IP Library Granted Patent US 12,388,846
Granted Patent B2
US 12,388,846 · App. 18/191,614 · Granted Aug 12, 2025

Method and system for processing data packages

Inventors: Jack Chapman (London, GB); Thomas Hazell (London, GB)
Assignee: Egress Software Technologies IP Limited
H04L63/1416G06F16/285H04L45/74H04L51/212H04L63/0245H04L63/123H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,846
App. No.
18/191,614
Granted
Aug 12, 2025
Kind
B2
Abstract

A method, device and non-transitory computer-readable medium for analysing a data package received by a recipient, using a framework. The framework comprises at least one adjuster; and a processing component for processing the received data package using the at least one adjuster. The at least one adjuster is configured to obtain payload data of the received data package and analyse the payload data for recipient-interactive content, wherein the recipient-interactive content provides access to remote content. The recipient-interactive content is substituted with sanitised recipient-interactive content, and recipient interaction with the sanitised recipient-interactive content is detected. A content check is performed when recipient interaction with the sanitised recipient-interactive content is detected. The content check comprises analysing the remote content, and determining, based on the content check whether the data package represents a security threat.

Claims (47)

1. A method for analyzing a data package received by a recipient, using a framework, the framework comprising:

at least one adjuster; and

a processing component configured to execute instructions for processing the received data package using the at least one adjuster;

wherein the at least one adjuster is configured to perform the steps of:

obtaining payload data of the received data package;

analyzing the payload data for recipient interactive content, wherein the recipient interactive content provides access to remote content;

substituting the recipient interactive content with sanitized recipient interactive content;

detecting recipient interaction with the sanitized recipient interactive content;

performing a content check when recipient interaction with the sanitized recipient interactive content is detected, wherein the content check comprises analyzing the remote content and determining a difference between the remote content at a time of the analysis of the payload data and the remote content at a time when the recipient interaction with the sanitized recipient interactive content is detected; and

determining, based on the content check whether the data package represents a security threat.

2. The method of claim 1 , wherein the step of analyzing the payload data is undertaken at a first time, where the first time is when the data package is received by the recipient.

3. The method of claim 2 , wherein the step of performing the content check is undertaken at a second time, the second time being after the first time.

4. The method of claim 1 , wherein, based on the determination of whether the data package represents a security threat, processing the data package comprises at least one of:

notifying a recipient of the data package of a potential security threat; and

forwarding the recipient to the remote content linked to by the recipient interactive content.

5. The method of claim 1 , wherein determining whether the data package represents a security threat comprises determining if the difference exceeds a predetermined threshold.

6. The method of claim 1 , wherein the content check comprises applying at least one of:

a geographical check;

a hygiene check;

a blacklist check; and

a linguistic and contextual check.

7. A device for analyzing a received data package received, the device comprising:

a user interface; and

a processor configured to execute instructions to process the data package using at least one adjuster, wherein the at least one adjuster is configured to:

obtain payload data of the received data package;

analyze the payload data for recipient interactive content, wherein the recipient interactive content provides access to remote content;

substitute the recipient interactive content with sanitized recipient interactive content;

detect recipient interaction via the user interface with the sanitized recipient interactive content;

perform a content check via the sanitized recipient interactive content when recipient interaction with the sanitized recipient-interactive content is detected, wherein the content check comprises analyzing the remote content linked to by the recipient interactive content and determining a difference between the remote content at a time of the analysis of the payload data and the remote content at a time when the recipient interaction with the sanitized recipient interactive content is detected; and

determine, based on the content check whether the data package represents a security threat.

8. The device of claim 7 , wherein the analysis of the payload data is undertaken at a first time, where the first time is when the data package is received by the recipient.

9. The device of claim 8 , wherein the content check is performed at a second time, the second time being after the first time.

10. The device of claim 7 , further comprising an output module, wherein, based on the determination of whether the data package represents a security threat, the output module is arranged to:

notify the recipient of the data package of a potential security threat; and

forward the recipient to the remote content linked to by the recipient-interactive content.

11. The device of claim 7 wherein determining whether the data package represents a security threat comprises determining if the difference exceeds a predetermined threshold.

12. The device of claim 7 , further comprising storage for storing data for use by the content check.

13. A non-transitory computer-readable storage medium comprising a set of computer-readable instructions stored thereon, which when executed by at least one processor are arranged to analyze a data package received by a recipient via a framework, the framework comprising:

at least one adjuster; and

a processing component for processing the received data package using the at least one adjuster;

wherein the at least one adjuster is configured to perform the steps of:

obtaining payload data of the received data package;

analyzing the payload data for recipient interactive content, wherein the recipient interactive content provides access to remote content;

substituting the recipient interactive content with sanitized recipient interactive content;

detecting recipient interaction with the sanitized recipient interactive content;

performing a content check when recipient interaction with the sanitized recipient interactive content is detected, wherein the content check comprises analyzing the remote content and determining a difference between the remote content at a time of the analysis of the payload data and the remote content at a time when the recipient interaction with the sanitized recipient interactive content is detected; and

determining, based on the content check whether the data package represents a security threat.

Assignments (3)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 068728/0719 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP.
To: EGRESS SOFTWARE TECHNOLOGIES IP LIMITED
Reel/Frame 072108/0083 →
SECURITY INTEREST Recorded Sep 27, 2024
From: EGRESS SOFTWARE TECHNOLOGIES IP LIMITED
To: BLUE OWL CREDIT INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 068728/0719 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2023
From: CHAPMAN, JACK; HAZELL, THOMAS
To: EGRESS SOFTWARE TECHNOLOGIES IP LIMITED
Reel/Frame 063922/0956 →
Priority Claims (4)
GB 2204562 · Mar 30, 2022 · national
GB 2204563 · Mar 30, 2022 · national
GB 2204564 · Mar 30, 2022 · national
GB 2204565 · Mar 30, 2022 · national
Continuity (1)
Related Publication 20230353580A1 · Nov 2, 2023
References Cited (9)
US 9621576B1 · Oprea · 2017 [cited by examiner]
US 10887261B2 · Egilmez · 2021 [cited by examiner]
US 11145221B2 · Shi · 2021 [cited by examiner]
US 20110030058A1 · Ben-Itzhak · 2011 [cited by examiner]
US 20180084002A1 · Shnitzer · 2018 [cited by examiner]
US 20180218155A1 · Grafi · 2018 [cited by examiner]
US 20210120035A1 · Onut et al. · 2021 [cited by applicant]
US 20210144174A1 · N · 2021 [cited by examiner]
US 20210211462A1 · Birch · 2021 [cited by examiner]