IP Library Granted Patent US 11,695,786
Granted Patent B2
US 11,695,786 · App. 16/889,473 · Granted Jul 4, 2023

Methods and apparatus to identify suspicious electronic communication based on communication history

Inventors: Oliver Georges Devane (Buckinghamshire, GB); Deepak Setty (Bangalore, IN)
Assignee: MCAFEE, LLC
H04L63/1416G06F16/22H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,695,786
App. No.
16/889,473
Granted
Jul 4, 2023
Kind
B2
Abstract

Example apparatus to process an electronic communication includes a trusted communication identifier including a contact identifier to compare sender information from the electronic communication to contact information from a contact datastore, determine that a communication has not previously been sent from a recipient of the electronic communication to the sender of the electronic communication when the sender information from the electronic communication is not found in the contact datastore, and in response to determining that the communication has not been previously sent, provide an alert message that the sender information from the electronic communication is unknown. The trusted communication identifier further including a user action determiner to store the sender information from the electronic communication in the contact datastore when a response to the electronic communication has been sent.

Claims (48)

1. An apparatus to process an electronic communication, the apparatus comprising:

an electronic communication receiver to receive the electronic communication from a first application;

a contact information controller to determine whether a sender of the electronic communication is stored within a contact datastore, the contact datastore including first known senders of communications corresponding to the first application and second known senders of communications corresponding to a second application;

a contact identifier to:

determine that a communication has not previously been sent from a recipient of the electronic communication to the sender of the electronic communication when the sender is not found in the contact datastore; and

after determining that the communication has not been previously sent, provide an alert message that the sender of the electronic communication is unknown; and

a user action determiner to, in response to a determination that a response to the electronic communication has been sent, store information corresponding to the sender of the electronic communication in the contact datastore.

2. The apparatus of claim 1 , further including a contact information initializer to:

obtain at least one of a communication history associated with an identified application on a user device or contacts associated with the identified application on the user device; and

store information associated with the at least one of the communication history or the contacts, wherein the at least one of the communication history or the contacts were utilized to send one or more communications from the user device.

3. The apparatus of claim 2 , wherein the identified application on the user device is the first application on the user device, and wherein the communication history is associated with at least the second application on the user device.

4. The apparatus of claim 1 , further including a new contact monitor to:

determine if a new contact is added to contacts associated with an application; and

after determining the new contact is added, store contact information associated with the new contact in the contact datastore.

5. The apparatus of claim 1 , further including a malicious content scanner to determine if the electronic communication includes a uniform resource locator (URL) or an attachment file.

6. The apparatus of claim 5 , further including the malicious content scanner to determine if the URL included in the electronic communication is malicious.

7. The apparatus of claim 5 , further including the malicious content scanner to determine if the attachment file included in the electronic communication is malicious.

8. At least one non-transitory computer readable storage medium comprising instructions that, when executed, cause at least one processor to at least:

receive an electronic communication from a first application;

determine whether a sender of the electronic communication is stored within a contact datastore, the contact datastore including first known senders of communications corresponding to the first application and second known senders of communications corresponding to a second application;

determine that a communication has not previously been sent from a recipient of the electronic communication to the sender of the electronic communication when the sender from the electronic communication is not found in the contact datastore;

after determining that the communication has not been previously sent, provide an alert message that the sender of the electronic communication is unknown; and

after determining that a response to the electronic communication has been sent, store information corresponding to the sender of the electronic communication in the contact datastore.

9. The at least one non-transitory computer readable storage medium of claim 8 , wherein the instructions, when executed, cause the at least one processor to:

obtain at least one of a communication history associated with an identified application on a user device or contacts associated with the identified application on the user device; and

store, in the contact datastore, information associated with the at least one of the communication history or the contacts, wherein the at least one of the communication history or the contacts were utilized to send one or more communications from the user device.

10. The at least one non-transitory computer readable storage medium of claim 9 , wherein the identified application on the user device is the first application on the user device, and wherein the communication history is associated with at least the second application on the user device.

11. The at least one non-transitory computer readable storage medium of claim 8 , wherein the contact datastore is accessible across a plurality of user devices.

12. The at least one non-transitory computer readable storage medium of claim 8 , wherein the instructions, when executed, cause the at least one processor to:

determine if a new contact is added to contacts associated with an application; and

after determining the new contact is added, store contact information associated with the new contact in the contact datastore.

13. The at least one non-transitory computer readable storage medium of claim 8 , wherein the instructions, when executed, cause the at least one processor to determine if the electronic communication includes a uniform resource locator (URL) or an attachment file.

14. The at least one non-transitory computer readable storage medium of claim 13 , wherein the instructions, when executed, cause the at least one processor to determine if the URL included in the electronic communication is malicious.

15. The at least one non-transitory computer readable storage medium of claim 13 , wherein the instructions, when executed, cause the at least one processor to determine if the attachment file included in the electronic communication is malicious.

16. A method to process an electronic communication, the method comprising:

receiving the electronic communication from a first application;

determining whether a sender of the electronic communication is stored within a contact datastore, the contact datastore including first known senders of communications corresponding to the first application and second known senders of communications corresponding to a second application;

determining that a communication has not previously been sent from a recipient of the electronic communication to the sender of the electronic communication when the sender from the electronic communication is not found in the contact datastore;

after determining that the communication has not been previously sent, providing an alert message that the sender of the electronic communication is unknown; and

after determining that a response to the electronic communication has been sent, storing information corresponding to the sender of the electronic communication in the contact datastore.

17. The method of claim 16 , further including:

obtaining at least one of a communication history associated with an identified application on a user device or contacts associated with the application on the user device; and

storing, in a datastore, information associated with the at least one of the communication history or the contacts, wherein the at least one of the communication history or the contacts were utilized to send one or more communications from the user device.

18. The method of claim 17 , wherein the identified application on the user device is the first application on the user device, and wherein the communication history is associated with at least the second application on the user device.

19. The method of claim 16 , wherein the contact datastore is accessible across a plurality of user devices.

20. The method of claim 16 , further including:

determining if a new contact is added to contacts associated with an application; and

after determining the new contact is added, storing contact information associated with the new contact in the contact datastore.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2022
From: DEVANE, OLIVER GEORGES; SETTY, DEEPAK
To: MCAFEE, LLC
Reel/Frame 059650/0133 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Priority Claims (1)
IN 202011016631 · Apr 17, 2020 · national
Continuity (1)
Related Publication 20210329015A1 · Oct 21, 2021