IP Library Granted Patent US 11,831,661
Granted Patent B2
US 11,831,661 · App. 17/831,335 · Granted Nov 28, 2023

Multi-tiered approach to payload detection for incoming communications

Inventors: Yu Zhou Lee (San Francisco, CA); Micah J. Zirn (San Francisco, CA); Umut Gultepe (San Francisco, CA); Jeshua Alexis Bratman (San Francisco, CA); Michael Douglas Kralka (San Francisco, CA); Cheng-Lin Yeh (San Francisco, CA); Dmitry Chechik (San Francisco, CA); Sanjay Jeyakumar (San Francisco, CA)
Assignee: Abnormal Security Corporation
H04L63/1416H04L51/08H04L51/212H04L63/145H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,831,661
App. No.
17/831,335
Granted
Nov 28, 2023
Kind
B2
Abstract

A plurality of features associated with a message are determined. At least one feature included in the plurality of features is associated with a payload of the message. A determination is made that supplemental analysis should be performed on the message. The determination is based at least in part on performing behavioral analysis using at least some of the features included in the plurality of features. Supplemental analysis is performed.

Claims (40)

1. A system, comprising:

a processor configured to:

determine a plurality of features associated with a message, wherein at least one feature included in the plurality of features is associated with a payload of the message, wherein the payload comprises at least one link;

determine, based at least in part by a primary scoring module performing behavioral analysis using at least some of the features included in the plurality of features, that a threat potentially posed by the message is neither definitively malicious or definitively benign, and in response flag the message as a candidate for supplemental analysis offloaded to a secondary scoring module; and

perform, by the secondary scoring module, the supplemental analysis, including by performing payload analysis comprising determining, from a set of links, a subset of links upon which to perform link analysis; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the processor is further configured to retrieve the message by establishing, via an application programming interface (API), a connection with a storage medium that includes a series of communications received by an employee of an enterprise.

3. The system of claim 1 , wherein performing the behavioral analysis includes evaluating content for a deviation from a history.

4. The system of claim 3 , wherein performing the behavioral analysis includes determining that a sender has deviated from a historical profile.

5. The system of claim 3 , wherein performing the behavioral analysis includes determining that receipt of the message by a recipient deviates from a historical profile.

6. The system of claim 1 , wherein performing the payload analysis includes performing file analysis on an attachment.

7. The system of claim 6 , wherein performing the payload analysis includes unzipping the attachment.

8. The system of claim 6 , wherein performing the payload analysis includes determining whether a macro is present in the attachment.

9. The system of claim 6 , wherein performing the payload analysis includes preferentially evaluating a first sheet of a spreadsheet.

10. The system of claim 6 , wherein performing the payload analysis includes performing Optical Character Recognition on at least a portion of the attachment.

11. The system of claim 10 , wherein the portion comprises a first page of a multi-page document.

12. The system of claim 1 , wherein the processor is further configured to perform link analysis, including by determining whether a link included in the message comprises an unsubscribe link.

13. The system of claim 1 , wherein the processor is further configured to perform link analysis, including by parsing anchor text.

14. The system of claim 1 , wherein the processor is further configured to perform link analysis, including by establishing a path to a file download.

15. A method, comprising:

determining a plurality of features associated with a message, wherein at least one feature included in the plurality of features is associated with a payload of the message, wherein the payload comprises at least one link;

determining, based at least in part by a primary scoring module performing behavioral analysis using at least some of the features included in the plurality of features, that a threat potentially posed by the message is neither definitively malicious or definitively benign, and in response flag the message as a candidate for supplemental analysis offloaded to a secondary scoring module; and

performing, by the secondary scoring module, the supplemental analysis, including by performing payload analysis comprising determining, from a set of links, a subset of links upon which to perform link analysis.

16. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

determining a plurality of features associated with a message, wherein at least one feature included in the plurality of features is associated with a payload of the message, wherein the payload comprises at least one link;

determining, based at least in part by a primary scoring module performing behavioral analysis using at least some of the features included in the plurality of features, that a threat potentially posed by the message is neither definitively malicious or definitively benign, and in response flag the message as a candidate for supplemental analysis offloaded to a secondary scoring module; and

performing, by the secondary scoring module, the supplemental analysis, including by performing payload analysis comprising determining, from a set of links, a subset of links upon which to perform link analysis.

17. The method of claim 15 , further comprising retrieving the message by establishing, via an application programming interface (API), a connection with a storage medium that includes a series of communications received by an employee of an enterprise.

18. The method of claim 15 , wherein performing the behavioral analysis includes evaluating content for a deviation from a history.

19. The method of claim 18 , wherein performing the behavioral analysis includes determining that a sender has deviated from a historical profile.

20. The method of claim 18 , wherein performing the behavioral analysis includes determining that receipt of the message by a recipient deviates from a historical profile.

21. The method of claim 15 , wherein performing the payload analysis includes performing file analysis on an attachment.

22. The method of claim 21 , wherein performing the payload analysis includes unzipping the attachment.

23. The method of claim 21 , wherein performing the payload analysis includes determining whether a macro is present in the attachment.

24. The method of claim 21 , wherein performing the payload analysis includes preferentially evaluating a first sheet of a spreadsheet.

25. The method of claim 21 , wherein performing the payload analysis includes performing Optical Character Recognition on at least a portion of the attachment.

26. The method of claim 25 , wherein the portion comprises a first page of a multi-page document.

27. The method of claim 15 , further comprising performing link analysis including by determining whether a link included in the message comprises an unsubscribe link.

28. The method of claim 15 , further comprising performing link analysis including by parsing anchor text.

29. The method of claim 15 , further comprising performing link analysis including by establishing a path to a file download.

Assignments (2)
CHANGE OF NAME Recorded Apr 22, 2025
From: ABNORMAL SECURITY CORPORATION
To: ABNORMAL AI, INC.
Reel/Frame 070947/0132 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 23, 2022
From: LEE, YU ZHOU; ZIRN, MICAH J.; GULTEPE, UMUT; BRATMAN, JESHUA ALEXIS; KRALKA, MICHAEL DOUGLAS; YEH, CHENG-LIN; CHECHIK, DMITRY; JEYAKUMAR, SANJAY
To: ABNORMAL SECURITY CORPORATION
Reel/Frame 061863/0553 →
Continuity (3)
Provisional Application 63287937 · Dec 9, 2021
Provisional Application 63196603 · Jun 3, 2021
Related Publication 20220394047A1 · Dec 8, 2022