IP Library Granted Patent US 12,634,340
Granted Patent B2
US 12,634,340 · App. 17/859,847 · Granted May 19, 2026

Method and system for determining and acting on an email cyber threat campaign

Inventors: Steven Haworth (Cambridge, GB); Stephen Pickman (Huntingdon, GB); Antony Steven Lawson (Tyne & Wear, GB); Paul Lancaster (Cambridge, GB)
Assignee: Darktrace Holdings Limited
H04L63/1466H04L63/1425H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,340
App. No.
17/859,847
Granted
May 19, 2026
Kind
B2
Abstract

A cyber security appliance (CSA) configurable to protect a computer system from email cyber threat campaigns is disclosed. The CSA may comprise: an email module configured to process all incoming emails and log data and metadata; a cyber threat module coupled configured to assess a severity level of a cyber threat using one or more Artificial Intelligence (AI) models; an AI classifier configured to determine the likelihood of an email cyber threat campaign; an autonomous response module configured to act against emails determined to be threats; and a user interface module configured to generate a report, present data on a display, and show a graphical display of the system indicating the details of a cyber threat campaign.

Claims (37)

1 . A cyber security appliance comprising:

a processor; and

a non-transitory storage medium accessible by the processor, the non-transitory storage medium stores software executable by the processor and comprises

an email module executable by the processor, the email module is configured to (i) process incoming emails and (ii) log data and metadata associated with the incoming emails,

a cyber threat module coupled to the email module and, when executed by the processor, analyzes the logged data and metadata to assess a severity level of a cyber threat using one or more Artificial Intelligence (AI) models specifically trained on dynamically updated datasets derived from one or more groups of parameters including: (i) email metrics, (ii) suspicious characteristics of emails, (iii) malicious links and attachments, (iv) a database of known malicious actors, or (v) any combination of these parameters, in order to cluster emails with similar parameters,

an AI classifier module coupled to the email module and the cyber threat module, the AI classifier module, when executed by the processor, parse an email of the incoming emails to extract characteristics associated with the email to classify the email in accordance with one of a plurality of categories using a multiple-pronged approach that comprises (a) considering the extracted characteristics relating to content of the email using word analysis, (b) considering the extracted characteristics relating to a tone of the email using structure analysis, and (c) considering a type of induced behavior that is determined to be requested of the recipient, wherein the AI classifier module is further configured to determine a likelihood of one or more of the plurality of categories including an email cyber threat campaign is occurring using the one or more AI models and analysis of the parameters including the extracted characteristics of the email,

an autonomous response module coupled to the email module, the cyber threat module, and the AI classifier module, the autonomous response module, when executed by the processor, acts against the email determined to be a threat when instructed by at least one of the cyber threat module and the AI classifier module, where the autonomous response module is configured to take an autonomous action against the email, where the email acted against had previously been examined and not stopped or acted upon but now is deemed part of an email campaign, and

a user interface module, when executed by the processor, performs at least one of the actions in the group consisting of: (i) presenting data on a display, and (ii) showing a graphical display of the system indicating the details of a cyber threat campaign,

wherein collective operations of the email module, the cyber threat module, the AI classifier module, the autonomous response module, and the user interface module provide an improved granularity in a classification of a structured document and thereby an improved ability to provide improved autonomous actions in response to the classification.

2 . The cyber security appliance of claim 1 , wherein the email module is further configured to detect incoming email cyber threats using one or more Artificial Intelligence (AI) models trained on the normal pattern of life in a computer system being protected by the cyber security appliance.

3 . The cyber security appliance of claim 1 , wherein the suspicious characteristics of emails consists of at least one of the group consisting of: (i) the email wording, (ii) the geographic location of a host or a domain, (iii) the relationship between sender and recipient, and (iv) the presence of a malign inducement.

4 . The cyber security appliance of claim 1 , wherein the AI classifier module is further configured to perform one or more of the group consisting of: (i) scoring emails according to a plurality of indices, (ii) grouping similar emails into clusters, (iii) examining the chronological sequence of detected cyber threats for fluctuations, (iv) analyzing each mailbox to determine its purpose, and (v) estimating the probability of unsolicited emails to each mailbox, and where the autonomous action is taken retrospectively on that email in order to have a positive impact of potentially stopping any harm from the email campaign.

5 . The cyber security appliance of claim 4 , wherein the AI classifier module is further configured to find outliers based on the detected cyber threats fluctuations and to return the outliers to the one or more AI models for training, and where the user interface module is further configured to display on a display screen trends for one or more ongoing email campaign detections, and the emails involved in the email campaign and the email accounts that have been targeted.

6 . The cyber security appliance of claim 4 , wherein the AI classifier module is further configured to perform at least one of the group consisting of (i) determining if a mailbox is public-facing or private-facing, (ii) logging the number of detected threats, and (iii) continuously scoring each mailbox based on the occurrence of threats to that mailbox.

7 . The cyber security appliance of claim 1 , wherein the autonomous response module is configured to take the autonomous action against detected cyber threat emails and email cyber campaigns by one or more of the actions in the group consisting of: (i) converting an attachment into a harmless format, (ii) stripping an attachment from an email, (iii) unspoofing an email header, (iv) deleting a link, (v) locking a link, (vi) double locking a link, (vii) holding a message from an email inbox, and (viii) moving an email to a junk email box.

8 . The cyber security appliance of claim 1 , wherein the autonomous response module is configured to take the autonomous action against detected cyber threat emails and email cyber campaigns is one or more of the group consisting of: (i) converting an attachment into a harmless format, (ii) stripping an attachment from an email, (iii) unspoofing an email header, (iv) deleting a link, (v) locking a link, (vi) double locking a link, (vii) holding a message from an email inbox, and (viii) moving an email to a junk email box.

9 . The cyber security appliance of claim 1 , wherein the user interface module is further configured to perform at least one of the group consisting of: (i) providing a single plane of analysis, (ii) displaying the risk profile of entities, (iii) tracking high permission users, (iv) tracking SaaS documents, (v) tracking macro-enabled documents, (vi) tracking documents within an organization, and (vii) model a connectivity web.

10 . The cyber security appliance of claim 1 , wherein the cyber security appliance is further configured to coordinate actions and share information with a second cyber security appliance coupled to a computer system being protected by the cyber security appliance in order to communicate when an email campaign is detected.

11 . A method of operating a cyber security appliance, comprising:

processing incoming emails;

logging data and metadata associated with the incoming emails;

determining a level of email cyber threat using one or more AI modules specifically trained on dynamically updated datasets derived from one or more groups of parameters including:

(i) email metrics, (ii) suspicious characteristics of emails, (iii) malicious links and attachments, (iv) a database of known malicious actors to assess a severity level of a cyber threat, or (v) any combination of these parameters, in order to cluster emails with similar parameters;

parsing an email of the incoming emails to extract characteristics associated with the email to classify the email in accordance with one of a plurality of categories using a multiple-pronged approach that comprises (a) considering the extracted characteristics relating to content of the email using word analysis, (b) considering the extracted characteristics relating to a tone of the email using structure analysis, and (c) considering a type of induced behavior that is determined to be requested of the recipient;

assessing a likelihood of one or more of the plurality of categories including an email cyber threat campaign is occurring using one or more AI models and analysis of the parameters including the extracted characteristics of the email;

taking autonomous action against an email determined to be a threat when instructed by at least one of the cyber threat module and the AI classifier module, where the autonomous response module is configured to take an autonomous action against the email, where the email acted against had previously been examined and not stopped or acted upon but now is deemed part of an email campaign; and

performing at least one of the reporting actions in the group consisting of (i) generating a report, (ii) presenting data on a screen, and (iii) showing a graphical display of the system indicating the details of a cyber threat campaign

wherein the logging of the data and the metadata, parsing of the email, and assessing the likelihood of the email cyber threat campaign is occurring provide an improved granularity in a classification of the email and thereby an improved ability to provide improved autonomous actions in response to the classification.

12 . The method of claim 11 , wherein the processing of all incoming emails uses one or more Artificial Intelligence (AI) models trained on the normal pattern of life in a computer system being protected by the cyber security appliance to detect incoming email cyber threats.

13 . The method of claim 11 , wherein the suspicious characteristics of emails consists of at least one of the group consisting of: (i) the email wording, (ii) the geographic location of a host or a domain, (iii) the relationship between sender and recipient, and (iv) the presence of a malign inducement.

14 . The method of claim 11 , wherein the assessing the likelihood of an email cyber threat campaign further comprises one or more of the group consisting of: (i) scoring emails according to a plurality of indices, (ii) grouping similar emails into clusters, (iii) examining the chronological sequence of detected cyber threats for fluctuations, (iv) analyzing each mailbox to determine its purpose, and (v) estimating the probability of unsolicited emails to each mailbox, and where the autonomous action is taken retrospectively on that email in order to have a positive impact of potentially stopping any harm from the email campaign.

15 . The method of claim 14 , wherein the cyber security appliance is further configured to find outliers based on the detected cyber threats fluctuations and to return the outliers to one or more AI models for training, and where the user interface module is further configured to display on a display screen trends for one or more ongoing email campaign detections, and the emails involved in the email campaign and the email accounts that have been targeted.

16 . The method of claim 14 , wherein the cyber security appliance is further configured to perform at least one of the group consisting of (i) determining if a mailbox is public-facing or private-facing, (ii) logging the number of detected threats, and (iii) continuously scoring each mailbox based on the occurrence of threats to that mailbox.

17 . The method of claim 11 , wherein assessing the likelihood that an email cyber threat campaign is occurring further comprises (i) comparing a detected email cyber campaign to previously detected cyber email campaigns and (ii) analyzing a detected email cyber campaign to understand its origin and purpose.

18 . The method of claim 11 , wherein taking the autonomous action against detected email cyber threats and email cyber campaigns further comprises one or more of the group of actions consisting of: (i) converting an attachment into a harmless format, (ii) stripping an attachment from an email, (iii) unspoofing an email header, (iv) deleting a link, (v) locking a link, (vi) double locking a link, (vii) holding a message from an email inbox, and (viii) moving an email to a junk email box.

19 . The method of claim 11 , wherein performing at least one of the reporting actions further comprises (i) providing a single plane of analysis, (ii) displaying the risk profile of entities, (iii) tracking high permission users, (iv) tracking SaaS documents, (v) tracking macro-enabled documents, (vi) tracking documents within an organization, and (vii) model a connectivity web.

20 . A non-transitory computer-readable medium comprising computer-readable code operable, when executed by one or more processing apparatuses in a cyber security appliance, to perform the method of claim 11 .

Assignments (3)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: HAWORTH, STEVEN; LAWSON, ANTONY STEVEN; LANCASTER, PAUL; PICKMAN, STEPHEN
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 060677/0055 →
Continuity (10)
Continuation In Part 17187381 · Feb 26, 2021
Continuation In Part 16732644 · Jan 2, 2020
Continuation In Part 16278932 · Feb 19, 2019
Provisional Application 63317157 · Mar 7, 2022
Provisional Application 63219026 · Jul 7, 2021
Provisional Application 63026446 · May 18, 2020
Provisional Application 62983307 · Feb 28, 2020
Provisional Application 62796507 · Jan 24, 2019
Provisional Application 62632623 · Feb 20, 2018
Related Publication 20230007042A1 · Jan 5, 2023
References Cited (29)
US 7693945B1 · Dulitz et al. · 2010 [cited by applicant]
US 10268821B2 · Stockdale · 2019 [cited by applicant]
US 10419466B2 · Ferguson · 2019 [cited by applicant]
US 10701093B2 · Dean · 2020 [cited by applicant]
US 11075930B1 · Xavier · 2021 [cited by examiner]
US 20050203929A1 · Hazarika et al. · 2005 [cited by applicant]
US 20070107059A1 · Chasin et al. · 2007 [cited by applicant]
US 20070294428A1 · Guy et al. · 2007 [cited by applicant]
US 20090327438A1 · Cheng et al. · 2009 [cited by applicant]
US 20100287246A1 · Klos et al. · 2010 [cited by applicant]
US 20170048261A1 · Gmach et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170230391A1 · Ferguson et al. · 2017 [cited by applicant]
US 20170244736A1 · Benishti et al. · 2017 [cited by applicant]
US 20180121566A1 · Filippi et al. · 2018 [cited by applicant]
US 20180295146A1 · Kovega et al. · 2018 [cited by applicant]
US 20190028510A1 · Celik · 2019 [cited by applicant]
US 20190171822A1 · Sjouwerman · 2019 [cited by examiner]
US 20190238571A1 · Adir et al. · 2019 [cited by applicant]
US 20200059447A1 · Bahar et al. · 2020 [cited by applicant]
US 20200067861A1 · Leddy et al. · 2020 [cited by applicant]
US 20200244673A1 · Stockdale · 2020 [cited by applicant]
US 20200344183A1 · Mummidi · 2020 [cited by applicant]
US 20210273958A1 · McLean · 2021 [cited by applicant]
Title: Mail Center Security Guidelines—Published—Sep. 2002 “https://adacounty.id.gov/emergencymanagement/wp-content/uploads/sites/39/mailroom.pdf” (Year: 2002). [cited by examiner]
United States Patent and Trademark Office, Non-Final Office Action, Feb. 15, 2022, 42 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Dec. 8, 2021, 37 pages. [cited by applicant]
United States Patent and Trademark Office, Final Office Action, Jun. 23, 2022, 26 pages. [cited by applicant]
United States Patent and Trademark Office, Non-Final Office Action, Apr. 12, 2023, 49 pages. [cited by applicant]