IP Library Granted Patent US 11,159,545
Granted Patent B2
US 11,159,545 · App. 16/801,130 · Granted Oct 26, 2021

Message platform for automated threat simulation, reporting, detection, and remediation

Inventors: Aaron Higbee (Leesburg, VA); David Chamberlain (New Boston, NH); Vineetha Philip (Fairfax Station, VA)
Assignee: Cofense Inc
H04L63/1416G06F16/35G06F21/00G06F21/554H04L51/12H04L63/1433H04L63/1483H04L63/1491H04L63/20H04L51/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,159,545
App. No.
16/801,130
Granted
Oct 26, 2021
Kind
B2
Abstract

The present invention relates to methods, network devices, and machine-readable media for an integrated environment and platform for automated processing of reports of suspicious messages, and further including automated threat simulation, reporting, detection, and remediation, including rapid quarantine and restore functions.

Claims (43)

1. A computerized method for suspicious message processing and incident response, comprising:

receiving a report at a threat detection platform of a potentially suspicious message delivered into a user account, the report being generated as a result of an action by the user indicating that the message has been identified by the user as a potential security threat, and

wherein the report having been initiated by a user interface element in an email client, and

wherein the report comprises a copy of the delivered message;

electronically storing defined textual or binary patterns associated with at least one security threat;

processing the received message according to the electronically stored patterns to determine if the body of the received message or an attachment of the received message contains the defined textual or binary patterns associated with the security threat;

if the received message contains the defined textual or binary patterns associated with the security threat, then:

transmitting a message identifier and associated account identifier for the received message to an email server in association with a command to move the received message from an inbox associated with the user account;

generating a copy of the received message, the copy having been modified such that the security threat has been replaced with innocuous content or deleted;

establishing a privileged account connection to an administrative account on the email server to access multiple user email accounts; and

using the privileged account, inserting the copy of the message having been modified into one or more of the accessed multiple user email accounts.

2. The method of claim 1 , wherein the inserting of the copy is performed only after a user activity action has been detected on the one or more multiple user email accounts.

3. The method of claim 1 , further comprising:

transmitting a command to the email server to return one or more message identifiers and associated account identifiers for other messages having the common characteristic;

receiving the message identifiers and account identifiers for the other messages having the common characteristic;

transmitting the message identifiers and account identifiers to the email server in association with a command to move the messages from user account inboxes.

4. The method of claim 1 , further comprising:

at the email server:

receiving copies of incoming email messages;

parsing the incoming email messages into Multipurpose Internet Mail Extension components; and

storing the message components in a data store, each of the messages components being stored as a separate field in a database in the data store, each of the fields being stored in association with a unique message identifier for the message.

5. A computerized system for suspicious message processing and incident response, comprising:

a processor at a threat detection platform configured with executable instructions for:

receiving a report at a threat detection platform of a potentially suspicious message delivered into a user account, the report being generated as a result of an action by the user indicating that the message has been identified by the user as a potential security threat, and

wherein the report having been initiated by a user interface element in an email client, and

wherein the report comprises a copy of the delivered message;

electronically storing defined textual or binary patterns associated with at least one security threat;

processing the received message according to the electronically stored patterns to determine if the body of the received message or an attachment of the received message contains the defined textual or binary patterns associated with the security threat;

if the received message contains the defined textual or binary patterns associated with the security threat, then:

transmitting a message identifier and associated account identifier for the received message to an email server in association with a command to move the received message from an inbox associated with the user account;

generating a copy of the received message, the copy having been modified such that the security threat has been replaced with innocuous content or deleted;

establishing a privileged account connection to an administrative account on the email server to access multiple user email accounts; and

using the privileged account, inserting the copy of the message having been modified into one or more of the accessed multiple user email accounts.

6. The system of claim 5 , wherein the inserting of the copy is performed only after a user activity action has been detected on the one or more multiple user email accounts.

7. The system of claim 5 , further comprising instructions for:

transmitting a command to the email server to return one or more message identifiers and associated account identifiers for other messages having the common characteristic;

receiving the message identifiers and account identifiers for the other messages having the common characteristic;

transmitting the message identifiers and account identifiers to the email server in association with a command to move the messages from user account inboxes.

8. The system of claim 5 , further comprising instructions for:

at the email server:

receiving copies of incoming email messages;

parsing the incoming email messages into Multipurpose Internet Mail Extension components; and

storing the message components in a data store, each of the messages components being stored as a separate field in a database in the data store, each of the fields being stored in association with a unique message identifier for the message.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE BLUE TORCH FINANCE LLC PREVIOUSLY RECORDED ON REEL 059800 FRAME 0834. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded May 5, 2023
From: COFENSE INC.
To: BLUE TORCH FINANCE LLC
Reel/Frame 064381/0245 →
RELEASE OF SECURITY INTEREST Recorded May 6, 2022
From: ORIX GROWTH CAPITAL, LLC
To: COFENSE INC.; COFENSE BIDCO CORPORATION
Reel/Frame 059864/0955 →
SECURITY INTEREST Recorded May 3, 2022
From: COFENSE INC.
To: BLUE TORCH CAPITAL LP
Reel/Frame 059800/0834 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2022
From: HIGBEE, AARON; CHAMBERLAIN, DAVID; PHILIP, VINEETHA
To: COFENSE INC.
Reel/Frame 059248/0873 →
SECURITY INTEREST Recorded Oct 4, 2021
From: COFENSE BIDCO CORPORATION; COFENSE INC.
To: ORIX GROWTH CAPITAL, LLC, AS ADMINSTRATIVE AGENT
Reel/Frame 057692/0722 →
Continuity (11)
Continuation In Part 16532449 · Aug 5, 2019
Continuation 16418973 · May 21, 2019
Continuation 16801130
Continuation In Part 16181122 · Nov 5, 2018
Continuation 15905784 · Feb 26, 2018
Continuation In Part 15584002 · May 1, 2017
Continuation 14986515 · Dec 31, 2015
Provisional Application 62810369 · Feb 25, 2019
Provisional Application 62581637 · Nov 3, 2017
Provisional Application 62145778 · Apr 10, 2015
Related Publication 20210021612A1 · Jan 21, 2021
Cited By (2)
US 12,418,510 US 12,476,985