IP Library Granted Patent US 11,477,235
Granted Patent B2
US 11,477,235 · App. 17/401,161 · Granted Oct 18, 2022

Approaches to creating, managing, and applying a federated database to establish risk posed by third parties

Inventors: Jeshua Alexis Bratman (Brooklyn, NY); Yu Zhou Lee (San Francisco, CA); Lawrence Stockton Moore (Palo Alto, CA); Rami Faris Habal (San Francisco, CA); Lei Xu (New York, NY)
Assignee: Abnormal Security Corporation
H04L63/1483G06F16/256G06F16/335G06Q10/0635G06Q10/107H04L51/212H04L51/214H04L63/14H04L63/1408H04L63/1433H04L63/1441H04L67/30H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,477,235
App. No.
17/401,161
Granted
Oct 18, 2022
Kind
B2
Abstract

Introduced here are computer programs and computer-implemented techniques for generating and then managing a federated database that can be used to ascertain the risk in interacting with vendors. At a high level, the federated database allows knowledge regarding the reputation of vendors to be shared amongst different enterprises with which those vendors may interact. A threat detection platform may utilize the federated database when determining how to handle incoming emails from vendors.

Claims (50)

1. A method comprising:

obtaining, by a threat detection platform, an email that originates from a domain associated with a first vendor and is addressed to an email account associated with a first enterprise;

applying, by the threat detection platform, a model to the email to establish whether the email represents a risk to a recipient to whom the email is addressed;

determining, by the threat detection platform, that the email is malicious based on an output produced by the model;

creating, by the threat detection platform, a first digital profile for the first vendor, including by populating a data structure with information regarding a feature of the email that influenced the output produced by the model; and

storing, by the threat detection platform, the first digital profile in a federated database that can be used to establish risk in interacting with vendors, wherein the federated database includes a plurality of digital profiles that are collectively associated with a plurality of different vendors, wherein at least some data stored in the first digital profile is generated by examining an email addressed to a second enterprise, wherein the first digital profile includes a temporal record of emails from the first vendor, and wherein the temporal record of emails is updated by the threat detection platform as emails are determined to have been sent by the first vendor to either of the first enterprise or the second enterprise.

2. The method of claim 1 , wherein the information is extracted or derived from the email or accompanying metadata.

3. The method of claim 1 , wherein the output produced by the model is indicative of a likelihood that the email is malicious.

4. The method of claim 1 , wherein the output produced by the model is indicative of a likelihood that the email is a given type of malicious email.

5. The method of claim 1 , wherein the first digital profile includes a record of vendor email addresses from which emails examined by the threat detection platform have originated.

6. The method of claim 1 , wherein each digital profile in the plurality of digital profiles is independently updated as new emails originating from a corresponding vendor are analyzed for threat detection purposes.

7. The method of claim 1 , wherein the first digital profile includes:

(i) a classification assigned to the first vendor based on an analysis of emails originating from the first vendor,

(ii) a record of vendor email addresses from which contact has been initiated on behalf of the first vendor, and

(iii) a record of enterprise email addresses with which contact has been initiated by one or more emails corresponding to the first vendor.

8. The method of claim 7 , wherein the first digital profile further includes:

(iv) information regarding types of attacks, if any, that one or more email addresses corresponding to the first vendor were found to have carried out.

9. The method of claim 1 , wherein the first digital profile is updated as new emails that originate from the domain associated with the first vendor are analyzed for threat detection purposes.

10. The method of claim 1 , wherein the feature includes at least one of: a vendor email address, a geographical origin, or content.

11. The method of claim 1 , further comprising:

obtaining an email that is addressed to an employee of an enterprise;

establishing that the obtained email that is addressed to the employee of the enterprise represents an instance of outreach by the first vendor; and

determining, based on an analysis of the first digital profile created for the first vendor, how to handle the obtained email that is addressed to the employee of the enterprise.

12. The method of claim 11 , wherein said determining based on the analysis of the first digital profile created for the vendor involves establishing a degree of similarity between the obtained email that is addressed to the employee of the enterprise and past emails that originated from the domain associated with the first vendor.

13. A system comprising:

a processor configured to:

obtain an email that originates from a domain associated with a first vendor and is addressed to an email account associated with a first enterprise;

apply a model to the email to establish whether the email represents a risk to a recipient to whom the email is addressed;

determine that the email is malicious based on an output produced by the model;

create a first digital profile for the first vendor, including by populating a data structure with information regarding a feature of the email that influenced the output produced by the model; and

store the first digital profile in a federated database that can be used to establish risk in interacting with vendors, wherein the federated database includes a plurality of digital profiles that are collectively associated with a plurality of different vendors, wherein at least some data stored in the first digital profile is generated by examining an email addressed to a second enterprise, wherein the first digital profile includes a temporal record of emails from the first vendor, and wherein the temporal record of emails is updated by a threat detection platform as emails are determined to have been sent by the first vendor to either of the first enterprise or the second enterprise; and

a memory coupled to the processor and configured to provide the processor with instructions.

14. The system of claim 13 , wherein the information is extracted or derived from the email or accompanying metadata.

15. The system of claim 13 , wherein the output produced by the model is indicative of a likelihood that the email is malicious.

16. The system of claim 13 , wherein the output produced by the model is indicative of a likelihood that the email is a given type of malicious email.

17. The system of claim 13 , wherein the first digital profile includes a record of vendor email addresses from which emails examined by the threat detection platform have originated.

18. The system of claim 13 , wherein each digital profile in the plurality of digital profiles is independently updated as new emails originating from a corresponding vendor are analyzed for threat detection purposes.

19. The system of claim 13 , wherein the first digital profile includes:

(i) a classification assigned to the first vendor based on an analysis of emails originating from the first vendor,

(ii) a record of vendor email addresses from which contact has been initiated on behalf of the first vendor, and

(iii) a record of enterprise email addresses with which contact has been initiated by one or more emails corresponding to the first vendor.

20. The system of claim 19 , wherein the first digital profile further includes:

(iv) information regarding types of attacks, if any, that one or more email addresses corresponding to the first vendor were found to have carried out.

21. The system of claim 13 , wherein the first digital profile is updated as new emails that originate from the domain associated with the first vendor are analyzed for threat detection purposes.

22. The system of claim 13 , wherein the feature includes at least one of: a vendor email address, a geographical origin, or content.

23. The system of claim 13 , wherein the processor is further configured to:

obtain an email that is addressed to an employee of an enterprise;

establish that the obtained email that is addressed to the employee of the enterprise represents an instance of outreach by the first vendor; and

determine, based on an analysis of the first digital profile created for the first vendor, how to handle the obtained email that is addressed to the employee of the enterprise.

24. The method of claim 23 , wherein said determining based on the analysis of the first digital profile created for the vendor involves establishing a degree of similarity between the obtained email that is addressed to the employee of the enterprise and past emails that originated from the domain associated with the first vendor.

Continuity (3)
Division 17185570 · Feb 25, 2021
Provisional Application 62983444 · Feb 28, 2020
Related Publication 20210374680A1 · Dec 2, 2021
Cited By (1)
US 12,500,927