IP Library Patent Application 19173269
Patent Application
App. No. 19/173,269

Dynamic Message Analysis Platform for Enhanced Enterprise Security

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/173,269
Abstract

Aspects of the disclosure relate to dynamic message analysis using machine learning. A computing platform may apply a security scoring process to an endpoint relationship to compute a weighted security score for the endpoint relationship. Subsequently, the computing platform may determine a weighted grade for the endpoint relationship based on the weighted security score for the endpoint relationship. Based on identifying that the weighted grade exceeds a predetermined threshold, the computing platform may tag the endpoint relationship as compromised. Subsequently, the computing platform may monitor an electronic messaging server to detect messages corresponding to the compromised endpoint relationship. Based on detecting that the electronic messaging server has received a first message, corresponding to an endpoint of the compromised endpoint relationship, the computing platform may rewrite a URL included in the first message to point to a security service that is configured to open the URL in an isolation environment.

Claims (72)

1 . A computing platform, comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

determine a weighted grade for an endpoint relationship;

identify that the weighted grade exceeds a predetermined threshold;

based on identifying that the weighted grade exceeds the predetermined threshold, tag the endpoint relationship as compromised;

determine that a first message involves an endpoint of the endpoint relationship that was tagged as compromised; and

rewrite a uniform resource located (URL) included in the first message to point to a security service that is configured to open the URL in an isolation environment.

2 . The computing platform of claim 1 , wherein determining the weighted grade for the endpoint relationship is based on a security scoring process and wherein the security scoring process includes, for each endpoint in the endpoint relationship:

determining that a first domain and a second domain are related;

determining a security score for the first domain and a security score for the second domain; and

determining a security score of a first endpoint of the endpoint relationship based on a combination of the first domain security score and the second domain security score.

3 . The computing platform of claim 1 , wherein the security service is hosted by one of: the computing platform or the isolation environment.

4 . The computing platform of claim 1 , wherein rewriting the URL to point to the security service that is configured to open the URL in the isolation environment causes the isolation environment to:

request content corresponding to the URL;

receive the content corresponding to the URL;

apply one or more security checks to the content corresponding to the URL;

render the content corresponding to the URL; and

send, based on the rendered content and to a user device, a graphical output.

5 . The computing platform of claim 4 , wherein sending the graphical output to the user device enables the user device to interact with the rendered content in the isolation environment.

6 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

detect that signals within a second message do not match signals within the first message; and

in response to detecting that the signals within the second message do not match the signals within the first message, trigger the second message to be displayed along with a warning label.

7 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

identify a parent organization corresponding to the endpoint relationship that was tagged as compromised;

identify additional endpoints associated with the parent organization;

determine that a second message involves one of the additional endpoints associated with the parent organization, the second message comprising a second URL; and

rewrite the second URL to point to the security service that is configured to open the URL in the isolation environment.

8 . The computing platform of claim 1 , wherein the first message is addressed to a first enterprise organization.

9 . The computing platform of claim 8 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

detect additional messages corresponding to the endpoint relationship that was tagged as compromised, wherein the additional messages are addressed to users at other enterprise organizations, different than the first enterprise organization;

identify a subset of the additional messages that include URLs; and

rewrite the URLs to point to the security service that is configured to open the URLs in the isolation environment.

10 . The computing platform of claim 9 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

identify a remainder of the additional messages that do not include URLs; and

cause the remainder of the additional messages to be displayed with a warning label.

11 . The computing platform of claim 10 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

generate a supply chain monitoring interface, wherein the supply chain monitoring interface includes message security information, and wherein the supply chain monitoring interface includes one or more selectable elements that, once selected, cause display of information related to malicious messages associated with the endpoint relationship that are sent to an individual enterprise organization and information related to malicious messages associated with the endpoint relationship that are sent to a plurality of enterprise organizations monitored by the computing platform.

12 . The computing platform of claim 1 , wherein tagging the endpoint relationship as compromised includes one of more of:

pushing an alert to one or more user devices indicating that the endpoint relationship that was tagged as compromised is compromised, or

configuring the alert for retrieval by the one or more user devices via application protocol interfaces (API).

13 . A method comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

determining, by the at least one processor, a weighted grade for an endpoint relationship;

identifying, by the at least one processor, that the weighted grade exceeds a predetermined threshold;

based on identifying that the weighted grade exceeds the predetermined threshold, tagging, by the at least one processor, the endpoint relationship as compromised;

determining that a first message involves an endpoint of the endpoint relationship that was tagged as compromised; and

rewriting, by the at least one processor, a uniform resource locator (URL) included in the first message to point to a security service that is configured to open the URL in an isolation environment.

14 . The method of claim 13 , wherein determining the weighted grade for the endpoint relationship is based on a security scoring process.

15 . The method of claim 13 , wherein the security service is hosted by one of: the computing platform or the isolation environment.

16 . The method of claim 13 , wherein rewriting the URL to point to the security service that is configured to open the URL in the isolation environment causes the isolation environment to:

request content corresponding to the URL;

receive the content corresponding to the URL;

apply one or more security checks to the content corresponding to the URL;

render the content corresponding to the URL; and

send, based on the rendered content and to a user device, a graphical output.

17 . The method of claim 16 , wherein sending the graphical output to the user device enables the user device to interact with the rendered content in the isolation environment.

18 . The method of claim 13 , comprising:

detecting, by the at least one processor, that signals within a second message do not match signals within the first message; and

in response to detecting that the signals within the second message do not match the signals within the first message, triggering, by the at least one processor, the second message to be displayed along with a warning label.

19 . The method of claim 13 , comprising:

identifying, by the at least one processor, a parent organization corresponding to the endpoint relationship that was tagged as compromised;

identifying, by the at least one processor, additional endpoints associated with the parent organization;

determine that a second message involves one of the additional endpoints associated with the parent organization, the second message comprising a second URL; and

rewriting, by the at least one processor, the second URL to point to the security service that is configured to open the URL in the isolation environment.

20 . One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

determine a weighted grade for an endpoint relationship;

identify that the weighted grade exceeds a predetermined threshold;

based on identifying that the weighted grade exceeds the predetermined threshold, tag the endpoint relationship as compromised;

determine that a first message involves an endpoint of the endpoint relationship that was tagged as compromised; and

rewrite a uniform resource locator (URL) included in the first message to point to a security service that is configured to open the URL in an isolation environment.

Assignments (3)
INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Dec 9, 2025
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 073910/0027 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2025
From: ADAMS, JOSEPH TRENT; HOLMES, ROBERT; BERGER, ABIGAIL LAUREN
To: PROOFPOINT, INC.
Reel/Frame 070772/0617 →