IP Library Granted Patent US 12,615,290
Granted Patent B2
US 12,615,290 · App. 17/323,860 · Granted Apr 28, 2026

Cyber security for instant messaging across platforms

Inventors: John Anthony Boyer (Cambridge, GB); Matthew Dunn (Cambridgeshire, GB)
Assignee: Darktrace Holdings Limited
H04L63/1483H04L51/046H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,290
App. No.
17/323,860
Granted
Apr 28, 2026
Kind
B2
Abstract

A cyber threat defense system can incorporate data from an instant messaging platform with multiple other platforms in a client system to identify cyber threats across the client system. The system can have one or more instant messaging modules to collect instant messaging data from one or more network entities that utilizes one or more instant messaging platforms. A user specific profile module can identify a user of the client system associated with the user account based on a composite user profile constructed from user context data collected across multiple platforms of the client system. A risk profile module can associate the user with a user risk profile based on the composite user profile. The risk profile module can apply one or more artificial intelligence classifiers to the instant message based on the user risk profile. A cyber threat module is configured to identify whether the instant messaging data corresponds to a cyber threat partially based on the user risk profile. An autonomous response module can execute an autonomous response in response to the cyber threat factoring in the user risk profile.

Claims (33)

1 . A method for a cyber threat defense system incorporating data across multiple platforms used by a client system to identify a cyber threat, comprising:

collecting, from one or more network entities that utilize one or more instant messaging platforms, instant messaging data describing an instant message and associated with a user account on at least a first instant messaging platform, where the instant messaging data is collected into one or more instant message modules;

generating a composite user profile from user context data collected across multiple platforms of the client system, where the composite user profile for the multiple platforms of the client system factors in data from i) the instant messaging platform and ii) at least one of a System-as-a-Service (SaaS) platform, a cloud platform, an information technology network, and an email platform, associated with the user;

identifying a user of the client system associated with the user account based on the composite user profile and contextualizing the instant messaging data under analysis with at least a portion of the user context data;

associating the user with a user risk profile, wherein the user risk profile is based on a combination of (i) a user importance score that identifies at least a number of services and resource that the user can affect and (ii) a vulnerability score directed to a determination of vulnerabilities based on analysis of the instant message data by one or more artificial intelligence classifiers to calculate a degree of damage attributable to the user in response to the cyber threat;

performing an autonomous response to the cyber threat by an autonomous response module interacting with the one or more instant messaging modules, the autonomous response is based, at least in part, on the user risk profile; and

wherein the collecting of the instant messaging data is conducted by (i) gathering a messaging archive for the client system using a web hook authorized by the instant messaging platform and (ii) translating the instant messaging data into a universal format.

2 . The method for the cyber threat defense system of claim 1 , further comprising:

applying one or more artificial intelligence classifiers to the instant message data based on the user risk profile; and

identifying that the instant messaging data under analysis by the cyber threat defense system corresponds to the cyber threat partially based on the user risk profile.

3 . The method for the cyber threat defense system of claim 2 , further comprising:

accessing the messaging archive to collect the instant messaging data for the user account.

4 . The method for the cyber threat defense system of claim 1 , further comprising:

polling an application programming interface of the instant messaging platform for the instant messaging data associated with the user account.

5 . The method for the cyber threat defense system of claim 1 , further comprising:

directing a mobile device management sub-module in the one or more instant message modules to gather a messaging archive from the instant messaging platform.

6 . The method for the cyber threat defense system of claim 1 , wherein the autonomous response directed by the autonomous response module is at least one of logging out the user, limiting access to a suspect message, deleting the suspect message, and revoking a permission level for the user.

7 . A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in the cyber threat defense system to instruct a computing device to perform the method of claim 1 .

8 . A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in a cyber threat defense system to instruct a computing device to perform operations comprising:

collecting, from one or more network entities that utilize one or more instant messaging platforms, instant messaging data describing an instant message and associated with a user account on at least a first instant messaging platform, wherein the instant messaging data is collected into one or more instant message modules and the collecting of the instant message data is conducted by at least (i) gathering a messaging archive for a client system using a web hook authorized by the instant messaging platform and (ii) translating the instant messaging data into a universal format;

generating a composite user profile from user context data collected across multiple platforms of the client system, where the composite user profile for the multiple platforms of the client system factors in data from i) the instant messaging platform and ii) at least one of a System-as-a-Service (SaaS) platform, a cloud platform, an information technology network, and an email platform, associated with the user;

identifying a user of the client system associated with the user account based on the composite user profile and contextualizing the instant messaging data under analysis with at least a portion of the user context data;

associating the user with a user risk profile based on the composite user profile, wherein the composite user profile is based on a combination of (i) a user importance score that identifies at least a number of services and resource that the user can affect and (ii) a vulnerability score directed to a determination of vulnerabilities based on analysis of the instant message data by one or more artificial intelligence classifiers to calculate a degree of damage attributable to the user in response to the cyber threat; and

performing an autonomous response to the cyber threat by an autonomous response module interacting with the one or more instant messaging modules, the autonomous response is based, at least in part, on the user risk profile.

9 . The non-transitory computer readable medium of claim 8 , wherein the operations performed by the computing device further comprising:

accessing the messaging archive to collect the instant messaging data for the user account.

10 . The non-transitory computer readable medium of claim 8 , wherein the operations performed by the computing device further comprising:

providing a client authorization to the web hook for the instant messaging platform.

11 . The non-transitory computer readable medium of claim 8 , wherein the operations performed by the computing device further comprising:

polling an application programming interface of the instant messaging platform for the instant messaging data associated with the user account.

12 . The non-transitory computer readable medium of claim 8 , wherein the operations performed by the computing device further comprising:

directing a mobile device management sub-module in the one or more instant message modules to gather a messaging archive from the instant messaging platform.

13 . The non-transitory computer readable medium of claim 8 , wherein the autonomous response directed by the autonomous response module is at least one of logging out the user, limiting access to a suspect message, deleting the suspect message, and revoking a permission level for the user.

Assignments (3)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2022
From: BOYER, JOHN ANTHONY; DUNN, MATTHEW
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 059575/0193 →
Continuity (3)
Provisional Application 63078092 · Sep 14, 2020
Provisional Application 63026446 · May 18, 2020
Related Publication 20210360027A1 · Nov 18, 2021
References Cited (153)
US 6154844A · Touboul · 2000 [cited by examiner]
US 6965968B1 · Touboul · 2005 [cited by examiner]
US 7307999B1 · Donaghey · 2007 [cited by examiner]
US 7418731B2 · Touboul · 2008 [cited by examiner]
US 7448084B1 · Apap · 2008 [cited by examiner]
US 7843322B2 · Zakrewski · 2010 [cited by examiner]
US 7890869B1 · Mayer · 2011 [cited by examiner]
US 8312540B1 · Kahn · 2012 [cited by examiner]
US 8661538B2 · Cohen-Ganor · 2014 [cited by examiner]
US 8819803B1 · Richards · 2014 [cited by examiner]
US 8879803B2 · Ukil · 2014 [cited by examiner]
US 8966036B1 · Asgekar · 2015 [cited by examiner]
US 9043905B1 · Allen · 2015 [cited by examiner]
US 9106687B1 · Sawhney · 2015 [cited by examiner]
US 9185095B1 · Moritz · 2015 [cited by examiner]
US 9213990B2 · Adjaoute · 2015 [cited by examiner]
US 9348742B1 · Brezinski · 2016 [cited by examiner]
US 9401925B1 · Guo · 2016 [cited by examiner]
US 9516039B1 · Yen · 2016 [cited by examiner]
US 9516053B1 · Muddu · 2016 [cited by examiner]
US 9641544B1 · Treat · 2017 [cited by examiner]
US 9712548B2 · Shmueli · 2017 [cited by examiner]
US 9727723B1 · Kondaveeti · 2017 [cited by examiner]
US 10237298B1 · Nguyen · 2019 [cited by examiner]
US 10268821B2 · Stockdale · 2019 [cited by examiner]
US 10419466B2 · Ferguson · 2019 [cited by examiner]
US 10516693B2 · Stockdale · 2019 [cited by examiner]
US 10701093B2 · Dean · 2020 [cited by examiner]
US 10880322B1 · Jakobsson · 2020 [cited by examiner]
US 11102244B1 · Jakobsson · 2021 [cited by examiner]
US 11323464B2 · Jakobsson · 2022 [cited by examiner]
US 11636213B1 · Elgressy · 2023 [cited by examiner]
US 20020174217A1 · Anderson · 2002 [cited by examiner]
US 20020186698A1 · Ceniza · 2002 [cited by examiner]
US 20030070003A1 · Chong · 2003 [cited by examiner]
US 20040083129A1 · Herz · 2004 [cited by examiner]
US 20040167893A1 · Matsunaga · 2004 [cited by examiner]
US 20050065754A1 · Schaf · 2005 [cited by examiner]
US 20070118909A1 · Hertzog · 2007 [cited by examiner]
US 20070294187A1 · Scherrer · 2007 [cited by examiner]
US 20080005137A1 · Surendran · 2008 [cited by examiner]
US 20080077358A1 · Marvasti · 2008 [cited by examiner]
US 20080109730A1 · Coffman · 2008 [cited by examiner]
US 20090106174A1 · Battisha · 2009 [cited by examiner]
US 20090254971A1 · Herz · 2009 [cited by examiner]
US 20100009357A1 · Nevins · 2010 [cited by examiner]
US 20100095374A1 · Gillum · 2010 [cited by examiner]
US 20100107254A1 · Eiland · 2010 [cited by examiner]
US 20100125908A1 · Kudo · 2010 [cited by examiner]
US 20100235908A1 · Eynon · 2010 [cited by examiner]
US 20100299292A1 · Collazo · 2010 [cited by examiner]
US 20110093428A1 · Wisse · 2011 [cited by examiner]
US 20110213742A1 · Lemmond · 2011 [cited by examiner]
US 20110261710A1 · Chen · 2011 [cited by examiner]
US 20120096549A1 · Amini · 2012 [cited by examiner]
US 20120137367A1 · Dupont · 2012 [cited by examiner]
US 20120209575A1 · Barbat · 2012 [cited by examiner]
US 20120210388A1 · Kolishchak · 2012 [cited by examiner]
US 20120284791A1 · Miller · 2012 [cited by examiner]
US 20120304288A1 · Wright · 2012 [cited by examiner]
US 20130091539A1 · Khurana · 2013 [cited by examiner]
US 20130145418A1 · Stein · 2013 [cited by examiner]
US 20130198119A1 · Eberhardt, III · 2013 [cited by examiner]
US 20130198840A1 · Drissi · 2013 [cited by examiner]
US 20130254885A1 · Devost · 2013 [cited by examiner]
US 20140007237A1 · Wright et al. · 2014 [cited by applicant]
US 20140074762A1 · Campbell · 2014 [cited by examiner]
US 20140165207A1 · Engel · 2014 [cited by examiner]
US 20140215618A1 · Striem Amit · 2014 [cited by examiner]
US 20140325643A1 · Bart · 2014 [cited by examiner]
US 20150067835A1 · Chari · 2015 [cited by examiner]
US 20150081431A1 · Akahoshi · 2015 [cited by examiner]
US 20150161394A1 · Ferragut · 2015 [cited by examiner]
US 20150163121A1 · Mahaffey · 2015 [cited by examiner]
US 20150172300A1 · Cochenour · 2015 [cited by examiner]
US 20150180893A1 · Im · 2015 [cited by examiner]
US 20150213358A1 · Shelton · 2015 [cited by examiner]
US 20150264084A1 · Kashyap · 2015 [cited by examiner]
US 20150281287A1 · Gill · 2015 [cited by examiner]
US 20150286819A1 · Coden · 2015 [cited by examiner]
US 20150310195A1 · Bailor · 2015 [cited by examiner]
US 20150319185A1 · Kirti · 2015 [cited by examiner]
US 20150341379A1 · Lefebvre · 2015 [cited by examiner]
US 20150363699A1 · Nikovski · 2015 [cited by examiner]
US 20150379110A1 · Marvasti · 2015 [cited by examiner]
US 20160062950A1 · Brodersen · 2016 [cited by examiner]
US 20160078365A1 · Baumard · 2016 [cited by examiner]
US 20160149941A1 · Thakur · 2016 [cited by examiner]
US 20160164902A1 · Moore · 2016 [cited by examiner]
US 20160173509A1 · Ray · 2016 [cited by examiner]
US 20160241576A1 · Rathod · 2016 [cited by examiner]
US 20160352768A1 · Lefebvre et al. · 2016 [cited by applicant]
US 20160359695A1 · Yadav · 2016 [cited by examiner]
US 20160373476A1 · Dell'Anno · 2016 [cited by examiner]
US 20160373477A1 · Moyle · 2016 [cited by examiner]
US 20170054745A1 · Zhang · 2017 [cited by examiner]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170161503A1 · Seigel · 2017 [cited by examiner]
US 20170169360A1 · Veeramachaneni · 2017 [cited by examiner]
US 20170212959A1 · Li · 2017 [cited by examiner]
US 20170270422A1 · Sorakado · 2017 [cited by examiner]
US 20180027006A1 · Zimmermann · 2018 [cited by examiner]
US 20180167402A1 · Scheidler · 2018 [cited by examiner]
US 20180375877A1 · Jakobsson · 2018 [cited by examiner]
US 20180375886A1 · Kirti · 2018 [cited by examiner]
US 20190028509A1 · Cidon · 2019 [cited by examiner]
US 20190036948A1 · Appel · 2019 [cited by examiner]
US 20190044963A1 · Rajasekharan · 2019 [cited by examiner]
US 20190141057A1 · Burgis · 2019 [cited by examiner]
US 20190251260A1 · Stockdale et al. · 2019 [cited by applicant]
US 20190306167A1 · LaManna · 2019 [cited by examiner]
US 20200021620A1 · Purathepparambil · 2020 [cited by examiner]
US 20200067861A1 · Leddy · 2020 [cited by examiner]
US 20200089848A1 · Abdelaziz · 2020 [cited by examiner]
US 20200177614A1 · Burns · 2020 [cited by examiner]
US 20200244673A1 · Stockdale · 2020 [cited by examiner]
US 20200280575A1 · Dean et al. · 2020 [cited by applicant]
US 20200286015A1 · Richards · 2020 [cited by examiner]
US 20210119951A1 · Santos · 2021 [cited by examiner]
US 20210120027A1 · Dean et al. · 2021 [cited by applicant]
US 20210152596A1 · Hemingway · 2021 [cited by examiner]
US 20210157919A1 · Stockdale et al. · 2021 [cited by applicant]
US 20210273958A1 · McLean · 2021 [cited by examiner]
US 20210360027A1 · Boyer · 2021 [cited by examiner]
EP 2922268A1 · 2015 [cited by applicant]
WO 2001031420A2 · 2001 [cited by applicant]
WO 2008121945A2 · 2008 [cited by applicant]
WO 2013053407A1 · 2013 [cited by applicant]
WO 2014088912A1 · 2014 [cited by applicant]
WO 2015027828A1 · 2015 [cited by applicant]
WO 2016020660A1 · 2016 [cited by applicant]
WO 2019243579A1 · 2019 [cited by applicant]
WO 2020021100A1 · 2020 [cited by applicant]
Abdallah Abbey Sebyala et al., “Active Platform Security through Intrusion Detection Using Naive Bayesian Network for Anomaly Detection,” Department of Electronic and Electrical Engineering, 5 pages, University College … [cited by applicant]
Marek Zachara et al., “Detecting Unusual User Behavior to Identify Hijacked Internet Auctions Accounts,” Lecture Notes in Computer Science, 2012, vol. 7465, Springer, Berlin, Heidelberg, Germany. [cited by applicant]
Gharan, Shayan Oveis, “Lecture 11; Clustering and the Spectral Partitioning Algorithm” May 2, 2016, 6 pages. [cited by applicant]
Nikolystylfw, “Can Senseon beat Darktrace at its very own game with its ‘An I triangulation’ modern technology?” Dec. 22, 2018, nikolystylfw. [cited by applicant]
Lunden, Ingrid, “Senseon raises $6.4M to tackle cybersecurity threats with an AI ‘triangulation’ approach” Feb. 19, 2019, Tech Crunch. [cited by applicant]
Senseon Tech Ltd., “The State of Cyber Security SME Report 2019” Jun. 3, 2019, 16 pages. [cited by applicant]
Caithness, Neil, “Supervised/unsupervised cross-over method for autonomous anomaly classification,” Oct. 25, 2019, CAMLIS 2019. [cited by applicant]
Senseon Tech Ltd., “Technology,” * please see the statement filed herewith. [cited by applicant]
Senseon Tech Ltd., “Senseon & You,” * please see the statement filed herewith. [cited by applicant]
Senseon Tech Ltd., “Technology Overview,” * please see the statement filed herewith. [cited by applicant]
Senseon Tech Ltd., “Senseon Enterprise,” * please see the statement filed herewith. [cited by applicant]
Senseon Tech Ltd., “Senseon Pro,” * please see the statement filed herewith. [cited by applicant]
Senseon Tech Ltd., “Senseon Reflex,” please see the statement filed herewith. [cited by applicant]
International Search Authority, The International Search Report and Written Opinion of the International search Authority, 10 pages. [cited by applicant]
Egele Mauel, et al: “Towards Detecting Compromised Accounts on Social Networks”, IEEE Transactions on Dependable and Secure Computing, IEEE Service Center, New Yorkkk, NY, US, vol. 14, No. 4, Jul. 1, 2017, pp. 447-460, … [cited by applicant]
Bimal Viswanath: “Towards Detecting Anomalous User Behavior in Online Aocial Networks”, Aug. 20, 2014, XP093167123, Retrieved from the Internet: URL: https://www.usenix.org/system/files/conference/usebixsecurity14/sec14… [cited by applicant]
Dai Wei, et al: “Abnormal user detection based on instant messages”, 2014 International Conference on Machin Learning and Cybernetics, IEEE, vol. 2, Jul. 13, 2014, pp. 831-837, XP032721580, ISSN: 2160-1333X, DOI: 10.110… [cited by applicant]
European Patent Office, Supplementary European Search Report, Jun. 13, 2024, 7 pages. [cited by applicant]