IP Library Granted Patent US 11,687,648
Granted Patent B2
US 11,687,648 · App. 17/547,141 · Granted Jun 27, 2023

Deriving and surfacing insights regarding security threats

Inventors: Yu Zhou Lee (San Francisco, CA); Kai Jiang (San Francisco, CA); Su Li Debbie Tan (San Francisco, CA); Geng Sng (San Francisco, CA); Cheng-Lin Yeh (San Francisco, CA); Lawrence Stockton Moore (San Francisco, CA); Sanny Xiao Lang Liao (San Francisco, CA); Joey Esteban Cerquera (San Francisco, CA); Jeshua Alexis Bratman (San Francisco, CA); Sanjay Jeyakumar (San Francisco, CA); Nishant Bhalchandra Karandikar (San Francisco, CA)
Assignee: Abnormal Security Corporation
G06F21/552G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,687,648
App. No.
17/547,141
Granted
Jun 27, 2023
Kind
B2
Abstract

Deriving and surfacing insights regarding security threats is disclosed. A plurality of features associated with a message is determined. A plurality of facet models is used to analyze the determined features. Based at least in part on the analysis, it is determined that the message poses a security threat. A prioritized set of information is determined to be provided as output that is representative of why the message was determined to pose a security threat. At least a portion of the prioritized set of information is provided as output.

Claims (43)

1. A system, comprising:

a processor configured to:

establish, via an application programming interface, a connection with a storage medium that includes a series of communications received by an employee of an enterprise and obtain an email that is addressed to the employee;

determine a plurality of features associated with the obtained email;

use a plurality of facet models to analyze the determined features, wherein at least one facet model included in the plurality of facet models is a topic model that identifies a topic that is mentioned either directly or indirectly in the email;

determine, based at least in part on the analysis, that the email poses a security threat;

determine a prioritized set of information to provide as output in a report, wherein the prioritized set of information is representative of why the email was determined to pose a security threat; and

provide at least a portion of the prioritized set of information as output in an interface; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the processor is further configured to associate the identified topic with the email.

3. The system of claim 1 , wherein the topic model is trained using a corpus of messages labeled as representative of a particular topic.

4. The system of claim 1 , wherein the topic model comprises a set of one or more rules for identifying a message as having a particular topic.

5. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an attack type model that identifies a type of attack of which the email is a part, wherein the attack type is derived based on a combination of other facets.

6. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an attack strategy model that identifies a strategy used in the email to perpetrate an attack.

7. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an impersonated party model that identifies an entity that a sender of the email is attempting to impersonate.

8. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an attacked party model that indicates an entity that is a target of an attack carried out by the email.

9. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an attack goal model that identifies a goal of an attack carried out by the email.

10. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an attack vector model that identifies a mechanism by which an attack is carried out by the email.

11. The system of claim 1 , wherein the prioritized set of information is determined based at least in part on an identity or group membership of a message recipient.

12. A method, comprising:

establishing, via an application programming interface, a connection with a storage medium that includes a series of communications received by an employee of an enterprise and obtaining an email that is addressed to the employee;

determining a plurality of features associated with the obtained email;

using a plurality of facet models to analyze the determined features, wherein at least one facet model included in the plurality of facet models is a topic model that identifies a topic that is mentioned either directly or indirectly in the email;

determining, based at least in part on the analysis, that the email poses a security threat;

determining a prioritized set of information to provide as output in a report, wherein the prioritized set of information is representative of why the email was determined to pose a security threat; and

providing at least a portion of the prioritized set of information as output in an interface.

13. The method of claim 12 , further comprising associating the identified topic with the email.

14. The method of claim 12 , wherein the topic model is trained using a corpus of messages labeled as representative of a particular topic.

15. The method of claim 12 , wherein the topic model comprises a set of one or more rules for identifying a message as having a particular topic.

16. The method of claim 12 , wherein at least one facet model included in the plurality of facet models is an attack type model that identifies a type of attack of which the email is a part, wherein the attack type is derived based on a combination of other facets.

17. The method of claim 12 , wherein at least one facet model included in the plurality of facet models is an attack strategy model that identifies a strategy used in the email to perpetrate an attack.

18. The method of claim 12 , wherein at least one facet model included in the plurality of facet models is an impersonated party model that identifies an entity that a sender of the email is attempting to impersonate.

19. The method of claim 12 , wherein at least one facet model included in the plurality of facet models is an attacked party model that indicates an entity that is a target of an attack carried out by the email.

20. The method of claim 12 , wherein at least one facet model included in the plurality of facet models is an attack goal model that identifies a goal of an attack carried out by the email.

21. The method of claim 12 , wherein at least one facet model included in the plurality of facet models is an attack vector model that identifies a mechanism by which an attack is carried out by the email.

22. The method of claim 12 , wherein the prioritized set of information is determined based at least in part on an identity or group membership of a message recipient.

23. A computer program product embodied in a non-transitory tangible computer readable storage medium and comprising computer instructions for:

establishing, via an application programming interface, a connection with a storage medium that includes a series of communications received by an employee of an enterprise and obtaining an email that is addressed to the employee;

determining a plurality of features associated with the obtained email;

using a plurality of facet models to analyze the determined features, wherein at least one facet model included in the plurality of facet models is a topic model that identifies a topic that is mentioned either directly or indirectly in the email;

determining, based at least in part on the analysis, that the email poses a security threat;

determining a prioritized set of information to provide as output in a report, wherein the prioritized set of information is representative of why the email was determined to pose a security threat; and

providing at least a portion of the prioritized set of information as output in an interface.

Assignments (2)
CHANGE OF NAME Recorded Apr 22, 2025
From: ABNORMAL SECURITY CORPORATION
To: ABNORMAL AI, INC.
Reel/Frame 070947/0132 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2022
From: LEE, YU ZHOU; JIANG, KAI; TAN, SU LI DEBBIE; SNG, GENG; YEH, CHENG-LIN; MOORE, LAWRENCE STOCKTON; LIAO, SANNY XIAO LANG; CERQUERA, JOEY ESTEBAN; BRATMAN, JESHUA ALEXIS; JEYAKUMAR, SANJAY; KARANDIKAR, NISHANT BHALCHANDRA
To: ABNORMAL SECURITY CORPORATION
Reel/Frame 059738/0163 →
Continuity (2)
Provisional Application 63123865 · Dec 10, 2020
Related Publication 20220188411A1 · Jun 16, 2022
Cited By (1)
US 12,699,578