IP Library Granted Patent US 11,595,354
Granted Patent B2
US 11,595,354 · App. 17/207,139 · Granted Feb 28, 2023

Mitigating communication risk by detecting similarity to a trusted message contact

Inventors: Bjorn Markus Jakobsson (Portola Valley, CA); Theodore C. Loder (Durham, NC); Jacob R. Rideout (Raleigh, NC); Arthur Kwan Jakobsson (Portola Valley, CA); Michael L. Jones (Livermore, CA)
Assignee: Agari Data, Inc.
H04L63/0263H04L63/0245H04L63/0254H04L63/1433H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,354
App. No.
17/207,139
Granted
Feb 28, 2023
Kind
B2
Abstract

At least one of a measure of trust or a measure of spoofing risk associated with a sender of a message is determined. A measure of similarity between an identifier of the sender of the message and an identifier of at least one trusted contact of a recipient of the message is determined. The measure of similarity is combined with at least one of the measure of trust or the measure of spoofing risk to at least in part determine a combined measure of risk associated with the message. Based at least in part on the combined measure of risk associated with the message, a verification action is performed including by automatically providing an inquiry message that requests a response to be provided.

Claims (40)

1. A method, comprising:

determining at least one of a measure of trust or a measure of spoofing risk associated with a sender of a received message;

determining a measure of similarity between an identifier of the sender of the received message and an identifier of at least one trusted contact of a recipient of the received message;

combining, using one or more computer processors of a network device, the measure of similarity with at least one of the measure of trust or the measure of spoofing risk to at least in part determine a combined measure of risk associated with the received message, wherein an address of the sender of the received message is not included in the at least one trusted contact of the recipient of the received message;

based at least in part on the combined measure of risk associated with the received message, performing, by the network device, a verification action including by automatically providing an inquiry message to a client device of one of the recipient or the sender, wherein the inquiry message requests a response to be provided; and

performing a security action based on the response responsive to the inquiry message.

2. The method of claim 1 , wherein the inquiry message is sent to the recipient of said received message.

3. The method of claim 2 , wherein the inquiry message requests the recipient of said received message to classify the sender of said received message.

4. The method of claim 3 , wherein the inquiry message includes an obfuscated version of said received message.

5. The method of claim 1 , wherein the inquiry message is sent to the sender of said received message.

6. The method of claim 5 , wherein the inquiry message requests verification of an identity of the sender of said received message.

7. The method of claim 5 , wherein the inquiry message requests the sender of said received message to forward the inquiry message to an alternate account of the sender of said received message and further forward the forwarded version of the inquiry message from the alternate account to a specified destination.

8. The method of claim 1 , wherein determining the measure of similarity includes sorting elements of the identifier of the sender and sorting elements of the identifier of the at least one trusted contact of the recipient of said received message.

9. The method of claim 1 , wherein determining the measure of similarity includes determining a string similarity measure between the identifier of the sender and the identifier of the at least one trusted contact.

10. The method of claim 1 , wherein determining the measure of similarity includes detecting substitution characters in the identifier of the sender.

11. The method of claim 1 , wherein the at least one trusted contacts of the recipient was identified based at least in part on contacts included an address book of the recipient of said received message.

12. The method of claim 1 , wherein the at least one trusted contact of the recipient was automatically identified at least in part by analyzing previous messages sent and received by the is recipient of said received message.

13. The method of claim 1 , wherein the at least one trusted contacts of the recipient was identified at least in part by analyzing previous messages sent and received by a plurality of different message accounts of a same network domain of the recipient of said received message.

14. The method of claim 1 , further comprising:

determining a first measure of reputation associated with the sender of said received message;

determining a second measure of reputation associated with the sender of said received message, wherein the first measure of reputation is associated with a longer timer period than the second measure of reputation; and

detecting a change in the second measure of reputation in light of the first measure of reputation, wherein said received message is filtered based at least in part on the detected change.

15. The method of claim 1 , further comprising determining a measure of control of a network domain of the sender of said received message, wherein said received message is filtered based at least in part on the measure of control of the network domain.

16. The method of claim 1 , wherein the measure of spoofing risk associated with the sender of said received message is determined and the spoofing risk is based at least in part a message validation policy associated with a network domain of the sender of said received message.

17. A system, comprising:

a processor of a network device, the processor configured to:

determine at least one of a measure of trust or a measure of spoofing risk associated with a sender of a received message;

determine a measure of similarity between an identifier of the sender of the received message and an identifier of at least one trusted contact of a recipient of the received message;

combine the measure of similarity with at least one of the measure of trust or the measure of spoofing risk to at least in part determine a combined measure of risk associated with the received message, wherein an address of the sender of the received message is not included in the at least one trusted contact of the recipient of the received message;

based at least in part on the combined measure of risk associated with the received message, perform a verification action including by automatically providing an inquiry message to a client device of one of the recipient or the sender, wherein the inquiry message requests a response to be provided; and

perform a security action based on the response responsive to the inquiry message; and

a non-transitory memory coupled to the processor and configured to provide the processor with instructions.

18. The system of claim 17 , wherein the inquiry message requests the recipient of said received message to classify the sender of said received message.

19. The system of claim 17 , wherein the inquiry message is sent to the sender of said received message and the inquiry message requests verification of an identity of the sender of said received message.

20. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions that, when executed, cause one or more processors of a network device to:

determine at least one of a measure of trust or a measure of spoofing risk associated with a sender of a received message;

determine a measure of similarity between an identifier of the sender of the received message and an identifier of at least one trusted contact of a recipient of the received message;

combine the measure of similarity with at least one of the measure of trust or the measure of spoofing risk to at least in part determine a combined measure of risk associated with the received message, wherein an address of the sender of the received message is not included in the at least one trusted contact of the recipient of the received message;

based at least in part on the combined measure of risk associated with the received message, perform a verification action including by automatically providing an inquiry message to a client device of one of the recipient or the sender, wherein the inquiry message requests a response to be provided; and

perform a security action based on the response responsive to the inquiry message.

Assignments (6)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 57157/0206 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: AGARI DATA, INC.
Reel/Frame 073769/0945 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 57157/0265 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: AGARI DATA, INC.
Reel/Frame 073662/0811 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 10, 2021
From: AGARI DATA, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 057157/0206 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 10, 2021
From: AGARI DATA, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 057157/0265 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2021
From: JAKOBSSON, BJORN MARKUS; LODER, THEODORE C.; RIDEOUT, JACOB R.; JAKOBSSON, ARTHUR KWAN; JONES, MICHAEL L.
To: AGARI DATA, INC.
Reel/Frame 057008/0354 →
Continuity (5)
Continuation 16399801 · Apr 30, 2019
Continuation 15723524 · Oct 3, 2017
Continuation 15453737 · Mar 8, 2017
Provisional Application 62399821 · Sep 26, 2016
Related Publication 20210211411A1 · Jul 8, 2021