IP Library Granted Patent US 11,050,793
Granted Patent B2
US 11,050,793 · App. 16/927,335 · Granted Jun 29, 2021

Retrospective learning of communication patterns by machine learning models for discovering abnormal behavior

Inventors: Sanjay Jeyakumar (Berkeley, CA); Jeshua Alexis Bratman (Brooklyn, NY); Dmitry Chechik (San Carlos, CA); Abhijit Bagri (Oakland, CA); Evan James Reiser (San Francisco, CA); Sanny Xiao Yang Liao (San Francisco, CA); Yu Zhou Lee (San Francisco, CA); Carlos Daniel Gasperi (New York, NY); Kevin Lau (Long Island, NY); Kai Jing Jiang (San Francisco, CA); Su Li Debbie Tan (San Mateo, CA); Jeremy Kao (Corona, CA); Cheng-Lin Yeh (Menlo Park, CA)
Assignee: Abnormal Security Corporation
H04L63/20G06N20/00H04L63/102H04L63/1416H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,050,793
App. No.
16/927,335
Granted
Jun 29, 2021
Kind
B2
Abstract

Conventional email filtering services are not suitable for recognizing sophisticated malicious emails, and therefore may allow sophisticated malicious emails to reach inboxes by mistake. Introduced here are threat detection platforms designed to take an integrative approach to detecting security threats. For example, after receiving input indicative of an approval from an individual to access past email received by employees of an enterprise, a threat detection platform can download past emails to build a machine learning (ML) model that understands the norms of communication with internal contacts (e.g., other employees) and/or external contacts (e.g., vendors). By applying the ML model to incoming email, the threat detection platform can identify security threats in real time in a targeted manner.

Claims (54)

1. A computer-implemented method comprising:

establishing, via an application programming interface, a connection with a storage medium that includes information regarding digital conduct of employees of an enterprise,

wherein the storage medium is managed by an entity that supports an office suite that is utilized by the employees of the enterprise;

downloading, via the application programming interface, a first series of past communications received by an employee over a first interval of time into a local processing environment;

building a machine learning (ML) model for the employee by providing the first series of past communications to the ML model as training data, so as to train the ML model to understand normal traits and content of communications received by the employee;

receiving, via the application programming interface, a communication addressed to the employee;

examining the communication to establish at least two email attributes;

generating a statistical profile that includes at least one score by providing the at least two email attributes to the ML model as input,

wherein each said score corresponds to a pair of email attributes formed from the at least two email attributes, and

wherein each said score is based on an analysis of the corresponding pair of email attributes by the ML model; and

establishing whether the communication represents a security risk based on a comparison of each score in the statistical profile to a corresponding threshold that is calibrated based on a target number of false positives and false negatives generated by the ML model for each employee of the enterprise.

2. The computer-implemented method of claim 1 , further comprising:

receiving input indicative of an approval from an administrator associated with the enterprise to access the information in the storage medium;

wherein said establishing is performed in response to receiving the input.

3. The computer-implemented method of claim 1 , wherein the first series of past communications includes multiple emails that were delivered to the employee.

4. The computer-implemented method of claim 1 , further comprising:

examining each past communication in the first series of past communications to establish email attributes of the first series of past communications; and

providing the email attributes derived from the first series of past communications to the ML model as training data.

5. The computer-implemented method of claim 1 , further comprising:

determining that the communication represents a security risk; and

characterizing the security risk along multiple dimensions.

6. The computer-implemented method of claim 5 , wherein the multiple dimensions include:

an attacked party,

an attack vector,

an impersonated party,

an impersonation strategy, and

an attack goal.

7. The computer-implemented method of claim 1 , wherein the first series of past communications includes all emails received by the employee during the first interval of time.

8. The computer-implemented method of claim 1 , further comprising:

downloading, via the application programming interface, a second series of past communications corresponding to a second interval of time that precedes the first interval of time into the local processing environment; and

establishing whether any communications received during the second interval of time represent security risks by applying the ML model to the second series of past communications.

9. A non-transitory computer-readable medium with instructions stored thereon that, when executed by a processor, cause the processor to perform operations comprising:

collecting data related to incoming emails and/or outgoing emails of a customer corresponding to a past interval of time;

generating, based on the data, a communication profile that specifies what constitutes normal behavior with respect to each of multiple individuals with whom the customer communicated over the past interval of time;

receiving an incoming email addressed to the customer;

deriving at least two email attributes of the incoming email; and

determining risk posed by the incoming email by:

forming at least one pair of email attributes by combining each email attribute of the at least two email attributes with each other email attribute of the at least two email attributes,

generating a statistical profile by producing at least one score indicative of the degree to which the incoming email deviates from past email activity by comparing each pair of email attributes to the communication profile, and

establishing an amount of risk posed by the incoming email based on a comparison of each said score in the statistical profile to a corresponding threshold that is calibrated based on a target number of false positives and false negatives generated by a machine learning (ML) model for each employee of the enterprise.

10. The non-transitory computer-readable medium of claim 9 , wherein the customer is an enterprise for which the communication profile is generated.

11. The non-transitory computer-readable medium of claim 9 , wherein the customer is an employee of an enterprise for whom the communication profile is generated.

12. The non-transitory computer-readable medium of claim 9 , wherein said generating comprises:

deriving at least one attribute from each email corresponding to the past interval of time; and

building the communication profile based on the derived attributes.

13. The non-transitory computer-readable medium of claim 9 , the operations further comprising:

providing deviations in the incoming email to the ML model as input; and

determining whether the incoming email is representative of a security risk based on an output produced by the ML model.

14. The non-transitory computer-readable medium of claim 13 , the operations further comprising:

performing a remediation action responsive to determining that the incoming email is representative of a security risk.

15. The non-transitory computer-readable medium of claim 9 , wherein the one or more email attributes include a primary attribute and a secondary attribute.

16. The non-transitory computer-readable medium of claim 15 , wherein said deriving comprises:

extracting the primary attribute from the incoming email; and

determining the secondary attribute based on the primary attribute and additional information associated with the customer.

Assignments (2)
CHANGE OF NAME Recorded Apr 22, 2025
From: ABNORMAL SECURITY CORPORATION
To: ABNORMAL AI, INC.
Reel/Frame 070947/0132 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2020
From: JEYAKUMAR, SANJAY; BRATMAN, JESHUA ALEXIS; CHECHIK, DMITRY; BAGRI, ABHIJIT; REISER, EVAN JAMES; LIAO, SANNY XIAO YANG; LEE, YU ZHOU; GASPERI, CARLOS DANIEL; LAU, KEVIN; JIANG, KAI JING; TAN, SU LI DEBBIE; KAO, JEREMY; YEH, CHENG-LIN
To: ABNORMAL SECURITY CORPORATION
Reel/Frame 053437/0208 →
Continuity (6)
Continuation In Part PCTUS2019067279 · Dec 18, 2019
Continuation In Part 16672854 · Nov 4, 2019
Provisional Application 62813603 · Mar 4, 2019
Provisional Application 62807888 · Feb 20, 2019
Provisional Application 62782158 · Dec 19, 2018
Related Publication 20200396258A1 · Dec 17, 2020
Cited By (7)
US 12,254,040 US 12,299,155 US 12,399,607 US 12,463,998 US 12,511,395 US 12,591,423 US 12,676,885