IP Library Granted Patent US 11,997,115
Granted Patent B1
US 11,997,115 · App. 17/510,380 · Granted May 28, 2024

Message platform for automated threat simulation, reporting, detection, and remediation

Inventors: Aaron Higbee (Leesburg, VA); David Chamberlain (New Boston, NH); Vineetha Philip (Fairfax Station, VA)
Assignee: Cofense Inc.
H04L63/1416G06F16/35G06F21/00G06F21/554H04L51/212H04L63/1433H04L63/1483H04L63/1491H04L63/20H04L51/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,997,115
App. No.
17/510,380
Granted
May 28, 2024
Kind
B1
Abstract

Methods, network devices, and machine-readable media for an integrated environment and platform for automated processing of reports of suspicious messages, and further including automated threat simulation, reporting, detection, and remediation, including rapid quarantine and restore functions.

Claims (43)

1. A computerized method for suspicious message processing and incident response, comprising:

receiving a report at a threat detection platform of a potentially suspicious message delivered into a user account, the report being generated as a result of an action by the user indicating that the message has been identified by the user as a potential security threat, and

wherein the report having been initiated by a user interface element in an email client, and

wherein the report comprises a copy of the delivered message;

electronically storing defined textual or binary patterns associated with at least one security threat;

processing the received message according to the electronically stored patterns to determine if the body of the received message or an attachment of the received message contains the defined textual or binary patterns associated with the security threat;

if the received message contains the defined textual or binary patterns associated with the security threat, then:

transmitting a message identifier and associated account identifier for the received message to an email server in association with a command to move the received message from an inbox associated with the user account;

based on the received message, generating a simulated phishing message;

establishing a privileged account connection to an administrative account on the email server to access multiple user email accounts; and

using the privileged account, inserting the simulated phishing message into one or more of the accessed multiple user email accounts.

2. The method of claim 1 , wherein the inserting of the simulated phishing message is performed only after a user activity action has been detected on the one or more multiple user email accounts.

3. The method of claim 1 , further comprising:

transmitting a command to the email server to return one or more message identifiers and associated account identifiers for other messages having the defined textual or binary patterns associated with the security threat;

receiving the message identifiers and account identifiers for the other messages having the defined textual or binary patterns associated with the security threat;

transmitting the message identifiers and account identifiers to the email server in association with a command to move the messages from user account inboxes.

4. The method of claim 1 , further comprising:

at the email server:

receiving copies of incoming email messages;

parsing the incoming email messages into Multipurpose Internet Mail Extension components; and

storing the message components in a data store, each of the messages components being stored as a separate field in a database in the data store, each of the fields being stored in association with a unique message identifier for the message.

5. A computerized system for suspicious message processing and incident response, comprising:

a processor at a threat detection platform configured with executable instructions for:

receiving a report at a threat detection platform of a potentially suspicious message delivered into a user account, the report being generated as a result of an action by the user indicating that the message has been identified by the user as a potential security threat, and

wherein the report having been initiated by a user interface element in an email client, and

wherein the report comprises a copy of the delivered message;

electronically storing defined textual or binary patterns associated with at least one security threat;

processing the received message according to the electronically stored patterns to determine if the body of the received message or an attachment of the received message contains the defined textual or binary patterns associated with the security threat;

if the received message contains the defined textual or binary patterns associated with the security threat, then:

transmitting a message identifier and associated account identifier for the received message to an email server in association with a command to move the received message from an inbox associated with the user account;

based on the received message, generating a simulated phishing message;

establishing a privileged account connection to an administrative account on the email server to access multiple user email accounts; and

using the privileged account, inserting the simulated phishing message into one or more of the accessed multiple user email accounts.

6. The system of claim 5 , wherein the inserting of the simulated phishing message is performed only after a user activity action has been detected on the one or more multiple user email accounts.

7. The system of claim 5 , further comprising instructions for:

transmitting a command to the email server to return one or more message identifiers and associated account identifiers for other messages having the defined textual or binary patterns associated with the security threat;

receiving the message identifiers and account identifiers for the other messages having the defined textual or binary patterns associated with the security threat;

transmitting the message identifiers and account identifiers to the email server in association with a command to move the messages from user account inboxes.

8. The system of claim 5 , further comprising instructions for:

at the email server:

receiving copies of incoming email messages;

parsing the incoming email messages into Multipurpose Internet Mail Extension components; and

storing the message components in a data store, each of the messages components being stored as a separate field in a database in the data store, each of the fields being stored in association with a unique message identifier for the message.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE BLUE TORCH FINANCE LLC PREVIOUSLY RECORDED ON REEL 059800 FRAME 0834. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded May 5, 2023
From: COFENSE INC.
To: BLUE TORCH FINANCE LLC
Reel/Frame 064381/0245 →
SECURITY INTEREST Recorded May 3, 2022
From: COFENSE INC.
To: BLUE TORCH CAPITAL LP
Reel/Frame 059800/0834 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2022
From: HIGBEE, AARON; CHAMBERLAIN, DAVID; PHILIP, VINEETHA
To: COFENSE INC.
Reel/Frame 059764/0585 →
Continuity (10)
Continuation 16801130 · Feb 25, 2020
Continuation In Part 16532449 · Aug 5, 2019
Continuation 16418973 · May 21, 2019
Continuation 15905784 · Feb 26, 2018
Continuation In Part 15584002 · May 1, 2017
Continuation 14986515 · Dec 31, 2015
Continuation In Part 16181122 · Nov 5, 2018
Provisional Application 62810369 · Feb 25, 2019
Provisional Application 62581637 · Nov 3, 2017
Provisional Application 62145778 · Apr 10, 2015
Cited By (5)
US 12,355,812 US 12,519,806 US 12,519,830 US 12,592,964 US 12,598,212