IP Library Granted Patent US 12,556,550
Granted Patent B2
US 12,556,550 · App. 18/373,134 · Granted Feb 17, 2026

Threat detection platforms for detecting, characterizing, and remediating email-based threats in real time

Inventors: Sanjay Jeyakumar (Berkeley, CA); Jeshua Alexis Bratman (New York, NY); Dmitry Chechik (San Francisco, CA); Abhijit Bagri (San Francisco, CA); Evan Reiser (San Francisco, CA); Sanny Xiao Lang Liao (San Francisco, CA); Yu Zhou Lee (San Francisco, CA); Carlos Daniel Gasperi (San Francisco, CA); Kevin Lau (San Francisco, CA); Kai Jing Jiang (San Francisco, CA); Su Li Debbie Tan (San Francisco, CA); Jeremy Kao (San Francisco, CA); Cheng-Lin Yeh (San Francisco, CA)
Assignee: Abnormal AI, Inc.
H04L63/1416H04L63/123H04L63/1433H04L63/145H04L63/1475
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,550
App. No.
18/373,134
Granted
Feb 17, 2026
Kind
B2
Abstract

A message addressed to a user is received. A first model is applied to the message to produce a first output indicative of whether the message is representative of a non-malicious message. The first model is trained using past messages that have been verified as non-malicious messages. It is determined, based on the first output, that the message is potentially a malicious message. Responsive to determining that the message is potentially a malicious email based on the first output, apply a second model to the message to produce a second output indicative of whether the message is representative of a given type of attack. The second model is one of a plurality of models. At least one model included in the plurality of models is associated with characterizing a goal of the malicious message. An action is performed with respect to the message based on the second output.

Claims (54)

1 . A system, comprising:

one or more processors configured to:

build a personalized behavioral model of normal communication for an enterprise by identifying a plurality of communication entities from ingested past messages and generate an entity risk graph that models historical combinations of the communication entities and associated risk scores;

receive a message addressed to a user;

apply the personalized behavioral model to the message to produce a first output indicative of whether the message is representative of a non-malicious message;

determine, based on the first output, that the message is potentially a malicious message;

responsive to determining that the message is potentially a malicious message based on the first output, apply to the message a second model from a multi-tiered ensemble framework to produce a second output used to determine for the message a type of attack among a plurality of types of attack able to be detected and characterize an attack goal based on a contextual analysis of a sender identity, message content, and message metadata, wherein the contextual analysis comprises scoring the message based at least in part on the entity risk graph; and

perform an action with respect to the message based on the second output; and

a memory coupled to at least one processor of the one or more processors and configured to provide instructions.

2 . The system of claim 1 , wherein performing the action comprises forwarding the message to the user.

3 . The system of claim 1 , wherein at least one model included in the multi-tiered ensemble framework is associated with determining whether content in a given message includes a query for data.

4 . The system of claim 1 , wherein at least one model included in the multi-tiered ensemble framework is associated with determining whether content in a given message includes a query for funds.

5 . The system of claim 1 , wherein at least one model included in the multi-tiered ensemble framework is associated with determining whether content in a given message includes a link to a Hypertext Markup Language (HTML) resource.

6 . The system of claim 1 , wherein at least one model included in the multi-tiered ensemble framework is associated with determining whether a given message includes an attachment.

7 . The system of claim 1 , wherein at least one model included in the multi-tiered ensemble framework is associated with discovering one or more facets of a security threat associated with the malicious message.

8 . The system of claim 1 , wherein a plurality of models in the multi-tiered ensemble framework collectively produce a plurality of outputs when applied to the message, and wherein the one or more processors are further configured to apply a third model designed to aggregate at least two of the plurality of outputs produced into a comprehensible visualization component.

9 . The system of claim 1 , wherein the second output indicates that the message includes a link to a Hypertext Markup Language (HTML) resource, and wherein performing the action comprises:

following the link so that the HTML resource is accessed using a virtual web browser;

extracting a Document Object Model (DOM) for the HTML resource through the virtual web browser; and

analyzing the DOM to determine whether the link represents a security threat.

10 . The system of claim 1 , wherein the second output indicates that the message includes a primary link to a resource hosted by a network-accessible hosting service, and wherein performing the action comprises:

following the primary link so that the resource is accessed using a virtual web browser;

discovering whether any secondary links to secondary resources are present by examining content of the resource through the virtual web browser;

for each secondary link, following the secondary link so that the corresponding secondary resource is accessed using the virtual web browser and analyzing content of the corresponding secondary resource to determine whether the secondary link represents a security threat; and

determining whether the primary link represents a security threat based on whether any secondary links were determined to represent security threats.

11 . The system of claim 1 ,

wherein the second output indicates that the message includes a link to a Hypertext Markup Language (HTML) resource, and wherein performing the action comprises:

following the link so that the HTML resource is accessed using a virtual web browser;

capturing a screenshot of the HTML resource through the virtual web browser;

applying a computer vision algorithm designed to identify similarities between the screenshot and a library of verified sign-in websites; and

determining whether the link represents a security threat based on an output produced by the computer vision algorithm.

12 . The system of claim 1 , wherein the second output indicates that the message includes an attachment, and wherein performing the action comprises:

opening the attachment within a secure processing environment; and

determining whether the attachment represents a security threat based on an analysis of content of the attachment.

13 . A method, comprising:

building a personalized behavioral model of normal communication for an enterprise by identifying a plurality of communication entities from ingested past messages and generate an entity risk graph that models historical combinations of the communication entities and associated risk scores;

receiving a message addressed to a user;

applying the personalized behavioral model to the message to produce a first output indicative of whether the message is representative of a non-malicious message;

determining, based on the first output, that the message is potentially a malicious message;

responsive to determining that the message is potentially a malicious message based on the first output, applying to the message a second model from a multi-tiered ensemble framework to produce a second output used to determine for the message a type of attack among a plurality of types of attack able to be detected and characterize an attack goal based on a contextual analysis of a sender identity, message content, and message metadata, wherein the contextual analysis comprises scoring the message based at least in part on the entity risk graph; and

performing an action with respect to the message based on the second output.

14 . The method of claim 13 , wherein performing the action comprises forwarding the message to the user.

15 . The method of claim 13 , wherein at least one model included in the multi-tiered ensemble framework is associated with determining whether content in a given message includes a query for data.

16 . The method of claim 13 , wherein at least one model included in the multi-tiered ensemble framework is associated with determining whether content in a given message includes a query for funds.

17 . The method of claim 13 , wherein at least one model included in the multi-tiered ensemble framework is associated with determining whether content in a given message includes a link to a Hypertext Markup Language (HTML) resource.

18 . The method of claim 13 , wherein at least one model included in the multi-tiered ensemble framework is associated with discovering one or more facets of a security threat associated with the malicious message.

19 . The method of claim 13 , wherein a plurality of models in the multi-tiered ensemble framework collectively produce a plurality of outputs when applied to the message, and further comprising applying a third model designed to aggregate at least two of the plurality of outputs produced into a comprehensible visualization component.

20 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

building a personalized behavioral model of normal communication for an enterprise by identifying a plurality of communication entities from ingested past messages and generate an entity risk graph that models historical combinations of the communication entities and associated risk scores;

receiving a message addressed to a user;

applying the personalized behavioral to the message to produce a first output indicative of whether the message is representative of a non-malicious message;

determining, based on the first output, that the message is potentially a malicious message;

responsive to determining that the message is potentially a malicious message based on the first output, applying to the message a second model from a multi-tiered ensemble framework to produce a second output used to determine for the message a type of attack among a plurality of types of attack able to be detected and characterize an attack goal based on a contextual analysis of a sender identity, message content, and message metadata, wherein the contextual analysis comprises scoring the message based at least in part on the entity risk graph; and

performing an action with respect to the message based on the second output.

Continuity (5)
Continuation 16672854 · Nov 4, 2019
Provisional Application 62813603 · Mar 4, 2019
Provisional Application 62807888 · Feb 20, 2019
Provisional Application 62782158 · Dec 19, 2018
Related Publication 20240171596A1 · May 23, 2024
References Cited (253)
US 5999932A · Paul · 1999 [cited by applicant]
US 6023723A · McCormick · 2000 [cited by applicant]
US 6088717A · Reed · 2000 [cited by applicant]
US 7263506B2 · Lee · 2007 [cited by applicant]
US 7451487B2 · Oliver · 2008 [cited by applicant]
US 7610344B2 · Mehr · 2009 [cited by applicant]
US 7865953B1 · Hsieh · 2011 [cited by examiner]
US 7953814B1 · Chasin · 2011 [cited by applicant]
US 8112484B1 · Sharma · 2012 [cited by applicant]
US 8244532B1 · Begeja · 2012 [cited by applicant]
US 8566938B1 · Prakash · 2013 [cited by applicant]
US 8819819B1 · Johnston · 2014 [cited by applicant]
US 8935788B1 · Diao · 2015 [cited by applicant]
US 9009824B1 · Chen · 2015 [cited by applicant]
US 9154514B1 · Prakash · 2015 [cited by applicant]
US 9213827B2 · Li · 2015 [cited by applicant]
US 9245115B1 · Jakobsson · 2016 [cited by examiner]
US 9245225B2 · Winn · 2016 [cited by applicant]
US 9264418B1 · Crosley · 2016 [cited by applicant]
US 9348981B1 · Hearn · 2016 [cited by applicant]
US 9413782B1 · Adams · 2016 [cited by examiner]
US 9473437B1 · Jakobsson · 2016 [cited by applicant]
US 9516053B1 · Muddu · 2016 [cited by applicant]
US 9537880B1 · Jones · 2017 [cited by applicant]
US 9571512B2 · Ray · 2017 [cited by applicant]
US 9686308B1 · Srivastava · 2017 [cited by applicant]
US 9756007B1 · Stringhini · 2017 [cited by applicant]
US 9774626B1 · Himler · 2017 [cited by applicant]
US 9781152B1 · Mistratov · 2017 [cited by applicant]
US 9847973B1 · Jakobsson · 2017 [cited by applicant]
US 9940394B1 · Grant · 2018 [cited by applicant]
US 9946789B1 · Li · 2018 [cited by applicant]
US 9954805B2 · Nigam · 2018 [cited by applicant]
US 9961096B1 · Pierce · 2018 [cited by applicant]
US 9967268B1 · Hewitt · 2018 [cited by applicant]
US 10015182B1 · Shintre · 2018 [cited by applicant]
US 10044745B1 · Jones · 2018 [cited by applicant]
US 10091312B1 · Khanwalkar · 2018 [cited by applicant]
US 10104029B1 · Chambers · 2018 [cited by applicant]
US 10129194B1 · Jakobsson · 2018 [cited by applicant]
US 10129288B1 · Xie · 2018 [cited by applicant]
US 10243989B1 · Ding · 2019 [cited by applicant]
US 10250624B2 · Mixer · 2019 [cited by applicant]
US 10277628B1 · Jakobsson · 2019 [cited by applicant]
US 10362057B1 · Wu · 2019 [cited by applicant]
US 10397272B1 · Bruss · 2019 [cited by examiner]
US 10419468B2 · Glatfelter · 2019 [cited by applicant]
US 10482239B1 · Liu · 2019 [cited by examiner]
US 10523609B1 · Subramanian · 2019 [cited by applicant]
US 10601865B1 · Mesdaq · 2020 [cited by applicant]
US 10616272B2 · Chambers · 2020 [cited by applicant]
US 10673880B1 · Pratt · 2020 [cited by applicant]
US 10721195B2 · Jakobsson · 2020 [cited by applicant]
US 10834127B1 · Yeh · 2020 [cited by applicant]
US 10911489B1 · Chechik · 2021 [cited by applicant]
US 10972483B2 · Thomas · 2021 [cited by applicant]
US 10972485B2 · Ladnai · 2021 [cited by applicant]
US 11019076B1 · Jakobsson · 2021 [cited by applicant]
US 11063897B2 · Kessler · 2021 [cited by applicant]
US 11153351B2 · Kalinin · 2021 [cited by applicant]
US 11494421B1 · Ghafourifar · 2022 [cited by applicant]
US 20020002520A1 · Gatto · 2002 [cited by applicant]
US 20020013692A1 · Chandhok · 2002 [cited by applicant]
US 20020116463A1 · Hart · 2002 [cited by applicant]
US 20030204569A1 · Andrews · 2003 [cited by applicant]
US 20040030913A1 · Liang · 2004 [cited by applicant]
US 20040117450A1 · Campbell · 2004 [cited by applicant]
US 20040128355A1 · Chao · 2004 [cited by applicant]
US 20040215977A1 · Goodman · 2004 [cited by applicant]
US 20040260922A1 · Goodman · 2004 [cited by applicant]
US 20050039019A1 · Delany · 2005 [cited by applicant]
US 20050076084A1 · Loughmiller · 2005 [cited by examiner]
US 20050187934A1 · Motsinger · 2005 [cited by applicant]
US 20050198518A1 · Kogan · 2005 [cited by applicant]
US 20060036698A1 · Hebert · 2006 [cited by applicant]
US 20060053203A1 · Mijatovic · 2006 [cited by applicant]
US 20060191012A1 · Banzhof · 2006 [cited by applicant]
US 20060253581A1 · Dixon · 2006 [cited by applicant]
US 20070074169A1 · Chess · 2007 [cited by applicant]
US 20070276851A1 · Friedlander · 2007 [cited by applicant]
US 20080005249A1 · Hart · 2008 [cited by applicant]
US 20080086532A1 · Cunningham · 2008 [cited by applicant]
US 20080114684A1 · Foster · 2008 [cited by applicant]
US 20080201401A1 · Pugh · 2008 [cited by applicant]
US 20090037350A1 · Rudat · 2009 [cited by applicant]
US 20090132490A1 · Okraglik · 2009 [cited by applicant]
US 20100115040A1 · Sargent · 2010 [cited by applicant]
US 20100211641A1 · Yih · 2010 [cited by applicant]
US 20100318614A1 · Sager · 2010 [cited by applicant]
US 20110173142A1 · Dasgupta · 2011 [cited by applicant]
US 20110179126A1 · Wetherell · 2011 [cited by applicant]
US 20110213869A1 · Korsunsky · 2011 [cited by applicant]
US 20110214157A1 · Korsunsky · 2011 [cited by applicant]
US 20110231510A1 · Korsunsky · 2011 [cited by applicant]
US 20110231564A1 · Korsunsky · 2011 [cited by applicant]
US 20110238855A1 · Korsunsky · 2011 [cited by applicant]
US 20120028606A1 · Bobotek · 2012 [cited by applicant]
US 20120110672A1 · Judge · 2012 [cited by applicant]
US 20120124671A1 · Fritzson · 2012 [cited by applicant]
US 20120137367A1 · Dupont · 2012 [cited by applicant]
US 20120233662A1 · Scott-Cowley · 2012 [cited by applicant]
US 20120278887A1 · Krish · 2012 [cited by applicant]
US 20120290712A1 · Walter · 2012 [cited by applicant]
US 20120297484A1 · Srivastava · 2012 [cited by applicant]
US 20130007152A1 · Alspector · 2013 [cited by applicant]
US 20130041955A1 · Chasin · 2013 [cited by applicant]
US 20130086180A1 · Midgen · 2013 [cited by applicant]
US 20130086261A1 · Lim · 2013 [cited by applicant]
US 20130097709A1 · Basavapatna · 2013 [cited by applicant]
US 20130167207A1 · Davis · 2013 [cited by applicant]
US 20130191759A1 · Bhogal · 2013 [cited by applicant]
US 20140013441A1 · Hencke · 2014 [cited by applicant]
US 20140032589A1 · Styler · 2014 [cited by applicant]
US 20140181223A1 · Homsany · 2014 [cited by applicant]
US 20140325662A1 · Foster · 2014 [cited by applicant]
US 20140365303A1 · Vaithilingam · 2014 [cited by applicant]
US 20140379825A1 · Speier · 2014 [cited by applicant]
US 20140380478A1 · Canning · 2014 [cited by applicant]
US 20150026027A1 · Priess · 2015 [cited by applicant]
US 20150128274A1 · Giokas · 2015 [cited by applicant]
US 20150143456A1 · Raleigh · 2015 [cited by applicant]
US 20150161609A1 · Christner · 2015 [cited by applicant]
US 20150161611A1 · Duke · 2015 [cited by applicant]
US 20150228004A1 · Bednarek · 2015 [cited by applicant]
US 20150234831A1 · Prasanna Kumar · 2015 [cited by applicant]
US 20150237068A1 · Sandke · 2015 [cited by applicant]
US 20150295942A1 · Tao · 2015 [cited by applicant]
US 20150295945A1 · Canzanese, Jr. · 2015 [cited by applicant]
US 20150319157A1 · Sherman · 2015 [cited by applicant]
US 20150339477A1 · Abrams · 2015 [cited by applicant]
US 20160014151A1 · Prakash · 2016 [cited by applicant]
US 20160036829A1 · Sadeh-Koniecpol · 2016 [cited by applicant]
US 20160057167A1 · Bach · 2016 [cited by applicant]
US 20160063277A1 · Vu · 2016 [cited by applicant]
US 20160134649A1 · Allen · 2016 [cited by applicant]
US 20160156654A1 · Chasin · 2016 [cited by applicant]
US 20160227367A1 · Alsehly · 2016 [cited by applicant]
US 20160253598A1 · Yamada · 2016 [cited by applicant]
US 20160262128A1 · Hailpern · 2016 [cited by applicant]
US 20160301705A1 · Higbee · 2016 [cited by applicant]
US 20160306812A1 · Mchenry · 2016 [cited by applicant]
US 20160321243A1 · Walia · 2016 [cited by applicant]
US 20160328526A1 · Park · 2016 [cited by applicant]
US 20160344770A1 · Verma · 2016 [cited by examiner]
US 20160380936A1 · Gunasekara · 2016 [cited by applicant]
US 20170041296A1 · Ford · 2017 [cited by applicant]
US 20170048273A1 · Bach · 2017 [cited by applicant]
US 20170098219A1 · Peram · 2017 [cited by applicant]
US 20170111506A1 · Strong · 2017 [cited by applicant]
US 20170180398A1 · Gonzales, Jr. · 2017 [cited by applicant]
US 20170186112A1 · Polapala · 2017 [cited by applicant]
US 20170214701A1 · Hasan · 2017 [cited by applicant]
US 20170222960A1 · Agarwal · 2017 [cited by applicant]
US 20170223046A1 · Singh · 2017 [cited by applicant]
US 20170230323A1 · Jakobsson · 2017 [cited by applicant]
US 20170230403A1 · Kennedy · 2017 [cited by applicant]
US 20170237754A1 · Todorovic · 2017 [cited by applicant]
US 20170237776A1 · Higbee · 2017 [cited by applicant]
US 20170251006A1 · Larosa · 2017 [cited by applicant]
US 20170289191A1 · Thioux · 2017 [cited by applicant]
US 20170324767A1 · Srivastava · 2017 [cited by applicant]
US 20170346853A1 · Wyatt · 2017 [cited by applicant]
US 20180026926A1 · Nigam · 2018 [cited by applicant]
US 20180027006A1 · Zimmermann · 2018 [cited by applicant]
US 20180041536A1 · Berlin · 2018 [cited by examiner]
US 20180084003A1 · Uriel · 2018 [cited by applicant]
US 20180084013A1 · Dalton · 2018 [cited by applicant]
US 20180091453A1 · Jakobsson · 2018 [cited by applicant]
US 20180091476A1 · Jakobsson · 2018 [cited by applicant]
US 20180115584A1 · Alhumaisan · 2018 [cited by examiner]
US 20180159808A1 · Pal · 2018 [cited by applicant]
US 20180189347A1 · Ghafourifar · 2018 [cited by applicant]
US 20180196942A1 · Kashyap · 2018 [cited by applicant]
US 20180219888A1 · Apostolopoulos · 2018 [cited by applicant]
US 20180227324A1 · Chambers · 2018 [cited by applicant]
US 20180295146A1 · Kovega · 2018 [cited by applicant]
US 20180324297A1 · Kent · 2018 [cited by applicant]
US 20180375814A1 · Hart · 2018 [cited by applicant]
US 20190007433A1 · McLane · 2019 [cited by examiner]
US 20190014143A1 · Syme · 2019 [cited by applicant]
US 20190020682A1 · Edwards · 2019 [cited by applicant]
US 20190026461A1 · Cidon · 2019 [cited by applicant]
US 20190028509A1 · Cidon · 2019 [cited by applicant]
US 20190052655A1 · Benishti · 2019 [cited by applicant]
US 20190065748A1 · Foster · 2019 [cited by applicant]
US 20190068616A1 · Woods · 2019 [cited by applicant]
US 20190081983A1 · Teal · 2019 [cited by applicant]
US 20190087428A1 · Crudele · 2019 [cited by applicant]
US 20190089711A1 · Faulkner · 2019 [cited by applicant]
US 20190104154A1 · Kumar · 2019 [cited by applicant]
US 20190109863A1 · Traore · 2019 [cited by applicant]
US 20190141183A1 · Chandrasekaran · 2019 [cited by applicant]
US 20190166161A1 · Anand · 2019 [cited by applicant]
US 20190166162A1 · Anand · 2019 [cited by applicant]
US 20190190929A1 · Thomas · 2019 [cited by applicant]
US 20190190936A1 · Thomas · 2019 [cited by applicant]
US 20190199745A1 · Jakobsson · 2019 [cited by applicant]
US 20190205511A1 · Zhan · 2019 [cited by applicant]
US 20190222606A1 · Schweighauser · 2019 [cited by applicant]
US 20190238571A1 · Adir · 2019 [cited by applicant]
US 20190260780A1 · Matthew · 2019 [cited by applicant]
US 20190311121A1 · Martin · 2019 [cited by applicant]
US 20190319905A1 · Baggett · 2019 [cited by applicant]
US 20190319987A1 · Levy · 2019 [cited by applicant]
US 20190349400A1 · Bruss · 2019 [cited by applicant]
US 20190384911A1 · Caspi · 2019 [cited by applicant]
US 20200007502A1 · Everton · 2020 [cited by applicant]
US 20200021609A1 · Kuppanna · 2020 [cited by applicant]
US 20200044851A1 · Everson · 2020 [cited by applicant]
US 20200053111A1 · Jakobsson · 2020 [cited by applicant]
US 20200053120A1 · Wilcox · 2020 [cited by applicant]
US 20200067861A1 · Leddy · 2020 [cited by applicant]
US 20200067976A1 · Jakobsson · 2020 [cited by applicant]
US 20200068031A1 · Kursun · 2020 [cited by applicant]
US 20200074078A1 · Saxe · 2020 [cited by applicant]
US 20200076825A1 · Vallur · 2020 [cited by applicant]
US 20200125725A1 · Petersen · 2020 [cited by applicant]
US 20200125728A1 · Savir · 2020 [cited by examiner]
US 20200127962A1 · Chuhadar · 2020 [cited by applicant]
US 20200162483A1 · Farhady · 2020 [cited by applicant]
US 20200204572A1 · Jeyakumar · 2020 [cited by applicant]
US 20200287936A1 · Nguyen · 2020 [cited by applicant]
US 20200344251A1 · Jeyakumar · 2020 [cited by applicant]
US 20200358804A1 · Crabtree · 2020 [cited by applicant]
US 20200374251A1 · Warshaw · 2020 [cited by applicant]
US 20200389486A1 · Jeyakumar · 2020 [cited by applicant]
US 20200396190A1 · Pickman · 2020 [cited by applicant]
US 20200396258A1 · Jeyakumar · 2020 [cited by applicant]
US 20200412767A1 · Crabtree · 2020 [cited by applicant]
US 20210021612A1 · Higbee · 2021 [cited by applicant]
US 20210058395A1 · Jakobsson · 2021 [cited by applicant]
US 20210091962A1 · Finke · 2021 [cited by applicant]
US 20210092154A1 · Kumar · 2021 [cited by applicant]
US 20210168161A1 · Dunn · 2021 [cited by applicant]
US 20210240836A1 · Hazony · 2021 [cited by applicant]
US 20210266294A1 · Chechik · 2021 [cited by applicant]
US 20210271741A1 · Habal · 2021 [cited by applicant]
US 20210272066A1 · Bratman · 2021 [cited by applicant]
US 20210295179A1 · Eyal Altman · 2021 [cited by applicant]
US 20210329035A1 · Jeyakumar · 2021 [cited by applicant]
US 20210336983A1 · Lee · 2021 [cited by applicant]
US 20210360027A1 · Boyer · 2021 [cited by applicant]
US 20210374679A1 · Bratman · 2021 [cited by applicant]
US 20210374680A1 · Bratman · 2021 [cited by applicant]
US 20220021700A1 · Devlin · 2022 [cited by applicant]
CN 107315954 · 2017 [cited by applicant]
Fette, Ian, Norman Sadeh, and Anthony Tomasic. “Learning to detect phishing emails.” Proceedings of the 16th international conference on World Wide Web. 2007. (Year: 2007). [cited by examiner]
Barngrover, Adam, ‘Vendor Access Management with IGA’, Saviynt Inc. Apr. 24, 2019 (Apr. 24, 2019) Retrieved on Apr. 17, 2021 (Apr. 17, 2021) from <https://saviynt.com/vendor-access-management-with-iga/> entire document,… [cited by applicant]
Information Security Media Group, ‘Multi-Channel Fraud: A Defense Plan’, Retrieved on Apr. 18, 2021 (Apr. 18, 2021) from <https ://www.bankInfosecurity.com/Interviews/multi-channel-fraud-defense-plan-i-1799>, Feb. 20, 2… [cited by applicant]
International Search Report and Written Opinion mailed Apr. 24, 2020 of PCT/US2019/067279 (14 pages). [cited by applicant]
Mahajan, et al., ‘Finding HTML Presentation Failures Using Image Comparison Techniques’, ASE'14, pp. 91-98 (Year: 2014). [cited by applicant]
Mont, Marco Casassa, ‘Towards accountable management of identity and privacy: Sticky policies and enforceable tracing services’, 14th International Workshop on Database and Expert Systems Applications, 2003. Proceedings… [cited by applicant]
Proofpoint (Proofpoint Closed-Loop Email Analysis and Response, Aug. 2018, 2 pages) (Year: 2018). [cited by applicant]