12,438,909 · App. 16/727,480 · Granted Oct 7, 2025

Systems and methods for threat detection and warning

Inventors: Simon Paul Tyler (Wiltshire, GB); Steven Malone (Berkshire, GB); Jackie Anne Maylor (Wiltshire, GB); Wayne Van Ry (London, GB); Francisco Ribeiro (London, GB); Reinhard Uebel (Melbourne, AU)
Assignee: Mimecast Services Ltd.
H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,909
App. No.
16/727,480
Granted
Oct 7, 2025
Kind
B2
Abstract

The present disclosure relates generally to computer security, and, more particularly, to systems and methods for assisting a user in avoiding the accidental disclosure of confidential or sensitive information, as well as avoiding potential security breaches, including phishing and impersonation, malware, and security issues, particularly with respect to websites and electronic communications.

Claims (29)

1. A system for proactively providing a user with security-related information associated with content on a computing device prior to user interaction with such content, the system comprising:

a processor coupled to a non-transitory memory containing instructions executable by the processor to cause the system to:

present content on a user interface of the computing device for browsing by the user, the content including a link to an information resource;

analyze the content including monitoring the information resource and analyzing the information resource to account for changes to the information resource occurring after the content has been presented on the user interface of the computing device for browsing by the user but prior to user interaction with such content to determine whether at least one of (a) the content or the changes to the information resource requires disclosure of information or (b) the content or the changes to the information resource poses a security threat; and

based, at least in part, on the analysis, at least one of (a) output to the user, prior to user interaction with the content, security-related information associated with the content or the changes to the information resource based, at least in part, on the analysis or (b) prevent, prior to user interaction with the content, user interaction with the content.

2. The system of claim 1 , wherein outputting the security-related information comprises transmitting a signal to the computing device, or to a secondary computing device associated with the user, resulting in the computing device or secondary computing device outputting an alert comprising at least one of a physical indication, an audible indication, and a visual indication of whether the content or the information resource poses a security threat.

3. The system of claim 2 , wherein the visual indication comprises at least one of a notification, icon, pop-up warning, and modification of one or more visual aspects of the content displayed on a user interface of the computing device, a remote computing device, or a secondary remote computing device.

4. The system of claim 3 , wherein the visual indication comprises at least one of an image, graphic, object, text or color indicating whether the content is safe or unsafe for subsequent user interaction.

5. The system of claim 1 , wherein the security-related information comprises a safety assessment of the content.

6. The system of claim 5 , wherein the safety assessment comprises an indication of whether the content is safe or potentially harmful if the user interacts with such content with regard to a security standpoint.

7. The system of claim 5 , wherein the safety assessment comprises a recommended action that the user take with regard to the content.

8. The system of claim 5 , wherein the safety assessment comprises an indication whether the content contains a virus, malware, a cyberattack mechanism including phishing, or a combination thereof.

9. The system of claim 5 , wherein the safety assessment comprises an indication whether a claimed provenance or authorship of the content appears to be valid.

10. The system of claim 1 , wherein the content is associated with at least one of a software application, operating system, website, email, instant message, text message, and telecommunication.

11. The system of claim 1 , wherein the analysis of the content comprises identifying one or more content elements in addition to the link to the information resource and determining whether the one or more content elements pose a security threat.

12. The system of claim 11 , wherein the one or more content elements comprises a link, an icon, an attachment, or other visual representation of an information resource.

13. The system of claim 12 , wherein the visual representation is an email address or a link associated with a domain.

14. The system of claim 1 , wherein the analysis comprises a correlation of data associated with the content to a set of data associated with trusted content and flagging the content as being legitimate and safe or flagging the content as being illegitimate and unsafe based on the correlation.

15. The system of claim 14 , wherein the content is flagged as being legitimate and safe based on a positive correlation and the content is flagged as being illegitimate and unsafe based on a negative correlation.

16. The system of claim 14 , wherein the content data and the trusted content data comprises at least one of domain name(s), Uniform Resource Locator(s) (URL), Uniform Resource Identifier(s) (URIs), Internet Protocol addresses, HTML structure, webpage resources, including images, and a combination thereof.

17. The system of claim 16 , wherein the analysis comprises a graphical comparison comprising either a full comparison or a partial comparison of a screen image of the content to a screen image of trusted content and the flagging of the content is based, at least in part, on the graphical comparison.

18. The system of claim 17 , wherein the analysis comprises determining a suspicion score based on the correlation, wherein the suspicion score is a similarity metric determined based on a degree of similarity between a display representation of the content and a display representation of the trusted content.

19. The system of claim 1 , wherein at least one of:

the processor is provided locally on the computing device or provided on a server remote from the computing device; or

the processor is associated with at least one of an operating system of the computing device, a plugin for use with an application running on the computing device, a software application installed on, or queued to be installed on, the computing device, and a cloud-based service to which the computing device communicates.

20. A method for proactively providing a user with security-related information associated with content on a computing device prior to user interaction with such content, the method comprising:

presenting content on a user interface of the computing device for browsing by the user, the content including a link to an information resource;

analyzing the content including monitoring the information resource and analyzing the information resource to account for changes to the information resource occurring after the content has been presented on the user interface of the computing device for browsing by the user but prior to user interaction with such content to determine whether at least one of (a) the content or the changes to the information resource requires disclosure of information or (b) the content or the changes to the information resource poses a security threat; and

based, at least in part, on the analysis, at least one of (a) outputting to the user, prior to user interaction with the content, security-related information associated with the content or the changes to the information resource based, at least in part, on the analysis or (b) preventing, prior to user interaction with the content, user interaction with the content.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2022
From: MIMECAST NORTH AMERICA, INC.; MIMECAST SERVICES LIMITED
To: ARES CAPITAL CORPORATION
Reel/Frame 060132/0429 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2020
From: TYLER, SIMON PAUL; MALONE, STEVEN; MAYLOR, JACKIE ANNE; RY, WAYNE VAN; RIBEIRO, FRANCISCO; UEBEL, REINHARD
To: MIMECAST SERVICES LTD.
Reel/Frame 052719/0147 →
Continuity (4)
Continuation In Part 15461857 · Mar 17, 2017
Continuation In Part 15010023 · Jan 29, 2016
Continuation In Part 14855200 · Sep 15, 2015
Related Publication 20200137110A1 · Apr 30, 2020
References Cited (143)
US 5959542A · Ishida · 1999 [cited by applicant]
US 6253193B1 · Ginter et al. · 2001 [cited by applicant]
US 6931532B1 · Davis et al. · 2005 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by examiner]
US 7058822B2 · Edery et al. · 2006 [cited by applicant]
US 7240212B2 · Amone et al. · 2007 [cited by applicant]
US 7363490B2 · Paulsen, Jr. et al. · 2008 [cited by applicant]
US 7418731B2 · Touboul · 2008 [cited by applicant]
US 7444380B1 · Diamond · 2008 [cited by applicant]
US 7562382B2 · Hinton et al. · 2009 [cited by applicant]
US 7647633B2 · Edery et al. · 2010 [cited by applicant]
US 7653695B2 · Flury et al. · 2010 [cited by applicant]
US 7827402B2 · Smith · 2010 [cited by applicant]
US 7970843B2 · Brown et al. · 2011 [cited by applicant]
US 8019689B1 · Nachenberg · 2011 [cited by applicant]
US 8141154B2 · Gruzman et al. · 2012 [cited by applicant]
US 8145718B1 · Kacker et al. · 2012 [cited by applicant]
US 8281372B1 · Vidal · 2012 [cited by applicant]
US 8392357B1 · Zou et al. · 2013 [cited by applicant]
US 8438474B1 · Lloyd · 2013 [cited by examiner]
US 8522331B2 · Onozawa · 2013 [cited by applicant]
US 8635690B2 · Alperovitch · 2014 [cited by applicant]
US 8667069B1 · Connelly et al. · 2014 [cited by applicant]
US 8843516B2 · Leong et al. · 2014 [cited by applicant]
US 8843997B1 · Hare · 2014 [cited by applicant]
US 8862675B1 · Coomer · 2014 [cited by applicant]
US 8990392B1 · Stamos · 2015 [cited by applicant]
US 9027115B2 · Larson et al. · 2015 [cited by applicant]
US 9129116B1 · Wiltzius · 2015 [cited by examiner]
US 9154498B2 · Byrne et al. · 2015 [cited by applicant]
US 9177293B1 · Gagnon · 2015 [cited by applicant]
US 9344449B2 · Brown et al. · 2016 [cited by applicant]
US 9413774B1 · Liu · 2016 [cited by examiner]
US 9467410B2 · Liebmann et al. · 2016 [cited by applicant]
US 9467435B1 · Tyler et al. · 2016 [cited by applicant]
US 9645722B1 · Stasior · 2017 [cited by examiner]
US 9654492B2 · Maylor et al. · 2017 [cited by applicant]
US 9760697B1 · Walker · 2017 [cited by applicant]
US 10050998B1 · Singh · 2018 [cited by applicant]
US 10148683B1 · Lin · 2018 [cited by applicant]
US 10277628B1 · Jakobsson · 2019 [cited by applicant]
US 10536449B2 · Maylor et al. · 2020 [cited by applicant]
US 10586261B2 · Baig · 2020 [cited by applicant]
US 10609073B2 · Jakobsson · 2020 [cited by applicant]
US 10728239B2 · Maylor et al. · 2020 [cited by applicant]
US 20020091019A1 · Bays et al. · 2002 [cited by applicant]
US 20020095567A1 · Royer et al. · 2002 [cited by applicant]
US 20020199096A1 · Wenocur et al. · 2002 [cited by applicant]
US 20030051054A1 · Redlich et al. · 2003 [cited by applicant]
US 20030065941A1 · Ballard et al. · 2003 [cited by applicant]
US 20030110272A1 · du Castel · 2003 [cited by examiner]
US 20030182383A1 · He · 2003 [cited by applicant]
US 20030202663A1 · Hollis et al. · 2003 [cited by applicant]
US 20030204569A1 · Andrews et al. · 2003 [cited by applicant]
US 20030227487A1 · Hugh · 2003 [cited by applicant]
US 20040003398A1 · Donian · 2004 [cited by applicant]
US 20040070678A1 · Toyama et al. · 2004 [cited by applicant]
US 20040083270A1 · Heckerman et al. · 2004 [cited by applicant]
US 20040086127A1 · Candelore · 2004 [cited by applicant]
US 20040249897A1 · Espinosa · 2004 [cited by applicant]
US 20050033855A1 · Moradi et al. · 2005 [cited by applicant]
US 20050076222A1 · Olkin et al. · 2005 [cited by applicant]
US 20050278540A1 · Cho · 2005 [cited by applicant]
US 20060015945A1 · Fields · 2006 [cited by applicant]
US 20060021031A1 · Leahy et al. · 2006 [cited by applicant]
US 20060031359A1 · Clegg et al. · 2006 [cited by applicant]
US 20060075494A1 · Bertman · 2006 [cited by examiner]
US 20060106802A1 · Giblin et al. · 2006 [cited by applicant]
US 20060168006A1 · Shannon et al. · 2006 [cited by applicant]
US 20060212931A1 · Shull · 2006 [cited by applicant]
US 20060253458A1 · Dixon et al. · 2006 [cited by applicant]
US 20060288274A1 · Bustelo · 2006 [cited by examiner]
US 20070005713A1 · LeVasseur et al. · 2007 [cited by applicant]
US 20070005984A1 · Florencio · 2007 [cited by applicant]
US 20070038614A1 · Guha · 2007 [cited by applicant]
US 20070079379A1 · Sprosts et al. · 2007 [cited by applicant]
US 20070143271A1 · Yuval · 2007 [cited by examiner]
US 20070143827A1 · Nicodemus et al. · 2007 [cited by applicant]
US 20070192853A1 · Shraim et al. · 2007 [cited by applicant]
US 20070245422A1 · Hwang · 2007 [cited by applicant]
US 20070294292A1 · Hydrie · 2007 [cited by applicant]
US 20080028444A1 · Loesch · 2008 [cited by applicant]
US 20080115227A1 · Toutonghi · 2008 [cited by applicant]
US 20080127319A1 · Galloway · 2008 [cited by applicant]
US 20080127339A1 · Swain et al. · 2008 [cited by applicant]
US 20080148376A1 · Onozawa · 2008 [cited by applicant]
US 20080178278A1 · Grinstein et al. · 2008 [cited by applicant]
US 20080222425A1 · Buss · 2008 [cited by applicant]
US 20080250106A1 · Rugg et al. · 2008 [cited by applicant]
US 20080250114A1 · Dubovsky et al. · 2008 [cited by applicant]
US 20080301445A1 · Vasic et al. · 2008 [cited by applicant]
US 20090006532A1 · Sinn · 2009 [cited by applicant]
US 20090063426A1 · Crouch · 2009 [cited by applicant]
US 20090097662A1 · Olechowski et al. · 2009 [cited by applicant]
US 20090157490A1 · Lawyer · 2009 [cited by applicant]
US 20090216841A1 · Choi et al. · 2009 [cited by applicant]
US 20100175136A1 · Frumer et al. · 2010 [cited by applicant]
US 20100211459A1 · Seeman · 2010 [cited by examiner]
US 20100306819A1 · Nahari et al. · 2010 [cited by applicant]
US 20110055004A1 · Libby · 2011 [cited by examiner]
US 20110113109A1 · LeVasseur et al. · 2011 [cited by applicant]
US 20110119258A1 · Forutanpour et al. · 2011 [cited by applicant]
US 20110145580A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110179362A1 · Craddock et al. · 2011 [cited by applicant]
US 20110296179A1 · Templin et al. · 2011 [cited by applicant]
US 20110320582A1 · Lewis · 2011 [cited by examiner]
US 20120215846A1 · Howes · 2012 [cited by examiner]
US 20120272317A1 · Rubin · 2012 [cited by examiner]
US 20130047254A1 · Radhakrishnan et al. · 2013 [cited by applicant]
US 20130074191A1 · Ben-Reuven · 2013 [cited by applicant]
US 20130091580A1 · Maha · 2013 [cited by examiner]
US 20130298192A1 · Kumar · 2013 [cited by applicant]
US 20140040394A1 · Tang · 2014 [cited by applicant]
US 20140074859A1 · Swaminathan · 2014 [cited by examiner]
US 20140189355A1 · Hunter · 2014 [cited by examiner]
US 20140229617A1 · Cyr et al. · 2014 [cited by applicant]
US 20140282964A1 · Stubblefield · 2014 [cited by applicant]
US 20140283068A1 · Call · 2014 [cited by examiner]
US 20140331119A1 · Dixon · 2014 [cited by applicant]
US 20140373123A1 · Kang · 2014 [cited by applicant]
US 20150032829A1 · Barshow et al. · 2015 [cited by applicant]
US 20150039886A1 · Kahol et al. · 2015 [cited by applicant]
US 20150121063A1 · Maller et al. · 2015 [cited by applicant]
US 20150281262A1 · Cai · 2015 [cited by examiner]
US 20150350143A1 · Yang et al. · 2015 [cited by applicant]
US 20160012213A1 · Walsh · 2016 [cited by examiner]
US 20160036833A1 · Ardeli · 2016 [cited by applicant]
US 20160119288A1 · Ardeli · 2016 [cited by examiner]
US 20160142426A1 · Bird et al. · 2016 [cited by applicant]
US 20160188721A1 · Glover · 2016 [cited by examiner]
US 20170026393A1 · Walsh · 2017 [cited by examiner]
US 20170148032A1 · Corniuk et al. · 2017 [cited by applicant]
US 20180191754A1 · Higbee · 2018 [cited by applicant]
US 20200137110A1 · Tyler et al. · 2020 [cited by applicant]
US 20200143011A1 · Kaplan · 2020 [cited by examiner]
US 20200186514A1 · Maylor et al. · 2020 [cited by applicant]
US 20200358798A1 · Maylor et al. · 2020 [cited by applicant]
Proofpoint/Gartner, Inc., ‘Protecting the way people work: best practices for detecting and mitigating advanced persistent threats’, Gartner, Inc., May 4, 2015, entire document,http://www.ciosummits.com/Online_Assets_Pr… [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action for U.S. Appl. No. 16/732,604, dated Mar. 1, 2021, 42 pages. [cited by applicant]
AVG Technologies, ‘AVG AntiVirus Free Edition User Manual’, revision AVG.22 (Aug. 8, 2016), AVG Technologies CZ, entire document,http://files-download.avg.com/doc/AVG_free_uma_en_Itst_22.pdf. [cited by applicant]
Blue Coat Systems Inc., ‘Web Application Firewall for Web Environments’, Blue Coat Systems Inc., 2015, entire document, https://www.bluecoat.com/documents/download/c8988db3-06c0-4fb5-8bf2-2ec3e- 934e18e/f86a2dc5-cc4c-47… [cited by applicant]
Proofpoint/Gartner, Inc., ‘Protecting the way people work:best practices for detecting and mitigating advanced persistent threats’, Gartner, Inc., May 4, 2015, entire document, http://www.ciosummits.com/Online.sub.-Asse… [cited by applicant]
SpamTitan, ‘SpamTitan Administrators Guide v6.02’,2014, SpamTitan, entire document, http://www.spamtitan.com/updates/PDF/Technical%20Documentation/- SpamTitan_Administrators_Guide_v602160414_gh.pdf. [cited by applicant]