IP Library Granted Patent US 11,902,302
Granted Patent B2
US 11,902,302 · App. 17/461,471 · Granted Feb 13, 2024

Systems and methods for efficient combining of characteristc detection rules

Inventors: Marcio Castilho (Palm Harbor, FL); Alin Irimie (Palm Harbor, FL); Michael Hanley (Palm Harbor, FL); Daniel Cormier (Clearwater, FL); Raymond Skinner (Dunedin, FL)
Assignee: KnowBe4, Inc.
H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,902,302
App. No.
17/461,471
Granted
Feb 13, 2024
Kind
B2
Abstract

System and methods are described which are useful for efficiently combining characteristic detection rules, such as may be done to efficiently and quickly assist in the dispositioning of user reported security threats.

Claims (27)

1. A method comprising:

identifying, by the device, one or more indexes of one or more characteristic detection rules within a combination rule that have one of a binary or textual pattern that match at least a portion of an electronic communication received by the device, each of the one or more indexes identifying a position of a respective characteristic detection rule within the combination rule, each of the one or more characteristic detection rules having a revision identifier;

determining, by the device, that the combination rule matches the electronic communication based at least on applying at least one or more logical operators of the combination rule to at least the one or more characteristic detection rules identified by the one or more indexes;

identifying, by the device using the revision identifier, historical versions of each of the one or more characteristic detection rules; and

identifying, by the device using the revisions identifier, whether a previous version of each of the one or more characteristic detection rules matched a previous electronic communication.

2. The method of claim 1 , further comprising determining, by the device, that the previous version of one of the one or more characteristic detection rules did match the previous electronic communication.

3. The method of claim 1 , further comprising determining, by the device, that the previous version of one of the one or more characteristic detection rules did not match the previous electronic communication.

4. The method of claim 3 , further comprising identifying, by the device, that a malicious electronic communication may have been received by the device undetected.

5. The method of claim 1 , wherein a condition of each of the one or more characteristic detection rules comprises the revision identifier.

6. The method of claim 1 , wherein the revision identifier is represented by a string.

7. The method of claim 1 , further comprising tracking, by the device, versions of each of the one or more characteristic detection rules over time using the revision identifier.

8. The method of claim 1 , wherein a description of each of one or more characteristic detection rules is based at least on one of the binary or textual pattern.

9. The method of claim 1 , further comprising determining, by the device, a classification score for the electronic communication based at least on which one of the one or more characteristic detection rules matched the electronic communication.

10. A system comprising;

one or more processors, coupled to memory device and configured to:

identify one or more indexes of one or more characteristic detection rules within a combination rule that have one of a binary or textual pattern that match at least a portion of an electronic communication received by the device, each of the one or more indexes identifying a position of a respective characteristic detection rule within the combination rule, each of the one or more characteristic detection rules having a revision identifier;

determine that the combination rule matches the electronic communication based at least on applying at least one or more logical operators of the combination rule to at least the one or more characteristic detection rules identified by the one or more indexes;

identify, using the revision identifier, historical versions of each of the one or more characteristic detection rules; and

identify, using the revisions identifier, whether a previous version of each of the one or more characteristic detection rules matched a previous electronic communication.

11. The system of claim 10 , wherein the one or more processors are further configured to determine that the previous version of one of the one or more characteristic detection rules did match the previous electronic communication.

12. The system of claim 10 , wherein the one or more processors are further configured to determine that the previous version of one of the one or more characteristic detection rules did not match the previous electronic communication.

13. The system of claim 12 , wherein the one or more processors are further configured to identify that a malicious electronic communication may have been received by the device undetected.

14. The system of claim 10 , wherein a condition of each of the one or more characteristic detection rules comprises the revision identifier.

15. The system of claim 10 , wherein the revision identifier is represented by a string.

16. The system of claim 10 wherein the one or more processors are further configured to track versions of each of the one or more characteristic detection rules over time using the revision identifier.

17. The system of claim 10 , wherein a description of each of one or more characteristic detection rules is based at least on one of the binary or textual pattern.

18. The system of claim 10 , wherein the one or more processors are further configured to determine a classification score for the electronic communication based at least on which one of the one or more characteristic detection rules matched the electronic communication.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2021
From: CASTILHO, MARCIO; IRIMIE, ALIN; HANLEY, MICHAEL; CORMIER, DANIEL; SKINNER, RAYMOND
To: KNOWBE4, INC.
Reel/Frame 057370/0088 →