IP Library › Granted Patent US 12,470,572
Granted Patent B2
US 12,470,572 · App. 18/523,501 · Granted Nov 11, 2025

Susceptibility-based warning techniques

Inventors: Nikolaos Sapountzis (San Francisco, CA); Madhuri Kolli (San Jose, CA); Fabio R. Maino (Palo Alto, CA); Daniela Alvim Seabra de Oliveira (Gainesville, FL)
Assignee: Cisco Technology, Inc.
H04L63/1416G06F40/30H04L63/1433H04L63/1483H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,572
App. No.
18/523,501
Granted
Nov 11, 2025
Kind
B2
Abstract

In one embodiment, a method comprises training at least one model based at least in part on interactions between one or more users and electronic messages sent to addresses associated with the one or more users, receiving a first electronic message sent to a first address associated with a first user, analyzing the first electronic message to generate first feature data, determining one or more characteristics of the first user to generate second feature data, inputting, to the at least one model, the first feature data and the second feature data, and receiving, as output of the at least one model, data indicating whether to output, to the first user, a warning regarding the first electronic message.

Claims (85)

1 . A messaging communication system comprising:

one or more processors; and

one or more computer-readable media storing computer-executable instructions that, when executed, cause the one or more processors to perform acts comprising:

receiving an electronic message sent to an address associated with a user;

analyzing content in a body of the electronic message to determine that the content of the body of the electronic message includes malicious data comprising a deceptive cue for a scam;

receiving characteristic data indicating a characteristic of the user;

receiving a model that is trained on characteristics and previous electronic messages, wherein the model is trained to determine likelihoods that the user is susceptible to falling victim to deceptive cues in the previous electronic messages based on the characteristics;

inputting the characteristic data into the model to determine whether the user is likely to interact with the malicious data in the electronic message and fall victim to the deceptive cue for the scam;

receiving, as output of the model, susceptibility data indicating that the user is likely to fall victim to the deceptive cue and determine that the scam is a legitimate message; and

determining, based at least in part on the susceptibility data indicating that the user is likely to determine that the scam is a legitimate message, that the user is likely to interact with the malicious data in the electronic message and fall victim to the deceptive cue for the scam.

2 . The messaging communication system as recited in claim 1 , the acts further comprising:

in response to determining the user is susceptible to falling victim to the malicious data, generating a warning indicating that the electronic message includes malicious data; and

sending the warning to the address associated with the user, the warning configured to be output in association with the electronic message.

3 . The messaging communication system as recited in claim 1 , the acts further comprising:

analyzing previous interactions between the user and a portion of the previous electronic messages which were sent to the address associated with the user; and

training the model based at least in part on the previous interactions.

4 . The messaging communication system as recited in claim 1 , the acts further comprising:

analyzing previous interactions between the user and a portion of the previous electronic messages sent to the address associated with the user;

performing natural-language-processing (NLP) analysis on the electronic message to identify the deceptive cue included in the electronic message; and

determining, based at least in part on the previous interactions, whether the user is susceptible to falling victim to the deceptive cue in the electronic message.

5 . The messaging communication system as recited in claim 1 , wherein:

the characteristic of the user is a particular demographic characteristic including at least one of age, gender, or location associated with the user; and

the susceptibility data indicates that the particular demographic characteristic of the user makes the user susceptible to the malicious data in the electronic message.

6 . The messaging communication system as recited in claim 1 , wherein:

performing natural-language-processing (NLP) analysis on the electronic message to identify text representing the malicious data;

identifying, from the text, one or more words that are of personal relevance to the user; and

determining, based at least in part on the one or more words that are of personal relevance to the user, that the user is susceptible to falling victim to the malicious data.

7 . The messaging communication system as recited in claim 1 , wherein:

the characteristic of the user is a cognitive ability of the user;

the susceptibility data indicates that the cognitive ability of the user makes the user susceptible to the malicious data in the electronic message.

8 . A computer-implemented method comprising:

receiving an electronic message sent to an address associated with a user;

analyzing content in a body of the electronic message to determine that the content of the body of the electronic message includes malicious data comprising a deceptive cue for a scam;

receiving characteristic data indicating a characteristic of the user;

receiving a model that is trained on characteristics and previous electronic messages, wherein the model is trained to determine likelihoods that the user is susceptible to falling victim to deceptive cues in the previous electronic messages based on the characteristics;

inputting the characteristic data into the model to determine whether the user is likely to interact with the malicious data in the electronic message and fall victim to the deceptive cue for the scam;

receiving, as output of the model, susceptibility data indicating that the user is likely to fall victim to the deceptive cue and determine that the scam is a legitimate message; and

determining, based at least in part on the susceptibility data indicating that the user is likely to determine that the scam is a legitimate message, that the user is likely to interact with the malicious data in the electronic message and fall victim to the deceptive cue for the scam.

9 . The computer-implemented method as recited in claim 8 , further comprising:

in response to determining the user is susceptible to falling victim to the malicious data, generating a warning indicating that the electronic message includes malicious data; and

sending the warning to the address associated with the user, the warning configured to be output in association with the electronic message.

10 . The computer-implemented method as recited in claim 8 , further comprising:

analyzing previous interactions between the user and a portion of the previous electronic messages which were sent to the address associated with the user; and

training the model based at least in part on the previous interactions.

11 . The computer-implemented method as recited in claim 8 , further comprising:

analyzing previous interactions between the user and a portion of the previous electronic messages sent to the address associated with the user;

performing natural-language-processing (NLP) analysis on the electronic message to identify the deceptive cue included in the electronic message; and

determining, based at least in part on the previous interactions, whether the user is susceptible to falling victim to the deceptive cue in the electronic message.

12 . The computer-implemented method as recited in claim 8 , wherein:

the characteristic of the user is a particular demographic characteristic including at least one of age, gender, or location associated with the user; and

the susceptibility data indicates that the particular demographic characteristic of the user makes the user susceptible to the malicious data in the electronic message.

13 . The computer-implemented method as recited in claim 8 , wherein:

performing natural-language-processing (NLP) analysis on the electronic message to identify text representing the malicious data;

identifying, from the text, one or more words that are of personal relevance to the user; and

determining, based at least in part on the one or more words that are of personal relevance to the user, that the user is susceptible to falling victim to the malicious data.

14 . The computer-implemented method as recited in claim 8 , wherein:

the characteristic of the user is a cognitive ability of the user;

the susceptibility data indicates that the cognitive ability of the user makes the user susceptible to the malicious data in the electronic message.

15 . One or more computing devices of an email communication platform, comprising:

one or more processors; and

one or more computer-readable media storing computer-executable instructions that, when executed, cause the one or more processors to perform acts comprising:

receiving an electronic message sent to an address associated with a user;

analyzing content in a body of the electronic message to determine that the content of the body of the electronic message includes malicious data comprising a deceptive cue for a scam;

receiving characteristic data indicating a characteristic of the user;

receiving a model that is trained on characteristics and previous electronic messages, wherein the model is trained to determine likelihoods that the user is susceptible to falling victim to deceptive cues in the previous electronic messages based on the characteristics;

inputting the characteristic data into the model to determine whether the user is likely to interact with the malicious data in the electronic message and fall victim to the deceptive cue for the scam;

receiving, as output of the model, susceptibility data indicating that the user is likely to fall victim to the deceptive cue and determine that the scam is a legitimate message; and

determining, based at least in part on the susceptibility data indicating that the user is likely to determine that the scam is a legitimate message, that the user is likely to interact with the malicious data in the electronic message and fall victim to the deceptive cue for the scam.

16 . The one or more computing devices as recited in claim 15 , the acts further comprising:

in response to determining the user is susceptible to falling victim to the malicious data, generating a warning indicating that the electronic message includes malicious data; and

sending the warning to the address associated with the user, the warning configured to be output in association with the electronic message.

17 . The one or more computing devices as recited in claim 15 , the acts further comprising:

analyzing previous interactions between the user and a portion of the previous electronic messages which were sent to the address associated with the user; and

training the model based at least in part on the previous interactions.

18 . The one or more computing devices as recited in claim 15 , the acts further comprising:

analyzing previous interactions between the user and a portion of the previous electronic messages sent to the address associated with the user;

performing natural-language-processing (NLP) analysis on the electronic message to identify the deceptive cue included in the electronic message; and

determining, based at least in part on the previous interactions, whether the user is susceptible to falling victim to the deceptive cue in the electronic message.

19 . The one or more computing devices as recited in claim 15 , wherein:

the characteristic of the user is a particular demographic characteristic including at least one of age, gender, or location associated with the user; and

the susceptibility data indicates that the particular demographic characteristic of the user makes the user susceptible to the malicious data in the electronic message.

20 . The one or more computing devices as recited in claim 15 , wherein:

performing natural-language-processing (NLP) analysis on the electronic message to identify text representing the malicious data;

identifying, from the text, one or more words that are of personal relevance to the user; and

determining, based at least in part on the one or more words that are of personal relevance to the user, that the user is susceptible to falling victim to the malicious data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2023
From: SAPOUNTZIS, NIKOLAOS; MAINO, FABIO R.; KOLLI, MADHURI
To: CISCO TECHNOLGY, INC.
Reel/Frame 065707/0135 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2023
From: OLIVEIRA, DANIELA ALVIM SEABRA DE
To: UNIVERSITY OF FLORIDA RESEARCH FOUNDATION, INC.
Reel/Frame 065707/0183 →
Continuity (2)
Continuation 17208366 · Mar 22, 2021
Related Publication 20240114041A1 · Apr 4, 2024
References Cited (19)
US 9674210B1 · Oprea · 2017 [cited by examiner]
US 10970188B1 · Åvist · 2021 [cited by examiner]
US 11190470B2 · Cox · 2021 [cited by examiner]
US 11233821B2 · Yadav · 2022 [cited by examiner]
US 20160119377A1 · Goldberg · 2016 [cited by examiner]
US 20160344770A1 · Verma et al. · 2016 [cited by applicant]
US 20190028510A1 · Celik · 2019 [cited by applicant]
US 20200021620A1 · Purathepparambil et al. · 2020 [cited by applicant]
US 20200084228A1 · Goutal · 2020 [cited by applicant]
US 20200175115A1 · Pandit · 2020 [cited by examiner]
US 20200192981A1 · Fox · 2020 [cited by examiner]
US 20200234109A1 · Lee · 2020 [cited by examiner]
US 20200252803A1 · Shah · 2020 [cited by examiner]
US 20200287917A1 · Sites et al. · 2020 [cited by applicant]
US 20200372172A1 · Murray · 2020 [cited by examiner]
US 20210075824A1 · Ibrahim · 2021 [cited by examiner]
US 20220303285A1 · Sapountzis et al. · 2022 [cited by applicant]
Office Action for U.S. Appl. No. 17/208,366, mailed on Jan. 6, 2023, Sapountzis, “Susceptibility-Based Warning Techniques”, 9 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/208,366, mailed on Sep. 16, 2022, Sapountzis, “Susceptibility-Based Warning Techniques”, 7 pages. [cited by applicant]