IP Library Granted Patent US 12,355,715
Granted Patent B2
US 12,355,715 · App. 18/230,047 · Granted Jul 8, 2025

Method for electronic impersonation detection and remediation

Inventors: Dhananjay Sampath (Sunnyvale, CA); Arjun Sambamoorthy (Sunnyvale, CA); Prashanth Arun (Sunnyvale, CA); Robert Lyons (Sunnyvale, CA)
Assignee: ArmorBlox LLC
H04L51/212G06F40/169G06F40/284H04L51/214
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,715
App. No.
18/230,047
Granted
Jul 8, 2025
Kind
B2
Abstract

A method includes: accessing a corpus of emails sent from a email account prior to the initial time period; correlating sequences of words, in the corpus of emails, with language signals; aggregating the language signals into a sender model that represents combinations of language signals characteristic of language in emails sent from the email account; later, accessing a email outbound from the email account and directed to a recipient; scanning the email for the set of language signals; correlating sequences of words in the email with language signals; calculating a similarity score for the email based on the subset of language signals detected in the email and the sender model; and, in response to the similarity score falling below a threshold similarity, flagging the email as suspicious and redirecting the email away from the recipient.

Claims (95)

1. A method comprising:

obtaining, at an email computer system, a sender model that represents first language included in previously sent emails associated with an email account;

accessing an outbound email sent from the email account and destined for a recipient;

analyzing second language of the outbound email with respect to a set of language concepts;

determining, based on the analyzing, that the second language includes a first word that is of a financial concept;

determining, based on the analyzing, that the second language includes a second word that is of an action concept associated with an action to take with respect to the first word;

based at least in part on the second language including the first word of the financial concept and the second word of the action concept, calculating a similarity score between the outbound email and at least one of the previously sent emails represented in the sender model;

identifying a characteristic of a user of the email account; and

obtaining a group sender model that represents third language included in second previously sent emails associated with a group of users exhibiting the characteristic;

determining that the outbound email is a malicious email based at least in part on the similarity score and at least partly using the group sender model; and

performing a remedial action with respect to the outbound email the remedial action comprising at least one of:

deleting the outbound email;

quarantining the outbound email; or

updating the sender model at least partly using the outbound email.

2. The method of claim 1 , further comprising:

determining, based on the analyzing, that the second language includes a third word that is of an urgency concept associated with the action to take with respect to the first word,

wherein determining that the outbound email is a malicious email is further based at least in part on the third word that is of the urgency concept.

3. The method of claim 1 , further comprising:

determining, based on the analyzing, that the second language includes a third word that is of a deadline concept associated with a time at which the action is to be taken with respect to the first word,

wherein determining that the outbound email is a malicious email is further based at least in part on the third word that is of the deadline concept.

4. The method of claim 1 , wherein analyzing second language of the outbound email with respect to the set of language concepts includes: obtaining a natural language processing model trained on a financial services and financial transaction lexicon; using the natural language processing model, identifying first word as being included in a sequence of words, related to financial transactions, in the outbound email; correlating the sequence of words to a financial transaction language concept; and utilizing the financial transaction language concept to identify the at least one of the previously sent emails represented in the sender model.

5. The method of claim 1 , further comprising:

determining that the email account is related to the group of email accounts;

associating the second sender model with the email account;

accessing a second outbound email sent from the email account;

analyzing third language of the second outbound email with respect to the set of language concepts;

determining, based on the analyzing, that the third language includes a third word that is of a second financial concept;

calculating a second similarity score between the second outbound email and at least one of the second previously sent emails represented in the group sender model; and

performing a second remedial action with respect to the second outbound email based at least in part on the second similarity score.

6. The method of claim 1 , wherein identifying the characteristic of the user of the email account includes identifying a department, within an organization, employing the user, further comprising:

accessing the second previously sent emails from the group of users associated with the department within the organization; and

generating the group sender model using the second previously sent emails.

7. A computer-email system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

obtaining a sender model that represents first language included in previously sent emails associated with an email account;

accessing an outbound email sent from the email account and destined for a recipient;

analyzing second language of the outbound email with respect to a set of language concepts;

determining, based on the analyzing, that the second language includes a first word that is of a financial concept;

determining, based on the analyzing, that the second language includes a second word that is of an action concept associated with an action to take with respect to the first word;

based at least in part on the second language including the first word of the financial concept and the second word of the action concept, calculating a similarity score between the outbound email and at least one of the previously sent emails represented in the sender model;

identifying a characteristic of a user of the email account; and

obtaining a group sender model that represents third language included in second previously sent emails associated with a group of users exhibiting the characteristic;

determining that the outbound email is a malicious email based at least in part on the similarity score and at least partly using the group sender model; and

performing a remedial action with respect to the outbound email the remedial action comprising at least one of:

deleting the outbound email;

quarantining the outbound email; or

updating the sender model at least partly using the outbound email.

8. The computer-email system of claim 7 , the operations further comprising:

determining, based on the analyzing, that the second language includes a third word that is of an urgency concept associated with the action to take with respect to the first word,

wherein determining that the outbound email is a malicious email is further based at least in part on the third word that is of the urgency concept.

9. The computer-email system of claim 7 , the operations further comprising:

determining, based on the analyzing, that the second language includes a third word that is of a deadline concept associated with a time at which the action is to be taken with respect to the first word,

wherein determining that the outbound email is a malicious email is further based at least in part on the third word that is of the deadline concept.

10. The computer-email system of claim 7 , the operations wherein analyzing second language of the outbound email with respect to the set of language concepts includes: obtaining a natural language processing model trained on a financial services and financial transaction lexicon; using the natural language processing model, identifying first word as being included in a sequence of words, related to financial transactions, in the outbound email; correlating the sequence of words to a financial transaction language concept; and utilizing the financial transaction language concept to identify the at least one of the previously sent emails represented in the sender model.

11. The computer-email system of claim 7 , the operations further comprising:

determining that the email account is related to the group of email accounts;

associating the second sender model with the email account;

accessing a second outbound email sent from the email account;

analyzing third language of the second outbound email with respect to the set of language concepts;

determining, based on the analyzing, that the third language includes a third word that is of a second financial concept;

calculating a second similarity score between the second outbound email and at least one of the second previously sent emails represented in the group sender model; and

performing a second remedial action with respect to the second outbound email based at least in part on the second similarity score.

12. The computer-email system of claim 7 , wherein identifying the characteristic of the user of the email account includes identifying a department, within an organization, employing the user, the operations further comprising:

accessing the second previously sent emails from the group of users associated with the department within the organization; and

generating the group sender model using the second previously sent emails.

13. One or more non-transitory computer-readable storage media storing computer-executable instructions that, when executed by one or more processors, cause a network orchestrator to perform operations comprising:

obtaining, at an email computer system, a sender model that represents first language included in previously sent emails associated with an email account;

accessing an outbound email sent from the email account and destined for a recipient;

analyzing second language of the outbound email with respect to a set of language concepts;

determining, based on the analyzing, that the second language includes a first word that is of a financial concept;

determining, based on the analyzing, that the second language includes a second word that is of an action concept associated with an action to take with respect to the first word;

based at least in part on the second language including the first word of the financial concept and the second word of the action concept, calculating a similarity score between the outbound email and at least one of the previously sent emails represented in the sender model;

identifying a characteristic of a user of the email account; and

obtaining a group sender model that represents third language included in second previously sent emails associated with a group of users exhibiting the characteristic;

determining that the outbound email is a malicious email based at least in part on the similarity score and at least partly using the group sender model; and

performing a remedial action with respect to the outbound email the remedial action comprising at least one of:

deleting the outbound email;

quarantining the outbound email; or

updating the sender model at least partly using the outbound email.

14. The one or more non-transitory computer-readable media of claim 13 , the operations further comprising:

determining, based on the analyzing, that the second language includes a third word that is of an urgency concept associated with the action to take with respect to the first word,

wherein determining that the outbound email is a malicious email is further based at least in part on the third word that is of the urgency concept.

15. The one or more non-transitory computer-readable media of claim 13 , the operations further comprising:

determining, based on the analyzing, that the second language includes a third word that is of a deadline concept associated with a time at which the action is to be taken with respect to the first word,

wherein determining that the outbound email is a malicious email is further based at least in part on the third word that is of the deadline concept.

16. The one or more non-transitory computer-readable media of claim 13 , wherein analyzing second language of the outbound email with respect to the set of language concepts includes: obtaining a natural language processing model trained on a financial services and financial transaction lexicon; using the natural language processing model, identifying first word as being included in a sequence of words, related to financial transactions, in the outbound email; correlating the sequence of words to a financial transaction language concept; and utilizing the financial transaction language concept to identify the at least one of the previously sent emails represented in the sender model.

17. The one or more non-transitory computer-readable media of claim 13 , the operations further comprising:

determining that the email account is related to the group of email accounts;

associating the second sender model with the email account;

accessing a second outbound email sent from the email account;

analyzing third language of the second outbound email with respect to the set of language concepts;

determining, based on the analyzing, that the third language includes a third word that is of a second financial concept;

calculating a second similarity score between the second outbound email and at least one of the second previously sent emails represented in the group sender model; and

performing a second remedial action with respect to the second outbound email based at least in part on the second similarity score.

Assignments (2)
CHANGE OF NAME Recorded Oct 13, 2023
From: ARMORBLOX, INC.
To: ARMORBLOX LLC
Reel/Frame 065238/0215 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2023
From: SAMPATH, DHANANJAY; SAMBAMOORTHY, ARJUN; ARUN, PRASHANTH; LYONS, ROBERT
To: ARMORBLOX, INC.
Reel/Frame 064625/0420 →
Continuity (3)
Continuation 17839847 · Jun 14, 2022
Provisional Application 63210164 · Jun 14, 2021
Related Publication 20240048514A1 · Feb 8, 2024
References Cited (5)
US 20120030115A1 · Peace · 2012 [cited by examiner]
US 20170054670A1 · Lee · 2017 [cited by examiner]
US 20170251006A1 · LaRosa · 2017 [cited by examiner]
US 20200067861A1 · Leddy · 2020 [cited by examiner]
US 20220141252A1 · Shi · 2022 [cited by examiner]
Cited By (1)
US 12,493,689