IP Library Granted Patent US 12,105,816
Granted Patent B2
US 12,105,816 · App. 16/875,118 · Granted Oct 1, 2024

Dynamically controlling access to linked content in electronic communications

Inventors: Conor Brian Hayes (Monte Sereno, CA); Michael Edward Jones (Fallbrook, CA); Alina V. Khayms (Sunnyvale, CA); Kenny Lee (Seattle, WA); David Jonathan Melnick (Los Angeles, CA); Adrian Knox Roston (Las Vegas, NV)
Assignee: Proofpoint, Inc.
G06F21/62G06F21/53G06F21/567G06N20/00H04L51/08H04L51/212H04L51/42H04L63/08H04L63/10H04L63/105H04L63/1416H04L63/1483G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,105,816
App. No.
16/875,118
Granted
Oct 1, 2024
Kind
B2
Abstract

Aspects of the disclosure relate to dynamically controlling access to linked content in electronic communications. A computing platform may receive, from a user computing device, a request for a uniform resource locator associated with an email message. Subsequently, the computing platform may identify that the uniform resource locator associated with the email message corresponds to a potentially-malicious site. In response to identifying that the uniform resource locator associated with the email message corresponds to the potentially-malicious site, the computing platform may determine a risk profile associated with the request received from the user computing device. Based on the risk profile associated with the request, the computing platform may execute an isolation method to provide limited access to the uniform resource locator associated with the email message. In some instances, executing the isolation method may include initiating a browser mirroring session to provide the limited access to the potentially-malicious site.

Claims (45)

1. A computing platform, comprising:

at least one hardware processor;

a communication interface; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive, via the communication interface, from a first user computing device associated with an enterprise organization, a first request to open a first uniform resource locator associated with a first email message;

identify that the first uniform resource locator associated with the first email message corresponds to a first potentially-malicious site;

in response to identifying that the first uniform resource locator associated with the first email message corresponds to the first potentially-malicious site, determine, based on features of the first uniform resource locator, a risk profile for the first request to open the first uniform resource locator received from the first user computing device, wherein determining the risk profile associated with the first request to open the first uniform resource locator received from the first user computing device includes identifying a web category associated with the first uniform resource locator and identifying that a user of the first user computing device is included in a very attacked persons group associated with the enterprise organization and dynamically determined, on a periodic basis, from an enterprise organization-specific index of users and wherein determining the risk profile associated with the first request to open the first uniform resource locator received from the first user computing device further includes determining that the first uniform resource locator associated with the first email message is associated with a specific web category by matching header content of a page corresponding to a site associated with the first uniform resource locator with information defined in one or more category templates; and

based on the risk profile associated with the first request to open the first uniform resource locator received from the first user computing device, execute an isolation method to provide limited access to the first uniform resource locator associated with the first email message.

2. The computing platform of wherein the first uniform resource locator associated with the first email message is an embedded link in the first email message that was rewritten, by an email filtering engine hosted on the computing platform, to point to the computing platform rather than a first resource associated with the first uniform resource locator, and

wherein identifying that the first uniform resource locator associated with the first email message corresponds to the first potentially-malicious site comprises identifying that the first uniform resource locator associated with the first email message corresponds to the first potentially-malicious site using a URL defense (UD) tool hosted on the computing platform.

3. The computing platform of claim 1 , wherein determining the risk profile associated with the first request received from the first user computing device further comprises determining one or more user-specific risk factors associated with a user of the first user computing device.

4. The computing platform of claim 1 , wherein executing the isolation method to provide limited access to the first uniform resource locator associated with the first email message comprises initiating a browser mirroring session with the first user computing device to provide the first user computing device with limited access to the first potentially-malicious site corresponding to the first uniform resource locator associated with the first email message.

5. The computing platform of claim 1 , wherein executing the isolation method to provide limited access to the first uniform resource locator associated with the first email message comprises preventing the first user computing device from downloading one or more binary objects.

6. The computing platform of claim 1 , wherein executing the isolation method to provide limited access to the first uniform resource locator associated with the first email message comprises preventing the first user computing device from uploading one or more binary objects.

7. The computing platform of claim 1 , wherein executing the isolation method to provide limited access to the first uniform resource locator associated with the first email message comprises providing data associated with the first potentially-malicious site to a phishing analysis service that is configured to return an indication of whether the first potentially-malicious site is a phishing site.

8. The computing platform of claim 1 , wherein executing the isolation method to provide limited access to the first uniform resource locator associated with the first email message comprises providing a user-selectable option to break out of isolation after data associated with the first potentially-malicious site is analyzed.

9. The computing platform of claim 1 , wherein executing the isolation method to provide limited access to the first uniform resource locator associated with the first email message comprises controlling input to the first potentially-malicious site.

10. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive, via the communication interface, from a second user computing device, a second request to open a second uniform resource locator associated with a second email message;

identify that the second uniform resource locator associated with the second email message corresponds to a second potentially-malicious site;

in response to identifying that the second uniform resource locator associated with the second email message corresponds to the second potentially-malicious site, determine a risk profile associated with the second request to open the second uniform resource locator received from the second user computing device and based on features of the second uniform resource locator; and

based on the risk profile associated with the second request to open the second uniform resource locator received from the second user computing device, execute a second isolation method to provide limited access to the second uniform resource locator associated with the second email message.

11. The computing platform of claim 1 , wherein the very attacked persons group is periodically reevaluated to determine whether users should be removed from the very attacked persons group.

12. The computing platform of claim 1 , wherein the very attacked persons group includes users within the enterprise organization who are targeted more frequently by malicious actors than other users.

13. The computing platform of claim 1 , wherein determining the risk profile associated with the first request to open the first uniform resource locator received from the first user computing device further includes adjusting the risk profile based on analyzed data from sensors embedded in one or more enterprise networks and configured to monitor enterprise-wide traffic.

14. The computing platform of claim 1 , further including instructions that, when executed, cause the computing platform to:

identify a score value corresponding the specific web category associated with the first uniform resource locator associated with the first email message; and

compare the score value to a plurality of thresholds to identify the risk profile associated with the request to open the first uniform resource locator.

15. The computing platform of claim 1 , wherein the features of the first uniform resource locator include at least one of: text or character pattern of the first uniform resource locator.

16. A method, comprising:

at a computing platform comprising at least one hardware processor, a communication interface, and memory:

receiving, by the at least one processor, via the communication interface, from a first user computing device associated with an enterprise organization, a first request to open a first uniform resource locator associated with a first email message;

identifying, by the at least one processor, that the first uniform resource locator associated with the first email message corresponds to a first potentially-malicious site;

in response to identifying that the first uniform resource locator associated with the first email message corresponds to the first potentially-malicious site, determining, by the at least one processor and based on features of the first uniform resource locator, a risk profile for the first request to open the first uniform resource locator received from the first user computing device, wherein determining the risk profile associated with the first request to open the first uniform resource locator received from the first user computing device includes identifying a web category associated with the first uniform resource locator and identifying that a user of the first user computing device is included in a very attacked persons group associated with the enterprise organization and dynamically determined, on a periodic basis, from an enterprise organization-specific index of users and wherein determining the risk profile associated with the first request to open the first uniform resource locator received from the first user computing device further includes determining that the first uniform resource locator associated with the first email message is associated with a specific web category by matching header content of a page corresponding to a site associated with the first uniform resource locator with information defined in one or more category templates; and

based on the risk profile associated with the first request to open the first uniform resource locator received from the first user computing device, executing, by the at least one processor, an isolation method to provide limited access to the first uniform resource locator associated with the first email message.

17. The method of claim 16 ,

wherein the first uniform resource locator associated with the first email message is an embedded link in the first email message that was rewritten, by an email filtering engine hosted on the computing platform, to point to the computing platform rather than a first resource associated with the first uniform resource locator, and

wherein identifying that the first uniform resource locator associated with the first email message corresponds to the first potentially-malicious site comprises identifying that the first uniform resource locator associated with the first email message corresponds to the first potentially-malicious site using a URL defense (UD) tool hosted on the computing platform.

18. The method of claim 16 , wherein determining the risk profile associated with the first request received from the first user computing device further comprises determining one or more user-specific risk factors associated with a user of the first user computing device.

19. The method of claim 16 , wherein executing the isolation method to provide limited access to the first uniform resource locator associated with the first email message comprises initiating a browser mirroring session with the first user computing device to provide the first user computing device with limited access to the first potentially-malicious site corresponding to the first uniform resource locator associated with the first email message.

20. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one hardware processor, a communication interface, and memory, cause the computing platform to:

receive, via the communication interface, from a first user computing device associated with an enterprise organization, a first request to open a first uniform resource locator associated with a first email message;

identify that the first uniform resource locator associated with the first email message corresponds to a first potentially-malicious site;

in response to identifying that the first uniform resource locator associated with the first email message corresponds to the first potentially-malicious site, determine, based on features of the first uniform resource locator, a risk profile for the first request to open the first uniform resource locator received from the first user computing device, wherein determining the risk profile associated with the first request to open the first uniform resource locator received from the first user computing device includes identifying a web category associated with the first uniform resource locator and identifying that a user of the first user computing device is included in a very attacked persons group associated with the enterprise organization and dynamically determined, on a periodic basis, from an enterprise organization-specific index of users and wherein determining the risk profile associated with the first request to open the first uniform resource locator received from the first user computing device further includes determining that the first uniform resource locator associated with the first email message is associated with a specific category by matching header content of a page corresponding to a site associated with the first uniform resource locator with information defined in one or more category templates; and

based on the risk profile associated with the first request to open the first uniform resource locator received from the first user computing device, execute an isolation method to provide limited access to the first uniform resource locator associated with the first email message.

Assignments (5)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Mar 21, 2024
From: GOLDMAN SACHS BANK USA, AS AGENT
To: PROOFPOINT, INC.
Reel/Frame 066865/0648 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0615 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0642 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2020
From: HAYES, CONOR BRIAN; JONES, MICHAEL EDWARD; KHAYMS, ALINA V.; LEE, KENNY; MELNICK, DAVID JONATHAN; ROSTON, ADRIAN KNOX
To: PROOFPOINT, INC.
Reel/Frame 052673/0624 →
Continuity (2)
Provisional Application 62863991 · Jun 20, 2019
Related Publication 20200404000A1 · Dec 24, 2020