IP Library Patent Application 18533517
Patent Application
App. No. 18/533,517

BLOCKLIST GENERATION SYSTEM BASED ON REPORTED THREATS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/533,517
Abstract

Described herein are systems and methods to provide for blocklist recommendations based on reported threats. In an example embodiment, a method is described for receiving a selection of one or more messages from a plurality of messages identified as threats and identifying, based at least on the one or more messages, one or more candidate blocklist entries (BLEs). The method further includes determining, based at least on the one or more candidate BLEs, a recommendation of one or more BLEs to add to a blocklist. The method includes adding, by the one or more servers, the one or more BLEs to the blocklist, where the blocklist is used by an email system to block messages that match at least the one or more BLEs on the blocklist.

Claims (33)

1 . A method comprising:

receiving, by one or more severs, a selection of one or more messages from a plurality of messages identified as threats;

identifying, by the one or more servers based at least on the one or more messages, one or more candidate blocklist entries (BLEs);

determining, by the one or more servers based at least on the more or more candidate BLEs, a recommendation of one or more BLEs to add to a blocklist; and

adding, by the one or more servers, the one or more BLEs to the blocklist, wherein the blocklist is used by an email system to block messages that match at least the one or more BLEs on the blocklist.

2 . The method of claim 1 , further comprising receiving, by the one or more servers, the plurality of messages from a threat detection system.

3 . The method of claim 2 , further comprising adding, by the threat detection system, a label to the one or more messages to identify potential threats in the one or more messages.

4 . The method of claim 1 , further comprising receiving, by the one or more servers, the selection of the one or more messages from an administrator via a user interface.

5 . The method of claim 1 , further comprising determining, by the one or more servers, the recommendation of the one or more BLEs to add to the blocklist according to a BLE characteristic type of a plurality of BLE characteristic types.

6 . The method of claim 1 , further comprising providing, by the one or more servers, a user interface to an administrator to select a confidence level for which to block messages similar to the plurality of messages identified as threats.

7 . The method of claim 6 , further comprising determining, by the one or more servers, the recommendation of the one or more BLEs based at least on the selected confidence level.

8 . The method of claim 1 , further comprising determining, by the one or more servers, a recommendation of a Time-To-Live (TTL) for each of the one or more BLEs.

9 . The method of claim 1 , wherein the blocklist is a private blocklist.

10 . The method of claim 1 , further comprising receiving, by the one or more processors, a global blocklist of one or more BLEs identified by a security services provider that aggregates private blocklists of multiple organizations.

11 . The method of claim 1 , further comprising providing, by the one or more processors, a priority indicator to each of the one or more BLEs, the priority indicator indicating an order for which each of the one or more BLEs are to be added to the blocklist used by the email system.

12 . The method of claim 1 , further comprising determining, by the one or more processors, an efficacy level for each of the one or more BLEs based at least on how often each of the one or more BLEs results in a message being blocked.

13 . A system comprising:

one or more severs configured to:

receive a selection of one or more messages from a plurality of messages identified as threats;

identify, based at least on the one or more messages, one or more candidate blocklist entries (BLEs);

determine, based at least on the more or more candidate BLEs, a recommendation of one or more BLEs to add to a blocklist; and

add, the one or more BLEs to the blocklist, wherein the blocklist is used by an email system to block messages that match at least the one or more BLEs on the blocklist.

14 . The system of claim 13 , wherein the one or more servers are further configured to receive the plurality of messages from a threat detection system.

15 . The system of claim 13 , wherein the one or more servers are further configured to add a label to the one or more messages to identify potential threats in the one or more messages.

16 . The system of claim 13 , wherein the one or more servers are further configured to receive the selection of the one or more messages from an administrator via a user interface.

17 . The system of claim 13 , wherein the one or more servers are further configured to, the recommendation of the one or more BLEs to add to the blocklist according to a BLE characteristic type of a plurality of BLE characteristic types.

18 . The system of claim 13 , wherein the one or more servers are further configured to provide a user interface to an administrator to select a confidence level for which to block messages similar to the plurality of messages identified as threats.

19 . The system of claim 18 , wherein the one or more servers are further configured to determine the recommendation of the one or more BLEs based at least on the selected confidence level.

20 . The system of claim 13 , wherein the one or more servers are further configured to determine a recommendation of a Time-To-Live (TTL) for each of the one or more BLEs.

21 . The system of claim 13 , wherein the blocklist is a private blocklist.

22 . The system of claim 13 , wherein the one or more servers are further configured to receive a global blocklist of one or more BLEs identified by a security services provider that aggregates private blocklists of multiple organizations.

23 . The system of claim 13 , wherein the one or more processors are further configured to provide, a priority indicator to each of the one or more BLEs, wherein the priority indicator indicates an order for which each of the one or more BLEs are to be added to the blocklist used by the email system.

24 . The system of claim 13 , wherein the one or more processors are further configured to determine an efficacy level for each of the one or more BLEs based at least on how often each of the one or more BLEs results in a message being blocked.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2023
From: BODKE, ANAND DINKAR; HOWES, ERIC; PATTON, MARK WILLIAM; KRAS, GREG; CLINE, CHRISTOPHER; SMITH, BRANDON SCOTT; PERRY, STEFFAN
To: KNOWBE4, INC.
Reel/Frame 065884/0571 →