IP Library Patent Application 18295766
Patent Application
App. No. 18/295,766

MACHINE LEARNING SYSTEM FOR AUTOMATED DETECTION OF SUSPICIOUS DIGITAL IDENTIFIERS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/295,766
Abstract

A machine learning system for providing automated detection of suspicious digital identifiers is disclosed. The system receives a request to determine if an identifier associated with a resource attempting to be accessed by a device is suspicious. In response to the request, the system selects a machine learning model and loads or computes features associated with the address to facilitate determination regarding suspiciousness of the digital identifier. The system executes the machine learning model utilizing the features to determine whether the digital identifier is suspicious. The determination regarding suspiciousness of the digital identifier is provided to a phishing and content protection classifier to persist the response in a database. The determination may be verified by an expert and may be utilized to prevent access to the resource associated with the identifier and to train the machine learning model to enhance future determinations relating to suspiciousness of digital identifiers.

Claims (63)

1 . A system, comprising:

a memory storing instructions; and

a processor configured to execute the instructions to cause the processor to be configured to:

receive a request to determine whether an identifier associated with a resource attempting to be accessed by a device associated with a user is suspicious;

access, in response to the request, a machine learning model to facilitate determination of whether the identifier associated with the resource is suspicious;

load identifier features extracted from the identifier associated with the resource attempting to be accessed;

determine a suspiciousness score for the identifier associated with the resource attempting to be accessed by the device;

determine whether the identifier associated with the resource attempting to be accessed is suspicious based on execution of the machine learning model using the identifier features and based on the suspiciousness score; and

provide, in response to the request, an indication of the suspiciousness score for the identifier and whether the identifier is suspicious.

2 . The system of claim 1 , wherein the processor is further configured to determine a context associated with suspiciousness of the identifier based on the suspiciousness score.

3 . The system of claim 1 , wherein the processor is further configured to reject the indication if feedback received relating to the indication does not verify the indication that the identifier is suspicious, confirms that the identifier is not suspicious, or a combination thereof.

4 . The system of claim 3 , wherein the processor is further configured to:

assign a label to the identifier to provide a labeled identifier indicating that the identifier is not suspicious if the indication is rejected.

5 . The system of claim 1 , wherein the processor is further configured to automatically select the machine learning model from a plurality of machine learning models to facilitate determination of whether the identifier associated with the resource is suspicious based on a type of the identifier, based on a type of the resource, based on an identity of the user, based on the identifier features extracted from the identifier, or a combination thereof.

6 . The system of claim 1 , wherein the processor is further configured to:

activate an inference pipeline service in response to the request; and

transmit, by utilizing an inference orchestrator of the inference pipeline service, a control signal to cause a feature extractor to extract the identifier features from the identifier.

7 . The system of claim 1 , wherein the processor is further configured to:

activate a training pipeline service; and

activate, by utilizing a training orchestrator of the training pipeline service, a model development sample generator configured to:

obtain a labeled dataset including data labeled as suspicious or not suspicious;

generate a plurality of samples from the labeled dataset; and

transmit a notification to the training orchestrator indicating that the plurality of samples have been generated.

8 . The system of claim 7 , wherein the processor is further configured to:

transmit, by utilizing the training orchestrator of the training pipeline service, a control signal to cause a feature extractor to obtain the plurality of samples;

extract, by utilizing the feature extractor, features from the plurality of samples; and

transmit a notification to the training orchestrator indicating that the features have been extracted from the plurality of samples.

9 . The system of claim 8 , wherein the processor is further configured to:

train, by utilizing a learner of the training pipeline service, the machine learning model using the features, the plurality of samples, or a combination thereof; and

store the machine learning model in a model registry.

10 . The system of claim 1 , wherein the processor is further configured to:

monitor the machine learning model utilizing a model monitoring service; and

trigger, by utilizing the model monitoring service, training of the machine learning model based on a schedule, based on the request, based on a task to be performed by the machine learning model, or a combination thereof.

11 . The system of claim 1 , wherein the processor is further configured to:

generate a recommendation for modifying the machine learning model based on telemetry data generated based on operation of the machine learning model; and

modify the machine learning model based on the recommendation.

12 . The system of claim 1 , wherein the processor is further configured to rank the identifier relative to a plurality of other ranked identifiers based on the suspiciousness score calculated for the identifier and suspiciousness scores calculated for the plurality of other ranked identifiers.

13 . A method, comprising:

receiving a request to determine whether an identifier associated with a resource attempting to be accessed by a device associated with a user is suspicious;

selecting, in response to the request, a machine learning model to facilitate determination of whether the identifier associated with the resource is suspicious;

loading identifier features extracted from the identifier associated with the resource attempting to be accessed;

determining a suspiciousness score for the identifier associated with the resource attempting to be accessed by the device;

determining, by utilizing instructions from a memory that are executed by a processor, whether the identifier associated with the resource attempting to be accessed is suspicious based on execution of the machine learning model using the identifier features and based on the suspiciousness score; and

providing, in response to the request, an indication of the suspiciousness score for the identifier and whether the identifier is suspicious.

14 . The method of claim 13 , further comprising confirming performance of the machine learning model based on feedback verifying the indication, an accuracy of the indication, a speed of the machine learning model in determining whether the identifier is suspicious, an uptime of the machine learning model, or a combination thereof.

15 . The method of claim 13 , further comprising assigning a label to the identifier, wherein the label indicates the suspiciousness score, a type of malicious attack associated with the identifier, an identity of a malicious actor associated with the identifier, or a combination thereof.

16 . The method of claim 13 , further comprising increasing the suspiciousness score for the identifier if the identifier matches a string in a list of authoritative strings.

17 . The method of claim 13 , further comprising:

redirecting the device of the user to a different resource if the identifier associated with the resource is determined to be suspicious.

18 . The method of claim 17 , further comprising identifying a type of malicious attack associated with the identifier if the identifier is determined to be suspicious.

19 . A system, comprising:

a memory storing instructions; and

a processor configured to execute the instructions to cause the processor to be configured to:

obtain labeled datasets that comprise data verified as suspicious or not suspicious;

extract training features from the labeled datasets;

train machine learning models using the training features extracted from the labeled datasets;

receive a request to determine whether an identifier associated with a resource attempting to be accessed by a device associated with a user is suspicious;

access, in response to the request, at least one machine learning model to facilitate determination of whether the identifier associated with the resource is suspicious;

load identifier features extracted from the identifier associated with the resource attempting to be accessed;

determine a suspiciousness score for the identifier associated with the resource attempting to be accessed by the device;

determine whether the identifier associated with the resource attempting to be accessed is suspicious based on execution of the machine learning model and based on the suspiciousness score; and

provide, in response to the request, an indication of the suspiciousness score for the identifier and whether the identifier is suspicious.

20 . The system of claim 19 , wherein the processor is further configured to adjust a level of access to the resource based on the suspiciousness score.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2023
From: RADON, AUNGON NAG; BUCK, BRIAN JAMES
To: LOOKOUT, INC.
Reel/Frame 063244/0756 →