IP Library Granted Patent US 11,722,497
Granted Patent B2
US 11,722,497 · App. 17/233,217 · Granted Aug 8, 2023

Message security assessment using sender identity profiles

Inventors: Bjorn Markus Jakobsson (Portola Valley, CA); John M. Wilson, III (Mountain View, CA)
Assignee: Agari Data, Inc.
H04L63/123H04L51/42H04L63/0236H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,722,497
App. No.
17/233,217
Granted
Aug 8, 2023
Kind
B2
Abstract

An identity profile of a user is tracked using previous message communications of the user. A message identified as potentially from the user is received. The identity profile of the user is identified and obtained. Information is extracted from a header of the received message. A security risk assessment of the received message is determined at least in part by comparing the extracted information with one or more corresponding entries of the identity profile of the user. A security action is performed based on the determined security risk assessment.

Claims (40)

1. A system, comprising:

one or more processors configured to:

track an identity profile of a user using previous message communications of the user, the identity profile including information descriptive of one or more of devices, networks, addresses, and software utilized by the user to send the previous message communications;

receive a message identified as potentially from the user;

identify and obtain the identity profile of the user;

extract information from a header of the received message;

determine a security risk assessment of the received message at least in part by comparing the extracted information with one or more corresponding entries of the identity profile of the user including by being configured to detect a change between at least a portion of the extracted information and at least one entry of the identity profile of the user and evaluating the detected change based on a likelihood-of-change probability associated with a likelihood that the at least one entry of the identity profile would change over time, wherein the likelihood-of-change probability is based on previously detected changes overtime in the previous message communications of the user; and

perform a security action based on the determined security risk assessment; and

one or more memory coupled to the one or more processors and configured to provide the one or more processors with instructions.

2. The system of claim 1 , wherein the likelihood-of-change probability is determined not using the detected change but only using the previously detected changes over time in the previous message communications of the user.

3. The system of claim 1 , wherein the extracted information includes information identifying an operating system used by a sender of the received message.

4. The system of claim 1 , wherein the extracted information includes information identifying a computer network used by a sender of the received message.

5. The system of claim 1 , wherein the extracted information includes information identifying a script used by a sender of the received message.

6. The system of claim 1 , wherein being configured to identify and obtain the identity profile of the user includes being configured to identify the identity profile of the user with a display name of a sender of the received message.

7. The system of claim 1 , wherein being configured to determine the security risk assessment includes being configured to determine that the user of the identity profile is likely not a sender of the received message.

8. The system of claim 1 , wherein being configured to compare the extracted information with the one or more corresponding entries of the identity profile of the user includes being configured to determine that although a mail user agent utilized by the received message does not exactly match a mail user agent specified in the identity profile, the mail user agent utilized by the received message is a newer version of the mail user agent utilized specified in the identity profile.

9. The system of claim 1 , wherein being configured to determine the security risk assessment of the received message includes being configured to determine that the message has likely been compromised by a phishing attack at least in part by determining that a sender message account of the received message matches an entry in the identity profile as a trusted message account but a device identifier extracted from the received message does not match a trusted device identifier in the identity profile and a network utilized to send the received message does not match a trusted network specified in the identity profile.

10. The system of claim 1 , wherein being configured to determine the security risk assessment of the received message includes being configured to determine that the received message is likely a part of a display name deception attack at least in part by determining that a sender message account of the received message does not match an entry in the identity profile but a sender display name of the received message matches an entry in the identity profile and a device identifier extracted from the received message does not match a trusted device identifier in the identity profile and a network utilized to send the received message does not match a trusted network specified in the identity profile.

11. The system of claim 1 , wherein being configured to determine the security risk assessment of the received message includes being configured to determine that the received message was sent by malware at least in part due to determining that the received message was sent using automation but the identity profile does not identify the user as being trusted to send messages using automation.

12. The system of claim 1 , wherein being configured to determine the security risk assessment of the received message includes being configured to determine that the received message was sent by the user despite a network utilized to send the received message not matching a trusted network specified in the identity profile at least in part because a sender message account of the message matches an entry in the identity profile as a trusted message account and a device identifier extracted from the message matches a trusted device identifier in the identity profile.

13. The system of claim 1 , wherein being configured to perform the security action includes being configured to update the identity profile based on the extracted information of the received message.

14. The system of claim 1 , wherein being configured to perform the security action includes being configured to add a device identifier to the identity profile of the user based on a determination that a sufficient number of messages have been received with the device identifier from a trusted account and via a trusted network.

15. The system of claim 1 , wherein being configured to perform the security action includes being configured to add a new message account identifier of a new account to the identity profile of the user based on a determination that a sufficient number of messages have been received from the new account specifying a trusted device identifier and a trusted network.

16. The system of claim 1 , wherein being configured to perform the security action includes being configured to modify a display name of a sender of the message prior to allowing an intended recipient of the received message to access the received message.

17. The system of claim 1 , wherein being configured to perform the security action includes being configured to perform one or more of the following: sending a verification challenge to an alternative contact of a sender of the received message; performing additional analysis of the received message; quarantining the received message; blocking the received message; executing an executable included in the received message in a sandbox or a virtual machine; adding a warning to the received message; and moving the received message to a different folder.

18. The system of claim 1 , wherein the likelihood-of-change probability is based on a measurement of a distribution of a frequency of changes in the previously detected changes overtime in the previous message communications of the user.

19. A method, comprising:

tracking an identity profile of a user using previous message communications of the user, the identity profile including information descriptive of one or more of devices, networks, addresses, and software utilized by the user to send the previous message communications;

receiving a message identified as potentially from the user;

identifying and obtaining the identity profile of the user;

extracting information from a header of the received message;

determining a security risk assessment of the received message at least in part by comparing the extracted information with one or more corresponding entries of the identity profile of the user including by detecting a change between at least a portion of the extracted information and at least one entry of the identity profile of the user and evaluating the detected change based on a likelihood-of-change probability associated with a likelihood that the at least one entry of the identity profile would change over time, wherein the likelihood-of-change probability is based on previously detected changes overtime in the previous message communications of the user; and

performing a security action based on the determined security risk assessment.

20. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

tracking an identity profile of a user using previous message communications of the user, the identity profile including information descriptive of one or more of devices, networks, addresses, and software utilized by the user to send the previous message communications;

receiving a message identified as potentially from the user;

identifying and obtaining the identity profile of the user;

extracting information from a header of the received message;

determining a security risk assessment of the received message at least in part by comparing the extracted information with one or more corresponding entries of the identity profile of the user including by detecting a change between at least a portion of the extracted information and at least one entry of the identity profile of the user and evaluating the detected change based on a likelihood-of-change probability associated with a likelihood that the at least one entry of the identity profile would change over time, wherein the likelihood-of-change probability is based on previously detected changes overtime in the previous message communications of the user; and

performing a security action based on the determined security risk assessment.

Assignments (6)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 57157/0206 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: AGARI DATA, INC.
Reel/Frame 073769/0945 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 57157/0265 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: AGARI DATA, INC.
Reel/Frame 073662/0811 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 10, 2021
From: AGARI DATA, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 057157/0206 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 10, 2021
From: AGARI DATA, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 057157/0265 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2021
From: JAKOBSSON, BJORN MARKUS; WILSON, JOHN M., III
To: AGARI DATA, INC.
Reel/Frame 056038/0899 →
Continuity (4)
Continuation 15958648 · Apr 20, 2018
Provisional Application 62647528 · Mar 23, 2018
Provisional Application 62490309 · Apr 26, 2017
Related Publication 20210234870A1 · Jul 29, 2021