IP Library › Granted Patent US 12,244,562
Granted Patent B2
US 12,244,562 · App. 17/867,464 · Granted Mar 4, 2025

Algorithm to detect malicious emails impersonating brands

Inventors: Durgamadhav Behera (Karnatakka, IN); Abhishek Singh (Morgan Hill, CA); Muhammad Sachedina (Calgary, CA)
Assignee: Cisco Technology, Inc.
H04L63/0236H04L63/1408H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,562
App. No.
17/867,464
Granted
Mar 4, 2025
Kind
B2
Abstract

Techniques for an email-security system to screen emails, extract information from the emails, analyze the information, assign probability scores to the emails, and classify the emails as likely fraudulent or not. The system may analyze emails for users and identify fraudulent emails by analyzing the contents of the emails. The system may evaluate the contents of the emails to determine probability score(s) which may further determine an overall probability score. The system may then classify the email as fraudulent, or not, and may perform actions including blocking the email, allowing the email, flagging the email, etc. In some instances, the screened emails may include legitimate brand domain addresses, names, images, URL(s), and the like. However, the screened emails may contain a reply-to domain address that matches a free email service provider domain. In such instances, the email-security system may assign a probability score indicative that the screened email is fraudulent.

Claims (116)

1. A method for an email-security system to detect malicious emails, the method comprising:

obtaining, at an email-security system, an email sent from a sending device to a receiving device;

extracting, from the email, first data representing a from field of the email, second data representing a Uniform Resource Locator (URL) in the email, and third data representing a reply-to address;

identifying, using the first data, that a display name in the from field represents a brand name and that a from address domain in the from field does not represent the brand name;

determining, based at least in part on the display name representing the brand name and the from address domain not representing the brand name, a first probability value indicating a first likelihood that the from field of the email is impersonating the brand name;

determining, using the second data, whether a URL domain in the URL matches to the from address domain in the from field;

determining, based on whether the URL domain matches to the from address domain, a second probability value indicating a second likelihood that the URL in the email is impersonating the brand name;

determining, using the third data, whether a reply-to domain of the reply-to address corresponds to a free email service domain;

determining, based at least in part on whether the reply-to domain corresponds to the free email service domain, a third probability value indicating a third likelihood that the reply-to address in the email is impersonating the brand name; and

determining, using the first probability value, the second probability value, and the third probability value, an overall probability value indicating an overall likelihood that the email is a malicious email that is impersonating the brand name.

2. The method of claim 1 , further comprising:

comparing the from address domain name and a plurality of free email service domains; and

determining the first probability value based at least in part on comparing the from address domain in the from field of the email and the plurality of free email service domains.

3. The method of claim 1 , further comprising:

comparing the brand name with the URL domain;

determining, based at least in part on the comparing, whether the brand name corresponds to the URL domain; and

determining the second probability value based at least in part on the determining whether the brand name corresponds to the URL domain.

4. The method of claim 1 , further comprising:

comparing the from address domain with a plurality of free email service domains;

comparing the from address domain and the reply-to domain;

determining, based on the comparing whether the from address domain corresponds to the plurality of free email service domains and whether the from address domain corresponds to the reply-to domain; and

determining the third probability value, based at least in part on the determining whether the from address domain corresponds to the plurality of free email service domains and whether the from address domain corresponds to the reply-to domain.

5. The method of claim 1 , further comprising:

identifying, using the first data, the second data, and the third data, an associated certificate;

determining, using the associated certificate, an owner;

identifying, using the owner, a corresponding name of the brand associated with the owner;

determining, using the first data, a displayed brand name and a display name of the email;

comparing the from address domain and the display name of the email to the name of the brand associated with the owner;

determining, based at least on the comparing whether the from address domain and the display name of the email correspond to the name of the brand associated with the owner; and

determining a fourth probability value, based at least in part on the determining whether the from address domain and the display name of the email correspond to the name of the brand associated with the owner.

6. The method of claim 1 , further comprising:

identifying, from the email, a selectable option for the receiving device to unsubscribe from additional emails;

extracting, from the email, an unsubscribe URL associated with the selectable option; and

comparing the unsubscribe URL and the from address domain,

wherein the determining the second probability value indicating the second likelihood that the email is impersonating the brand name is based at least in part on the comparing the URL and the from address domain.

7. The method of claim 1 , further comprising:

identifying an image included in the email;

identifying, from image data associated with the image, an image URL; and

comparing the image URL and the from address domain;

wherein the determining, based at least in part on comparing the image URL and the from address domain, the second probability value indicating the second likelihood that the email is impersonating the brand name is based at least in part on the comparing the image URL and the from address domain.

8. The method of claim 1 , further comprising:

identifying, using the first data, the second data, and the third data, an associated Whois database entry;

determining, from the associated Whois database entry, a registrant;

identifying a name of the brand associated with the registrant;

comparing the display name of the email to the name of the brand associated with the registrant; and

determining a seventh probability value, based at least in part on the comparing whether the display name of the email corresponds to the name of the brand associated with the registrant.

9. A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processor to perform operations comprising:

obtaining, at an email-security system, an email sent from a sending device to a receiving device;

extracting, from the email, first data representing a from field of the email, second data representing a Uniform Resource Locator (URL) in the email, and third data representing a reply-to address;

identifying, using the first data, that a display name in the from field represents a brand name and that a from address domain in the from field does not represent the brand name;

determining, based at least in part on the display name representing the brand name and the from address domain not representing the brand name, a first probability value indicating a first likelihood that the from field of the email is impersonating the brand name;

determining, using the second data, whether a URL domain in the URL matches to the from address domain in the from field;

determining, based on whether the URL domain matches to the from address domain, a second probability value indicating a second likelihood that the URL in the email is impersonating the brand name;

determining, using the third data, whether a reply-to domain of the reply-to address corresponds to a free email service domain;

determining, based at least in part on whether the reply-to domain corresponds to the free email service domain, a third probability value indicating a third likelihood that the reply-to address in the email is impersonating the brand name; and

determining, using the first probability value, the second probability value, and the third probability value, an overall probability value indicating an overall likelihood that the email is a malicious email that is impersonating the brand name.

10. The system of claim 9 , further comprising:

comparing the from address domain and a plurality of free email service domains; and

determining the first probability value based at least in part on comparing the from address domain in the from field of the email and the plurality of free email service domains.

11. The system of claim 9 , further comprising:

comparing the brand name with the URL domain;

determining, based at least in part on the comparing, whether the brand name corresponds to the URL domain; and

determining the second probability value based at least in part on the determining whether the brand name corresponds to the URL domain.

12. The system of claim 9 , further comprising:

comparing the from address domain with a plurality of free email service domains;

comparing the from address domain and the reply-to domain;

determining, based on the comparing, whether the from address domain corresponds to the plurality of free email service domains and whether the from address domain corresponds to the reply-to domain; and

determining the third probability value, based at least in part on the determining whether the from address domain corresponds to the plurality of free email service domains and whether the from address domain corresponds to the reply-to domain.

13. The system of claim 9 , further comprising:

identifying, using the first data, the second data, and the third data, an associated certificate;

determining, using the associated certificate, an owner;

identifying, using the owner, a corresponding name of the brand associated with the owner;

determining, using the first data, a displayed brand name and a display name of the email;

comparing the from address domain and the display name of the email to the name of the brand associated with the owner;

determining, based at least on the comparing whether the from address domain and the display name of the email correspond to the name of the brand associated with the owner; and

determining a fourth probability value, based at least in part on the determining whether the from address domain and the display name of the email correspond to the name of the brand associated with the owner.

14. The system of claim 9 , further comprising:

identifying, from the email, a selectable option for the receiving device to unsubscribe from additional emails;

extracting, from the email, an unsubscribe URL associated with the selectable option; and

comparing the unsubscribe URL and the from address domain,

wherein the determining the second probability value indicating the second likelihood that the email is impersonating the brand name is based at least in part on the comparing the URL and the from address domain.

15. The system of claim 9 , further comprising:

identifying an image included in the email;

identifying, from image data associated with the image, an image URL; and

comparing the image URL and the from address domain;

wherein the determining, based at least in part on comparing the image URL and the from address domain, the second probability value indicating the second likelihood that the email is impersonating the brand name is based at least in part on the comparing the image URL and the from address domain.

16. The system of claim 9 , further comprising:

identifying, using the first data, the second data, and the third data, an associated Whois database entry;

determining, from the associated Whois database entry, a registrant;

identifying a name of the brand associated with the registrant;

comparing the display name of the email to the name of the brand associated with the registrant; and

determining a seventh probability value, based at least in part on the comparing whether the display name of the email corresponds to the name of the brand associated with the registrant.

17. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

obtaining, at an email-security system, an email sent from a sending device to a receiving device;

extracting, from the email, first data representing a from field of the email, second data representing a Uniform Resource Locator (URL) in the email, and third data representing a reply-to address;

identifying, using the first data, that a display name in the from field represents a brand name and that a from address domain in the from field does not represent the brand name;

determining, based at least in part on the display name representing the brand name and the from address domain not representing the brand name, a first probability value indicating a first likelihood that the from field of the email is impersonating the brand name;

determining, using the second data, whether a URL domain in the URL matches to the from address domain in the from field;

determining, based on whether the URL domain matches to the from address domain, a second probability value indicating a second likelihood that the URL in the email is impersonating the brand name;

determining, using the third data, whether a reply-to domain of the reply-to address corresponds to a free email service domain;

determining, based at least in part on whether the reply-to domain corresponds to the free email service domain, a third probability value indicating a third likelihood that the reply-to address in the email is impersonating the brand name; and

determining, using the first probability value, the second probability value, and the third probability value, an overall probability value indicating an overall likelihood that the email is a malicious email that is impersonating the brand name.

18. The one or more non-transitory computer-readable media of claim 17 , further including:

comparing the from address domain and a plurality of free email service domains; and

determining the first probability value based at least in part on comparing the from address domain in the from field of the email and the plurality of free email service domains.

19. The one or more non-transitory computer-readable media of claim 18 , further including:

comparing the brand name with the URL domain;

determining, based at least in part on the comparing, whether the brand name corresponds to the URL domain; and

determining the second probability value based at least in part on the determining whether the brand name corresponds to the URL domain.

20. The one or more non-transitory computer-readable media of claim 17 , further including:

comparing the from address domain with a plurality of free email service domains;

comparing the from address domain and the reply-to domain;

determining, based on the comparing, whether the from address domain corresponds to the plurality of free email service domains and whether the from address domain corresponds to the reply-to domain; and

determining the third probability value, based at least in part on the determining whether the from address domain corresponds to the plurality of free email service domains and whether the from address domain corresponds to the reply-to domain.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2022
From: BEHERA, DURGAMADHAV; SINGH, ABHISHEK; SACHEDINA, MUHAMMAD
To: CISCO TECHNOLOGY, INC.
Reel/Frame 060538/0987 →
Continuity (1)
Related Publication 20230328034A1 · Oct 12, 2023
References Cited (12)
US 10601865B1 · Mesdaq et al. · 2020 [cited by applicant]
US 10764313B1 · Mushtaq · 2020 [cited by applicant]
US 20160119377A1 · Goldberg · 2016 [cited by examiner]
US 20160352772A1 · O'Connor · 2016 [cited by applicant]
US 20170230406A1 · Gould · 2017 [cited by examiner]
US 20180012184A1 · Shraim · 2018 [cited by examiner]
US 20190319905A1 · Baggett · 2019 [cited by examiner]
US 20200279225A1 · Li · 2020 [cited by applicant]
US 20210027306A1 · Somaraju et al. · 2021 [cited by applicant]
US 20210248624A1 · Keren et al. · 2021 [cited by applicant]
EP 1863240A2 · 2007 [cited by applicant]
PCT Search Report and Written Opinion mailed Jun. 21, 2023 for PCT application No. PCT/US23/17530, 12 pgs. [cited by applicant]