IP Library Granted Patent US 12,585,764
Granted Patent B2
US 12,585,764 · App. 18/355,825 · Granted Mar 24, 2026

Malicious behavior detection and mitigation in a document execution environment

Inventors: Nicholas William West (Redmond, WA); Brian Yeckley (Chicago, IL); Abhijit Salvi (Cupertino, CA); Taiga Matsumoto (Redmond, WA); Glenn Doren (Seattle, WA); Alexander Gregory Silverman (Seattle, WA); Roshan Satish (Seattle, WA); Michael Anthony Palazzolo (Seattle, WA)
Assignee: Docusign, Inc.
G06F21/554G06F21/567G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,764
App. No.
18/355,825
Granted
Mar 24, 2026
Kind
B2
Abstract

A document execution engine that receives a document for execution within a document execution environment. The document execution engine may also detect activity within the document execution environment associated with the received document, and apply the trained machine learned model to the detected activity to determine if the detected activity is representative of malicious behavior and, in response to determining that the detected activity is representative of malicious behavior, to identify remedial actions that can mitigate the malicious behavior. The document execution engine may also provide, to a device of a user, a recommendation to perform the identified remedial actions.

Claims (66)

1 . A method comprising:

receiving a document for execution within a document execution environment;

detecting activity within the document execution environment associated with the received document to obtain a detected activity, wherein the detected activity includes an amount of time between accessing the document and execution of the document within the document execution environment;

applying a trained machine learned model to the detected activity to determine if the detected activity is representative of malicious behavior and, in response to determining that the detected activity is representative of malicious behavior, to identify one or more remedial actions that can mitigate the malicious behavior,

wherein applying the trained machine learning model comprises:

applying, the trained machine learning model to the amount of the the time to determine a likelihood that the amount of the time is indicative of malicious behavior; and

applying a threshold to the likelihood that the amount of the time to identify the one or more remedial actions, wherein the threshold is determined based on a length of the document; and

providing, to a device of a user, a recommendation to perform the identified one or more remedial actions.

2 . The method of claim 1 , wherein detecting the activity associated with the received document further comprises:

identifying a party that created the document for execution;

detecting the access to the document by a second party;

detecting the execution of the document by the second party; and

determining a time of the execution.

3 . The method of claim 2 , wherein detecting the activity associated with the received document further comprises:

determining a geographic location associated with the detected access of the document by the second party; or

determining a geographic location associated with the detected execution of the document by the second party.

4 . The method of claim 1 , wherein detecting the activity associated with the received document further comprises:

identifying a type of the document;

accessing a second document of the same type; and

comparing the document and the second document for variability.

5 . The method of claim 1 , wherein detecting the activity associated with the received document further comprises identifying changes made to content of the document.

6 . The method of claim 1 , wherein detecting the activity associated with the received document comprises:

identifying a payment associated with the execution of the document; and

identifying the amount of the payment.

7 . The method of claim 1 , wherein detecting the activity associated with the received document further comprises detecting a deletion of the document or content within the document from the document execution environment.

8 . The method of claim 1 , wherein the recommendation identifies the document for execution and a type of the detected activity determined to be malicious.

9 . The method of claim 1 , wherein the one or more identified remedial actions comprise at least one of:

in response to detecting a deletion of the document for execution, restoring the document within the document execution environment;

providing the document for execution to additional signatories; and

limiting access to the document within the document execution environment.

10 . The method of claim 1 , wherein at least one type of detected activity representative of malicious behavior is defined by the user.

11 . The method of claim 10 , wherein the at least one type of detected activity representative of malicious behavior defined by the user comprises a threshold amount of the at least one type of detected activity.

12 . The method of claim 1 , wherein the device of the user comprises:

an interface on which the recommendation is displayed, the interface comprising:

for each of the one or more identified remedial actions, an interface element that, when selected by the user, causes at least one identified remedial action of the one or more identified remedial actions to be performed.

13 . Non-transitory computer readable storage media comprising instructions that when executed by one or more processors causes the one or more processors to:

receive a document for execution within the document execution environment;

detect activity within the document execution environment associated with the received document to obtain a detected activity, wherein the detected activity includes an amount of time between accessing the document and execution of the document within the document execution environment;

applying a trained machine learned model to the detected activity to determine if the detected activity is representative of malicious behavior and, in response to determining that the detected activity is representative of malicious behavior, to identify one or more remedial actions that can mitigate the malicious behavior, wherein applying the trained machine learning model comprises:

applying, the trained machine learning model to the amount of the the time to determine a likelihood that the amount of the time is indicative of malicious behavior; and

applying a threshold to the likelihood that the amount of the time to identify the one or more remedial actions, wherein the threshold is determined based on a length of the document; and

providing, to a device of a user, a recommendation to perform the identified one or more remedial actions.

14 . The non-transitory computer readable storage media of claim 13 , wherein detecting the activity associated with the received document corresponds to instructions that further cause the processors to:

identify a party that created the document for execution;

detect the access to the document by a second party;

detect the execution of the document by the second party; and

determine a time of the execution.

15 . The non-transitory computer readable storage medium of claim 13 , wherein detecting the activity associated with the received document corresponds to computer executable code that further causes the processors to:

identify changes made to content of the document.

16 . The non-transitory computer readable storage medium of claim 13 , wherein detecting the activity associated with the received document corresponds to computer executable code that causes the processors to:

identify a payment in conjunction with the execution of the document; and

identify an amount of the payment.

17 . The non-transitory computer readable storage medium of claim 13 , wherein the one or more remedial actions comprise at least one of:

in response to detecting a deletion of the document for execution, restore the document within the document execution environment;

providing the document for execution to additional signatories; and

limiting access to the document execution environment.

18 . The non-transitory computer readable storage medium of claim 13 , wherein at least one type of detected activity representative of malicious behavior is defined by the user.

19 . The non-transitory computer readable storage medium of claim 18 , wherein the at least one type of detected activity representative of malicious behavior defined by the user comprises a threshold amount of the at least one type of detected activity.

20 . A computer system comprising:

one or more processors; and

a non-transitory computer readable storage medium comprising instructions that when executed by the one or more processors causes the one or more processors to: receive a document for execution within a document execution environment; detect activity within the document execution environment associated with the received document to obtain a detected activity, wherein the detected activity includes an amount of time between accessing the document and execution of the document within the document execution environment;

apply a trained machine learned model to the detected activity to determine if the detected activity is representative of malicious behavior and, in response to determining that the detected activity is representative of malicious behavior, to identify one or more remedial actions that can mitigate the malicious behavior,

wherein applying the trained machine learning model comprises:

applying, the trained machine learning model to the amount of the the time to determine a likelihood that the amount of the time is indicative of malicious behavior; and

applying a threshold to the likelihood that the amount of the time to identify the one or more remedial actions, wherein the threshold is determined based on a length of the document; and

provide, to a device of a user, a recommendation to perform the identified one or more remedial actions.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded May 23, 2025
From: DOCUSIGN, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 071337/0240 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2023
From: WEST, NICHOLAS WILLIAM; YECKLEY, BRIAN; SALVI, ABHIJIT; MATSUMOTO, TAIGA; DOREN, GLENN; SILVERMAN, ALEXANDER GREGORY; SATISH, ROSHAN; PALAZZOLO, MICHAEL ANTHONY
To: DOCUSIGN, INC.
Reel/Frame 064328/0535 →
Continuity (2)
Continuation 16854802 · Apr 21, 2020
Related Publication 20230367874A1 · Nov 16, 2023
References Cited (49)
US 8549643B1 · Shou · 2013 [cited by applicant]
US 8607353B2 · Rippert, Jr. et al. · 2013 [cited by applicant]
US 8997219B2 · Staniford et al. · 2015 [cited by applicant]
US 9021352B2 · Goel · 2015 [cited by examiner]
US 9634875B2 · Porat · 2017 [cited by applicant]
US 10430570B2 · Gonser et al. · 2019 [cited by applicant]
US 10949852B1 · Kramme et al. · 2021 [cited by applicant]
US 11170104B1 · Stickle et al. · 2021 [cited by applicant]
US 20030159048A1 · Matsumoto · 2003 [cited by examiner]
US 20080114710A1 · Pucher et al. · 2008 [cited by applicant]
US 20100064369A1 · Stolfo et al. · 2010 [cited by applicant]
US 20110040784A1 · Rousseau · 2011 [cited by examiner]
US 20130254111A1 · Gonser et al. · 2013 [cited by applicant]
US 20130305101A1 · Gupta · 2013 [cited by examiner]
US 20150150090A1 · Carroll · 2015 [cited by examiner]
US 20150222667A1 · Nayshtut et al. · 2015 [cited by applicant]
US 20160092682A1 · Adams · 2016 [cited by examiner]
US 20160179776A1 · Bartley · 2016 [cited by examiner]
US 20170041296A1 · Ford · 2017 [cited by examiner]
US 20170171240A1 · Arzi · 2017 [cited by examiner]
US 20180034642A1 · Kaehler · 2018 [cited by examiner]
US 20180191770A1 · Nachenberg et al. · 2018 [cited by applicant]
US 20180205546A1 · Haque · 2018 [cited by examiner]
US 20180239959A1 · Bui et al. · 2018 [cited by applicant]
US 20180276390A1 · Grafi · 2018 [cited by examiner]
US 20190332619A1 · De Sousa Webber · 2019 [cited by applicant]
US 20190356641A1 · Isaacson · 2019 [cited by examiner]
US 20200074515A1 · Ghatage · 2020 [cited by examiner]
US 20200311646A1 · Koenig et al. · 2020 [cited by applicant]
US 20200322351A1 · Jadav et al. · 2020 [cited by applicant]
US 20200351285A1 · Eisenkot et al. · 2020 [cited by applicant]
US 20210012020A1 · Malton · 2021 [cited by examiner]
US 20210029164A1 · Albero et al. · 2021 [cited by applicant]
US 20210029170A1 · Gupta et al. · 2021 [cited by applicant]
US 20210036867A1 · Attard · 2021 [cited by examiner]
US 20210042180A1 · Sutton et al. · 2021 [cited by applicant]
US 20210182388A1 · Myneni · 2021 [cited by examiner]
US 20210209708A1 · Admon · 2021 [cited by applicant]
Advisory Action from U.S. Appl. No. 16/854,802 dated May 19, 2023, 5 pp. [cited by applicant]
Buczak et al., “A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection”, IEEE Communications Surveys & Tutorials, vol. 18, No. 2, IEEE, Oct. 2015, pp. 1153-1176. [cited by applicant]
Final Office Action from U.S. Appl. No. 16/854,802 dated Feb. 21, 2023, 25 pp. [cited by applicant]
Final Office Action from U.S. Appl. No. 16/854,802 dated Feb. 22, 2022, 22 pp. [cited by applicant]
Maiorca et al., “A structural and content-based approach for a precise and robust detection of malicious PDF files”, 2015 International Conference on Information Systems Security and Privacy (ICISSP), Feb. 2015, pp. 27-… [cited by applicant]
Office Action from U.S. Appl. No. 16/854,802 dated Oct. 25, 2021, 17 pp. [cited by applicant]
Office Action from U.S. Appl. No. 16/854,802 dated Sep. 20, 2022, p. 24. [cited by applicant]
Response to Final Office Action dated Feb. 22, 2022 from U.S. Appl. No. 16/854,802, filed May 17, 2022, 12 pp. [cited by applicant]
Response to Office Action dated Oct. 25, 2021 from U.S. Appl. No. 16/854,802, filed Jan. 10, 2022, 11 pp. [cited by applicant]
Response to Office Action dated Sep. 20, 2022 from U.S. Appl. No. 16/854,802, filed Dec. 1, 2022, p. 12. [cited by applicant]
Response to Office Action dated Feb. 21, 2023 from U.S. Appl. No. 16/854,802, filed Apr. 21, 2023, p. 15. [cited by applicant]