IP Library Granted Patent US 11,470,108
Granted Patent B2
US 11,470,108 · App. 17/239,152 · Granted Oct 11, 2022

Detection and prevention of external fraud

Inventors: Yu Zhou Lee (San Francisco, CA); Lawrence Stockton Moore (Palo Alto, CA); Jeshua Alexis Bratman (Brooklyn, NY); Lei Xu (New York, NY); Sanjay Jeyakumar (Berkeley, CA)
Assignee: Abnormal Security Corporation
H04L63/1433H04L51/08H04L51/212H04L63/0236H04L63/0245H04L63/126H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,470,108
App. No.
17/239,152
Granted
Oct 11, 2022
Kind
B2
Abstract

Introduced here are computer programs and computer-implemented techniques for detecting instances of external fraud by monitoring digital activities that are performed with accounts associated with an enterprise. A threat detection platform may determine the likelihood that an incoming email is indicative of external fraud based on the context and content of the incoming email. For example, to understand the risk posed by an incoming email, the threat detection platform may seek to determine not only whether the sender normally communicates with the recipient, but also whether the topic is one normally discussed by the sender and recipient. In this way, the threat detection platform can establish whether the incoming email deviates from past emails exchanged between the sender and recipient.

Claims (59)

1. A method comprising:

obtaining an email that is addressed to a first email account associated with a first enterprise;

establishing that the email represents an instance of outreach by a second email account associated with a vendor for payment of an invoice by the first enterprise;

obtaining a metric that is indicative of a risk in communicating with the second email account based at least in part on a comparison of the email to a set of emails that are representative of past instances of outreach by the second email account, at least in part by accessing a digital profile associated with the vendor, wherein the digital profile is a first digital profile included in a set of digital profiles collectively associated with a plurality of vendors, wherein the first digital profile includes a classification indicative of correspondence risk and information regarding how the classification was determined, wherein at least one email included in the set of emails is an outreach by the second email account to an email account associated with a second enterprise that is different from the first enterprise; and

determining, based on the metric, how to handle the obtained email.

2. The method of claim 1 , wherein said establishing comprises:

determining that the email is sent from an email address with a domain that is associated with the vendor; and

determining that the email contains the invoice based on an analysis of content of the email.

3. The method of claim 1 , wherein when the metric indicates that the risk in communicating with the second email account is high, said determining comprises:

implementing a filter so as to at least temporarily prohibit incoming emails from the second email account from being received by employees of the first enterprise.

4. The method of claim 1 , wherein when the metric indicates that the risk in communicating with the second email account is high, said determining comprises:

causing display of a notification by a computer program that includes information regarding the instance of outreach by the second email account.

5. The method of claim 4 , wherein the information includes a first email address of the first email account, a second email address of the second email account, a time at which the email was transmitted, a geographical location from which the email was transmitted, an Internet Protocol (IP) address from which the email was transmitted, or any combination thereof.

6. The method of claim 1 , wherein when the metric indicates that the risk in communicating with the second email account is low, said determining comprises:

allowing the email to reach an inbox of the first email account.

7. The method of claim 1 , further comprising:

applying a first maliciousness model to the email to produce a first output indicative of whether the email is representative of a non-malicious email;

establishing, based on the first output, that the email is representative of a malicious email; and

applying a second maliciousness model to the email to produce a second output indicative of whether the email is representative of a given type of malicious email;

wherein said determining is further based on the first output and/or the second output.

8. A non-transitory medium with instructions stored thereon that, when executed by a processor of a computing device, cause the computing device to perform operations comprising:

obtaining an email that is addressed to a first email account associated with a first enterprise;

establishing that the email represents an instance of outreach by a second email account associated with a vendor for payment of an invoice by the first enterprise;

obtaining a metric that is indicative of a risk in communicating with the second email account based at least in part on a comparison of the email to a set of emails that are representative of past instances of outreach by the second email account, at least in part by accessing a digital profile associated with the vendor, wherein the digital profile is a first digital profile included in a set of digital profiles collectively associated with a plurality of vendors, wherein the first digital profile includes a classification indicative of correspondence risk and information regarding how the classification was determined, wherein at least one email included in the set of emails is an outreach by the second email account to an email account associated with a second enterprise that is different from the first enterprise; and

determining, based on the metric, how to handle the obtained email.

9. The non-transitory medium of claim 8 , wherein said establishing comprises:

determining that the email is sent from an email address with a domain that is associated with the vendor; and

determining that the email contains the invoice based on an analysis of the content of the email.

10. The non-transitory medium of claim 8 , wherein when the metric indicates that the risk in communicating with the second email account is high, said determining comprises: implementing a filter so as to at least temporarily prohibit incoming emails from the second email account from being received by employees of the first enterprise.

11. The non-transitory medium of claim 8 , wherein when the metric indicates that the risk in communicating with the second email account is high, said determining comprises: causing display of a notification by a computer program that includes information regarding the instance of outreach by the second email account.

12. The non-transitory medium of claim 11 , wherein the information includes a first email address of the first email account, a second email address of the second email account, a time at which the email was transmitted, a geographical location from which the email was transmitted, an Internet Protocol (IP) address from which the email was transmitted, or any combination thereof.

13. The non-transitory medium of claim 8 , wherein when the metric indicates that the risk in communicating with the second email account is low, said determining comprises: allowing the email to reach an inbox of the first email account.

14. The non-transitory medium of claim 8 , wherein the instructions further cause the computing device to perform operations comprising:

applying a first maliciousness model to the email to produce a first output indicative of whether the email is representative of a non-malicious email;

establishing, based on the first output, that the email is representative of a malicious email; and

applying a second maliciousness model to the email to produce a second output indicative of whether the email is representative of a given type of malicious email;

wherein said determining is further based on the first output and/or the second output.

15. A system comprising:

a processor configured to:

obtain an email that is addressed to a first email account associated with a first enterprise;

establish that the email represents an instance of outreach by a second email account associated with a vendor for payment of an invoice by the first enterprise;

obtain a metric that is indicative of a risk in communicating with the second email account based at least in part on a comparison of the obtained email to a set of emails that are representative of past instances of outreach by the second email account, at least in part by accessing a digital profile associated with the vendor, wherein the digital profile is a first digital profile included in a set of digital profiles collectively associated with a plurality of vendors, wherein the first digital profile includes a classification indicative of correspondence risk and information regarding how the classification was determined, wherein at least one email included in the set of emails used in the comparison is an outreach by the second email account to an email account associated with a second enterprise that is different from the first enterprise; and

determine, based on the metric, how to handle the obtained email; and

a memory coupled to the processor and configured to provide the processor with instructions.

16. The system of claim 15 , wherein said establishing comprises:

determining that the email is sent from an email address with a domain that is associated with the vendor; and

determining that the email contains the invoice based on an analysis of content of the email.

17. The system of claim 15 , wherein when the metric indicates that the risk in communicating with the second email account is high, said determining comprises:

implementing a filter so as to at least temporarily prohibit incoming emails from the second email account from being received by employees of the first enterprise.

18. The system of claim 15 , wherein when the metric indicates that the risk in communicating with the second email account is high, said determining comprises:

causing display of a notification by a computer program that includes information regarding the instance of outreach by the second email account.

19. The system of claim 18 , wherein the information includes a first email address of the first email account, a second email address of the second email account, a time at which the email was transmitted, a geographical location from which the email was transmitted, an Internet Protocol (IP) address from which the email was transmitted, or any combination thereof.

20. The system of claim 15 , wherein when the metric indicates that the risk in communicating with the second email account is low, said determining comprises:

allowing the email to reach an inbox of the first email account.

21. The system of claim 15 , wherein the processor is further configured to:

apply a first maliciousness model to the email to produce a first output indicative of whether the email is representative of a non-malicious email;

establish, based on the first output, that the email is representative of a malicious email; and

apply a second maliciousness model to the email to produce a second output indicative of whether the email is representative of a given type of malicious email;

wherein said determining is further based on the first output and/or the second output.

Assignments (2)
CHANGE OF NAME Recorded Apr 22, 2025
From: ABNORMAL SECURITY CORPORATION
To: ABNORMAL AI, INC.
Reel/Frame 070947/0132 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2021
From: LEE, YU ZHOU; MOORE, LAWRENCE STOCKTON; BRATMAN, JESHUA ALEXIS; XU, LEI; JEYAKUMAR, SANJAY
To: ABNORMAL SECURITY CORPORATION
Reel/Frame 056608/0960 →
Continuity (2)
Provisional Application 63014421 · Apr 23, 2020
Related Publication 20210336983A1 · Oct 28, 2021
Cited By (1)
US 12,476,985