IP Library Granted Patent US 11,966,469
Granted Patent B2
US 11,966,469 · App. 17/324,997 · Granted Apr 23, 2024

Detecting and protecting against cybersecurity attacks using unprintable tracking characters

Inventor: Thomas Lee (Kensington, CA)
Assignee: Proofpoint, Inc.
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,966,469
App. No.
17/324,997
Granted
Apr 23, 2024
Kind
B2
Abstract

Aspects of the disclosure relate to detecting and protecting against cybersecurity attacks using unprintable tracking characters. A computing platform may receive a character-limited message sent to a user device. Subsequently, the computing platform may detect that the character-limited message sent to the user device includes suspicious content. Then, the computing platform may generate a modified character-limited message by inserting one or more special characters into the character-limited message and cause transmission of the modified character-limited message to the user device. Next, the computing platform may receive, from the user device, a spam report that includes the modified character-limited message. Then, the computing platform may identify a presence of the one or more special characters included in the modified character-limited message and adjust one or more filters based on the identification.

Claims (61)

1. A computing platform, comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive, via the communication interface, a character-limited message sent to a user device;

scan the character-limited message to evaluate the character-limited message for suspicious content;

detect, based on the scan, that the character-limited message sent to the user device comprises suspicious content;

responsive to detecting that the character-limited message sent to the user device comprises the suspicious content, generate a modified character-limited message by selecting and inserting one or more unprintable characters into the character-limited message, wherein:

selecting and inserting the one or more unprintable characters into the character-limited message includes detecting a length of the character-limited message and inserting the one or more unprintable characters based on a number of available unused characters in the character-limited message,

the one or more unprintable characters are configured to track the character-limited message comprising the suspicious content and identify a confidence level, determined upon scanning the character-limited message, indicative of a confidence that the suspicious content is suspicious, and

the one or more unprintable characters include different unprintable characters indicating different confidence levels;

cause transmission of the modified character-limited message to the user device;

receive, via the communication interface, from the user device, a spam report confirming that the character-limited message comprises the suspicious content that is suspicious, wherein the spam report includes the modified character-limited message;

identify a presence of the one or more unprintable characters included in the modified character-limited message; and

adjust one or more filters based on identifying the presence of the one or more unprintable characters included in the modified character-limited message.

2. The computing platform of claim 1 , wherein the one or more unprintable characters indicates a type of messaging associated with the character-limited message sent to the user device.

3. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

prior to detecting that the character-limited message sent to the user device comprises the suspicious content, classify the character-limited message based on message type.

4. The computing platform of claim 1 , wherein generating the modified character-limited message by inserting the one or more unprintable characters into the character-limited message further comprises:

prioritizing the one or more unprintable characters for insertion based on one or more criteria; and

inserting the one or more unprintable characters based on the prioritization.

5. The computing platform of claim 1 , wherein the character-limited message comprises at least one of a short message service (SMS) message or a multimedia messaging service (MMS) message.

6. The computing platform of claim 1 , wherein adjusting the one or more filters comprises modifying one or more filter criteria based on an aggregate of character-limited messages identified as comprising actually suspicious content.

7. The computing platform of claim 1 , wherein adjusting the one or more filters comprises allowing more character-limited messages to pass through to the user device.

8. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive, via the communication interface, an additional character-limited message sent to the user device;

based on the adjusted one or more filters, detect that the additional character-limited message sent to the user device comprises the suspicious content; and

based on detecting that the additional character-limited message sent to the user device comprises the suspicious content, execute one or more security actions.

9. The computing platform of claim 8 , wherein executing the one or more security actions comprises blocking the additional character-limited message or inserting a warning message into the additional character-limited message.

10. A method, comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

receiving, by the at least one processor, a character-limited message sent to a user device;

scanning, by the at least one processor, the character-limited message to evaluate the character-limited message for suspicious content;

detecting, by the at least one processor and based on the scanning, that the character-limited message sent to the user device comprises suspicious content;

responsive to detecting that the character-limited message sent to the user device comprises the suspicious content, generating, by the at least one processor, a modified character-limited message by selecting and inserting one or more unprintable characters into the character-limited message, wherein:

selecting and inserting the one or more unprintable characters into the character-limited message includes detecting a length of the character-limited message and inserting the one or more unprintable characters based on a number of available unused characters in the character-limited message,

the one or more unprintable characters are configured to track the character-limited message comprising the suspicious content and identify a confidence level, determined upon scanning the character-limited message, indicative of a confidence that the suspicious content is suspicious, and

the one or more unprintable characters include different unprintable characters indicating different confidence levels;

causing, by the at least one processor, transmission of the modified character-limited message to the user device;

receiving, by the at least one processor, from the user device, a spam report confirming that the character-limited message comprises the suspicious content that is suspicious, wherein the spam report includes the modified character-limited message;

identifying, by the at least one processor, a presence of the one or more unprintable characters included in the modified character-limited message; and

adjusting, by the at least one processor, one or more filters based on identifying the presence of the one or more unprintable characters included in the modified character-limited message.

11. The method of claim 10 , wherein generating the modified character-limited message by inserting the one or more unprintable characters into the character-limited message further comprises:

prioritizing, by the at least one processor, the one or more unprintable characters for insertion based on one or more criteria; and

inserting, by the at least one processor, the one or more unprintable characters based on the prioritization.

12. The method of claim 10 , further comprising:

receiving, by the at least one processor, an additional character-limited message sent to the user device;

based on the adjusted one or more filters, detecting, by the at least one processor, that the additional character-limited message sent to the user device comprises the suspicious content; and

based on detecting that the additional character-limited message sent to the user device comprises the suspicious content, executing, by the at least one processor, one or more security actions.

13. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

receive, via the communication interface, a character-limited message sent to a user device;

scan the character-limited message to evaluate the character-limited message for suspicious content;

detect, based on the scan, that the character-limited message sent to the user device comprises suspicious content;

responsive to detecting that the character-limited message sent to the user device comprises the suspicious content, generate a modified character-limited message by selecting and inserting one or more unprintable characters into the character-limited message, wherein:

selecting and inserting the one or more unprintable characters into the character-limited message includes detecting a length of the character-limited message and inserting the one or more unprintable characters based on a number of available unused characters in the character-limited message,

the one or more unprintable characters are configured to track the character-limited message comprising the suspicious content and identify a confidence level, determined upon scanning the character-limited message, indicative of a confidence that the suspicious content is suspicious, and

the one or more unprintable characters include different unprintable characters indicating different confidence levels;

cause transmission of the modified character-limited message to the user device;

receive, via the communication interface, from the user device, a spam report confirming that the character-limited message comprises the suspicious content that is suspicious, wherein the spam report includes the modified character-limited message;

identify a presence of the one or more unprintable characters included in the modified character-limited message; and

adjust one or more filters based on identifying the presence of the one or more unprintable characters included in the modified character-limited message.

Assignments (5)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Mar 21, 2024
From: GOLDMAN SACHS BANK USA, AS AGENT
To: PROOFPOINT, INC.
Reel/Frame 066865/0648 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0615 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0642 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2021
From: LEE, THOMAS
To: PROOFPOINT, INC.
Reel/Frame 056297/0534 →