IP Library Granted Patent US 12,225,046
Granted Patent B1
US 12,225,046 · App. 18/068,428 · Granted Feb 11, 2025

Method and system for stopping multi-vector phishing attacks using cloud powered endpoint agents

Inventor: Atif Mushtaq (San Ramon, CA)
Assignee: SlashNext, Inc.
H04L63/1483H04L41/16H04L41/22H04L63/1408H04L63/1416H04L63/1425H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,046
App. No.
18/068,428
Granted
Feb 11, 2025
Kind
B1
Abstract

An endpoint protection system is provided. The system comprises: an endpoint agent deployed to an endpoint device, wherein the endpoint agent is built-into one or more existing applications running on the endpoint device and is configured to capture network session activity between the endpoint device and one or more internet servers to detect a phishing attack using a set of machine learning algorithm trained classifiers, and block the phishing attack; and an endpoint management system in remote communication with the endpoint agent, wherein the endpoint management system is configured to train and develop the set of classifiers, and receive information about the detected phishing attack and an incident report from the endpoint agent, the endpoint agent provides a graphical user interface running on the endpoint device allowing an end user to configure one or more protections provided by the endpoint agent.

Claims (28)

1. A multi-vector endpoint protection system comprising:

an endpoint agent deployed to an endpoint device, wherein the endpoint device comprises a processor, a memory, and a computer program including instructions executable by the processor to implement the endpoint agent to perform operations comprising:

(a) using a set of machine learning algorithm trained classifiers to detect one or more phishing attacks across a plurality of attack vectors, wherein the plurality of attack vectors comprise at least two items selected from the group consisting of email, text message, social media, games, advertisements, pop-ups, browser, technical scams, and SMShing,

(b) blocking the one or more phishing attacks,

(c) providing a graphical user interface (GUI) running on the endpoint device allowing an end user to configure one or more protections provided by the endpoint agent and providing a safe preview of the one or more blocked phishing attacks within the GUI; and

a cloud system in remote communication with the endpoint agent, wherein the cloud system comprises at least one processor configured to execute instructions stored on a memory of the cloud system to train and develop the set of classifiers.

2. The multi-vector endpoint protection system of claim 1 , wherein the endpoint device is a mobile device and wherein the endpoint agent is a mobile application running on the mobile device.

3. The multi-vector endpoint protection system of claim 1 , wherein the one or more phishing attacks comprise a potentially malicious webpage and wherein the potentially malicious webpage is detected by at least one of the set of machine learning algorithm trained classifiers.

4. The multi-vector endpoint protection system of claim 3 , wherein upon detecting the potentially malicious webpage, the endpoint agent is configured to send a request to the cloud system to further inspect the potentially malicious webpage by the cloud system.

5. The multi-vector endpoint protection system of claim 3 , wherein the potentially malicious webpage is inspected by launching the potentially malicious webpage in the cloud system and analyzing a content of the potentially malicious webpage based on artifacts from a virtual browser memory.

6. The multi-vector endpoint protection system of claim 5 , wherein the potentially malicious webpage is further inspected by inspecting a behavior of a server hosting the potentially malicious webpage.

7. The multi-vector endpoint protection system of claim 4 , wherein upon determining the potentially malicious webpage is malicious, the safe preview is generated based on artifacts from a virtual browser memory.

8. The multi-vector endpoint protection system of claim 2 , wherein the endpoint device is a web browser extension.

9. The multi-vector endpoint protection system of claim 1 , wherein the one or more phishing attacks comprises a phishing message and wherein the phishing message is detected using natural language processing techniques.

10. A method for providing multi-vector endpoint protection comprising:

deploying an endpoint agent to an endpoint device, wherein the endpoint device comprises a processor, a memory, and a computer program including instructions executable by the processor to implement the endpoint agent;

using a set of machine learning algorithm trained classifiers to detect one or more phishing attacks across a plurality of attack vectors, wherein the plurality of attack vectors comprise at least two items selected from the group consisting of email, text message, social media, games, advertisements, pop-ups, browser, technical scams, and SMShing;

blocking, by the endpoint agent, the one or more phishing attacks;

providing a graphical user interface (GUI) running on the endpoint device allowing an end user to configure one or more protections provided by the endpoint agent and providing a safe preview of the one or more blocked phishing attacks within the GUI; and

providing a cloud system in remote communication with the endpoint agent, wherein the cloud system comprises at least one processor configured to execute instructions stored on a memory of the cloud system to train and develop the set of classifiers.

11. The method of claim 10 , wherein the endpoint device is a mobile device and wherein the endpoint agent is a mobile application running on the mobile device.

12. The method of claim 10 , wherein the one or more phishing attacks comprises a potentially malicious webpage and wherein the potentially malicious webpage is detected by at least one of the sets of machine learning algorithm trained classifiers.

13. The method of claim 12 , further comprising upon detecting the potentially malicious webpage, sending, by the endpoint agent, a request to the cloud system to further inspect the potentially malicious webpage.

14. The method of claim 12 , further comprising launching the potentially malicious webpage in the cloud system and analyzing a content of the potentially malicious webpage is based on artifacts from a virtual browser memory.

15. The method of claim 12 , further comprising upon detecting the potentially malicious webpage, inspecting a behavior of a server hosting the potentially malicious webpage.

16. The method of claim 13 , further comprising upon determining the potentially malicious webpage is malicious, generating the safe preview based on artifacts from a virtual browser memory.

17. The method of claim 10 , wherein the endpoint agent is a web browser extension.

18. The method of claim 9 , wherein the one or more phishing attacks comprises a phishing message and wherein the phishing message is detected using natural language processing techniques.

Assignments (3)
CHANGE OF NAME Recorded Apr 16, 2026
From: SLASHNEXT, INC.
To: SLASHNEXT, LLC
Reel/Frame 075409/0484 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2026
From: SLASHNEXT, LLC
To: VARONIS SYSTEMS, INC.
Reel/Frame 075409/0567 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2023
From: MUSHTAQ, ATIF
To: SLASHNEXT, INC.
Reel/Frame 062351/0609 →
Continuity (2)
Continuation 17235546 · Apr 20, 2021
Provisional Application 63013905 · Apr 22, 2020
References Cited (23)
US 9027128B1 · Oliver · 2015 [cited by examiner]
US 9258261B1 · O'Connor · 2016 [cited by applicant]
US 10313387B1 · Kras · 2019 [cited by applicant]
US 10362047B2 · Lowry et al. · 2019 [cited by applicant]
US 10404723B1 · Mushtaq · 2019 [cited by applicant]
US 10469519B2 · Irimie et al. · 2019 [cited by applicant]
US 10764313B1 · Mushtaq · 2020 [cited by applicant]
US 11201890B1 · Coull · 2021 [cited by examiner]
US 11381597B2 · Lancioni · 2022 [cited by examiner]
US 11595437B1 · Mushtaq · 2023 [cited by applicant]
US 20170257397A1 · Graham · 2017 [cited by examiner]
US 20190104154A1 · Kumar · 2019 [cited by examiner]
US 20190149574A1 · Thomas · 2019 [cited by examiner]
US 20190173918A1 · Sites · 2019 [cited by applicant]
US 20190268302A1 · McDonald · 2019 [cited by applicant]
US 20200036751A1 · Kohavi · 2020 [cited by examiner]
US 20200252428A1 · Gardezi · 2020 [cited by examiner]
US 20210144174A1 · N · 2021 [cited by examiner]
US 20210176272A1 · Maha · 2021 [cited by examiner]
Arshey et al., “Thwarting Cyber Crime and Phishing Attacks with Machine Learning: A Study,” 2021 7th International Conference on Advanced Computing and Communication Systems (ICACCS) Year: 2021 | Conference Paper | Publ… [cited by examiner]
Thirumallai et al., “Machine Learning Inspired Phishing Detection (PD) for Efficient Classification and Secure Storage Distribution (SSD) for Cloud-IoT Application,” 2020 IEEE Symposium Series on Computational Intellige… [cited by examiner]
Notice of Allowance dated Sep. 21, 2022 for U.S. Appl. No. 17/235,546. [cited by applicant]
Notice of Allowance dated Sep. 29, 2022 for U.S. Appl. No. 17/235,546. [cited by applicant]
Cited By (2)
US 12,399,994 US 12,450,359