IP Library Granted Patent US 12,388,870
Granted Patent B2
US 12,388,870 · App. 18/885,207 · Granted Aug 12, 2025

Systems and methods for intelligent identification and automated disposal of non-malicious electronic communications

Inventors: Elisabeth Weber (Herndon, VA); Jane Hung (Raleigh, NC)
Assignee: Expel, Inc.
H04L63/1483G06N20/00H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,870
App. No.
18/885,207
Granted
Aug 12, 2025
Kind
B2
Abstract

A system and method for accelerating a disposition of non-malicious electronic communications includes extracting one or more corpora of feature vectors from an electronic communication based on providing the electronic communication as input to a feature extractor; computing, by a machine learning-based electronic communication classification model, an electronic communication-type classification inference that includes a probability of the electronic communication being of the target non-malicious electronic communication type in response to the machine learning-based electronic communication classification model receiving the one or more corpora of feature vectors; attributing a classification label of the target non-malicious electronic communication type to the electronic communication based on the probability of the electronic communication-type classification inference satisfying a minimum electronic communication classification threshold; and automatically routing a security alert associated with the electronic communication to an alert disposal queue based on the electronic communication having the classification label of the target non-malicious electronic communication type.

Claims (61)

1. A method comprising:

extracting one or more corpora of feature vectors from electronic communication data associated with an electronic communication, wherein extracting the one or more corpora of feature vectors includes:

(i) extracting a first corpus of feature vectors comprising feature data indicative of whether the electronic communication is of a target type, wherein:

the target type refers to a class of electronic communications that promotes one or more products, one or more services, or one or more events, and

(ii) extracting a second corpus of feature vectors comprising feature data indicative of whether the electronic communication is a malicious electronic communication;

computing, by an electronic communication classification model, a classification inference that includes a probability of the electronic communication being of the target type based on the electronic communication classification model receiving the first corpus of feature vectors and the second corpus of feature vectors; and

automatically closing a security alert associated with the electronic communication based on the probability satisfying a predetermined minimum classification threshold.

2. The method according to claim 1 , wherein:

the class of electronic communications are non-malicious.

3. The method according to claim 1 , further comprising:

automatically attributing a classification label of the target type to the electronic communication based on the probability of the classification inference satisfying the predetermined minimum classification threshold.

4. The method according to claim 1 , further comprising:

automatically routing the security alert to an alert disposition queue based on the probability satisfying the predetermined minimum classification threshold.

5. A computer-implemented method comprising:

extracting one or more corpora of feature vectors from third-party electronic communication data associated with a third-party electronic communication, wherein extracting the one or more corpora of feature vectors includes:

(i) extracting a first corpus of feature vectors indicative of whether the third-party electronic communication is of a target non-malicious electronic communication type, wherein:

the target non-malicious electronic communication type refers to a class of electronic communications that promotes one or more products, one or more services, or one or more events, and

(ii) extracting a second corpus of feature vectors indicative of whether the third-party electronic communication is a suspected malicious electronic communication;

computing, by a machine learning-based electronic communication classification model, an electronic communication-type classification inference that includes a probability of the third-party electronic communication being of the target non-malicious electronic communication type based on the first corpus of feature vectors and the second corpus of feature vectors; and

automatically closing a security alert associated with the third-party electronic communication based on the probability satisfying a predetermined minimum classification threshold.

6. The computer-implemented method according to claim 5 , further comprising:

in response to automatically closing the security alert associated with the third-party electronic communication:

bypassing a cybersecurity investigation into the security alert, wherein the cybersecurity investigation includes executing one or more cybersecurity investigation workflows.

7. The computer-implemented method according to claim 5 , further comprising:

obtaining, from a subscriber, a request to assess a threat of the third-party electronic communication, wherein the security alert is automatically generated in response to obtaining the request from the subscriber.

8. The computer-implemented method according to claim 7 , wherein:

the security alert is routed to a security alert queue after generating the security alert, and

the security alert queue includes a plurality of security alerts, wherein each security alert of the plurality of security alerts is awaiting an alert triage.

9. The computer-implemented method according to claim 8 , further comprising:

automatically removing the security alert associated with the third-party electronic communication from the security alert queue in response to automatically closing the security alert.

10. The computer-implemented method according to claim 5 , further comprising:

obtaining a corpus of training data that includes a plurality of electronic communication training data samples, wherein the corpus of training data includes:

(a) a first set of labeled electronic communications, wherein each electronic communication of the first set of labeled electronic communications is labeled as being of the target non-malicious electronic communication type,

(b) a second set of labeled electronic communications, wherein each electronic communication of the second set of labeled electronic communications is labeled as not being of the target non-malicious electronic communication type, and

(c) a third set of unlabeled electronic communications, wherein the corpus of training data includes more unlabeled electronic communications than labeled electronic communications; and

configuring the machine learning-based electronic communication classification model based on a semi-supervised training of a machine learning classification model using the corpus of training data.

11. The computer-implemented method according to claim 5 , further comprising:

displaying, via a web-accessible user interface, a representation of the security alert that includes:

(a) a representation of the third-party electronic communication, and

(b) the probability of the third-party electronic communication being of the target non-malicious electronic communication type.

12. The computer-implemented method according to claim 5 , wherein:

one feature of the second corpus of feature vectors indicates whether a return path of the third-party electronic communication matches a sender address of the third-party electronic communication, and

the machine learning-based electronic communication classification model uses the one feature of the second corpus of feature vectors to assist with computing the probability of the third-party electronic communication being of the target non-malicious electronic communication type.

13. The computer-implemented method according to claim 5 , wherein:

one feature of the second corpus of feature vectors indicates whether a sender domain of the third-party electronic communication was involved in a previous security incident, and

the machine learning-based electronic communication classification model uses the one feature of the second corpus of feature vectors to assist with computing the probability of the third-party electronic communication being of the target non-malicious electronic communication type.

14. The computer-implemented method according to claim 5 , wherein:

one feature of the first corpus of feature vectors indicates whether a sender of the third-party electronic communication corresponds to a corporate marketing account of an organization, and

the machine learning-based electronic communication classification model uses the one feature of the first corpus of feature vectors to assist with computing the probability of the third-party electronic communication being of the target non-malicious electronic communication type.

15. The computer-implemented method according to claim 5 , wherein:

one feature of the first corpus of feature vectors indicates a combined number of terms and phrases included in a body of the third-party electronic communication that is indicative of the target non-malicious electronic communication type, and

the machine learning-based electronic communication classification model uses the one feature of the first corpus of feature vectors to assist with computing the probability of the third-party electronic communication being of the target non-malicious electronic communication type.

16. The computer-implemented method according to claim 5 , wherein:

one feature of the first corpus of feature vectors indicates a chromatic intensity of the third-party electronic communication, and

the machine learning-based electronic communication classification model uses the one feature of the first corpus of feature vectors to assist with computing the probability of the third-party electronic communication being of the target non-malicious electronic communication type.

17. The computer-implemented method according to claim 5 , wherein:

one feature of the second corpus of feature vectors indicates a domain age of a sender domain used in the third-party electronic communication, and

the machine learning-based electronic communication classification model uses the one feature of the second corpus of feature vectors to assist with computing the probability of the third-party electronic communication being of the target non-malicious electronic communication type.

18. The computer-implemented method according to claim 5 , wherein:

one feature of the first corpus of feature vectors indicates whether digital images are embedded in the third-party electronic communication, and

the machine learning-based electronic communication classification model uses the one feature of the first corpus of feature vectors to assist with computing the probability of the third-party electronic communication being of the target non-malicious electronic communication type.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 5, 2026
From: EXPEL, INC.
To: HERCULES CAPITAL, INC.
Reel/Frame 075041/0970 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2024
From: WEBER, ELISABETH; HUNG, JANE
To: EXPEL, INC.
Reel/Frame 068593/0001 →
Continuity (10)
Continuation 18607463 · Mar 16, 2024
Continuation In Part 17970069 · Oct 20, 2022
Continuation 17696151 · Mar 16, 2022
Continuation 17501708 · Oct 14, 2021
Provisional Application 63463195 · May 1, 2023
Provisional Application 63454078 · Mar 23, 2023
Provisional Application 63129836 · Dec 23, 2020
Provisional Application 63092307 · Oct 15, 2020
Provisional Application 63091409 · Oct 14, 2020
Related Publication 20250088534A1 · Mar 13, 2025
References Cited (49)
US 9154516B1 · Vaystikh · 2015 [cited by examiner]
US 9245115B1 · Jakobsson · 2016 [cited by examiner]
US 9774626B1 · Himler · 2017 [cited by examiner]
US 10027701B1 · Himler · 2018 [cited by examiner]
US 10277628B1 · Jakobsson · 2019 [cited by examiner]
US 10397272B1 · Bruss · 2019 [cited by examiner]
US 10601865B1 · Mesdaq et al. · 2020 [cited by applicant]
US 10880322B1 · Jakobsson · 2020 [cited by examiner]
US 11595437B1 · Mushtag · 2023 [cited by applicant]
US 11757914B1 · Jakobsson · 2023 [cited by examiner]
US 20040128355A1 · Chao · 2004 [cited by examiner]
US 20060168041A1 · Mishra · 2006 [cited by examiner]
US 20070027992A1 · Judge · 2007 [cited by examiner]
US 20070078936A1 · Quinlan · 2007 [cited by examiner]
US 20070079379A1 · Sprosts · 2007 [cited by examiner]
US 20100145900A1 · Zheng et al. · 2010 [cited by applicant]
US 20100162396A1 · Liu et al. · 2010 [cited by applicant]
US 20100205123A1 · Sculley · 2010 [cited by examiner]
US 20130246017A1 · Heckerman et al. · 2013 [cited by applicant]
US 20130247192A1 · Krasser et al. · 2013 [cited by applicant]
US 20150067833A1 · Verma · 2015 [cited by examiner]
US 20160014151A1 · Prakash · 2016 [cited by examiner]
US 20160142429A1 · Reneria · 2016 [cited by applicant]
US 20170359362A1 · Kashi et al. · 2017 [cited by applicant]
US 20180082062A1 · Hager et al. · 2018 [cited by applicant]
US 20180278627A1 · Goutal · 2018 [cited by applicant]
US 20180295153A1 · Eisen · 2018 [cited by applicant]
US 20180324201A1 · Lowry · 2018 [cited by examiner]
US 20180375877A1 · Jakobsson · 2018 [cited by examiner]
US 20190052655A1 · Enishti · 2019 [cited by applicant]
US 20190222608A1 · Naccarato et al. · 2019 [cited by applicant]
US 20200084228A1 · Goutal · 2020 [cited by examiner]
US 20200234109A1 · Lee · 2020 [cited by examiner]
US 20200267181A1 · Pandey et al. · 2020 [cited by applicant]
US 20200358819A1 · Bowditch et al. · 2020 [cited by applicant]
US 20200366712A1 · Onut · 2020 [cited by examiner]
US 20210168161A1 · Dunn et al. · 2021 [cited by applicant]
US 20210266345A1 · Chen et al. · 2021 [cited by applicant]
US 20210273950A1 · Lawson · 2021 [cited by examiner]
US 20210281606A1 · Singh et al. · 2021 [cited by applicant]
US 20210352093A1 · Hassanzadeh et al. · 2021 [cited by applicant]
US 20210360006A1 · Kim et al. · 2021 [cited by applicant]
US 20220166784A1 · Patton · 2022 [cited by examiner]
US 20220210188A1 · Grewal et al. · 2022 [cited by applicant]
US 20220294751A1 · Slobodyanuk et al. · 2022 [cited by applicant]
US 20230164180A1 · Singh et al. · 2023 [cited by applicant]
US 20230171287A1 · Slobodyanuk et al. · 2023 [cited by applicant]
US 20230224326A1 · Horesh et al. · 2023 [cited by applicant]
US 20230328034A1 · Behera et al. · 2023 [cited by applicant]
Cited By (1)
US 12,647,434