IP Library Granted Patent US 11,704,406
Granted Patent B2
US 11,704,406 · App. 17/942,931 · Granted Jul 18, 2023

Deriving and surfacing insights regarding security threats

Inventors: Yu Zhou Lee (San Francisco, CA); Kai Jiang (San Francisco, CA); Su Li Debbie Tan (San Francisco, CA); Geng Sng (San Francisco, CA); Cheng-Lin Yeh (San Francisco, CA); Lawrence Stockton Moore (San Francisco, CA); Sanny Xiao Lang Liao (San Francisco, CA); Joey Esteban Cerquera (San Francisco, CA); Jeshua Alexis Bratman (New York, NY); Sanjay Jeyakumar (Berkeley, CA); Nishant Bhalchandra Karandikar (San Francisco, CA)
Assignee: Abnormal Security Corporation
G06F21/552G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,704,406
App. No.
17/942,931
Granted
Jul 18, 2023
Kind
B2
Abstract

Deriving and surfacing insights regarding security threats is disclosed. A plurality of features associated with a message is determined. A plurality of facet models is used to analyze the determined features. Based at least in part on the analysis, it is determined that the message poses a security threat. A prioritized set of information is determined to be provided as output that is representative of why the message was determined to pose a security threat. At least a portion of the prioritized set of information is provided as output.

Claims (41)

1. A system, comprising:

a processor configured to:

establish, via an application programming interface, a connection with a storage medium that includes a series of communications received by an employee of an enterprise and obtain an email that is addressed to the employee;

determine a plurality of features associated with the obtained email;

use a plurality of facet models to analyze the determined plurality of features;

determine, based at least in part on the analysis, that the obtained email poses a security threat;

determine a prioritized set of information to provide as output in a report, wherein the prioritized set of information is representative of why the email was determined to pose a security threat; and

provide at least a portion of the prioritized set of information as output in an interface; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an attack type model that identifies a type of attack of which the email is a part, wherein the attack type is derived based on a combination of other facets.

3. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an attack strategy model that identifies a strategy used in the email to perpetrate an attack.

4. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an impersonated party model that identifies an entity that a sender of the email is attempting to impersonate.

5. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an attacked party model that indicates an entity that is a target of an attack carried out by the email.

6. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an attack goal model that identifies a goal of an attack carried out by the email.

7. The system of claim 1 , wherein at least one facet model included in the plurality of facet models is an attack vector model that identifies a mechanism by which an attack is carried out by the email.

8. The system of claim 1 , wherein the prioritized set of information is determined based at least in part on an identity or group membership of a message recipient.

9. The system of claim 1 , wherein the prioritized set of information is determined based at least in part by using a logistic regression model that is trained to detect attacks.

10. The system of claim 1 , wherein the report includes information indicating whether the email has associated email campaign activity.

11. A method, comprising:

establishing, via an application programming interface, a connection with a storage medium that includes a series of communications received by an employee of an enterprise and obtaining an email that is addressed to the employee;

determining a plurality of features associated with the obtained email;

using a plurality of facet models to analyze the determined plurality of features;

determining, based at least in part on the analysis, that the obtained email poses a security threat;

determining a prioritized set of information to provide as output in a report, wherein the prioritized set of information is representative of why the email was determined to pose a security threat; and

providing at least a portion of the prioritized set of information as output in an interface.

12. The method of claim 11 , wherein at least one facet model included in the plurality of facet models is an attack type model that identifies a type of attack of which the email is a part, wherein the attack type is derived based on a combination of other facets.

13. The method of claim 11 , wherein at least one facet model included in the plurality of facet models is an attack strategy model that identifies a strategy used in the email to perpetrate an attack.

14. The method of claim 11 , wherein at least one facet model included in the plurality of facet models is an impersonated party model that identifies an entity that a sender of the email is attempting to impersonate.

15. The method of claim 11 , wherein at least one facet model included in the plurality of facet models is an attacked party model that indicates an entity that is a target of an attack carried out by the email.

16. The method of claim 11 , wherein at least one facet model included in the plurality of facet models is an attack goal model that identifies a goal of an attack carried out by the email.

17. The method of claim 11 , wherein at least one facet model included in the plurality of facet models is an attack vector model that identifies a mechanism by which an attack is carried out by the email.

18. The method of claim 11 , wherein the prioritized set of information is determined based at least in part on an identity or group membership of a message recipient.

19. The method of claim 11 , wherein the prioritized set of information is determined based at least in part by using a logistic regression model that is trained to detect attacks.

20. The method of claim 11 , wherein the report includes information indicating whether the email has associated email campaign activity.

21. A computer program product embodied in a non-transitory tangible computer readable storage medium and comprising computer instructions for:

establishing, via an application programming interface, a connection with a storage medium that includes a series of communications received by an employee of an enterprise and obtaining an email that is addressed to the employee;

determining a plurality of features associated with the obtained email;

using a plurality of facet models to analyze the determined plurality of features;

determining, based at least in part on the analysis, that the obtained email poses a security threat;

determining a prioritized set of information to provide as output in a report, wherein the prioritized set of information is representative of why the email was determined to pose a security threat; and

providing at least a portion of the prioritized set of information as output in an interface.

Continuity (3)
Continuation 17547141 · Dec 9, 2021
Provisional Application 63123865 · Dec 10, 2020
Related Publication 20230020623A1 · Jan 19, 2023
Cited By (2)
US 12,197,912 US 12,277,126