IP Library Patent Application 19376830
Patent Application
App. No. 19/376,830

INVESTIGATION OF THREATS USING QUERYABLE RECORDS OF BEHAVIOR

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/376,830
Abstract

A method for behavior-based threat investigation may include obtaining data that is related to a series of email communications performed with accounts on a channel through which an employee of an enterprise can communicate with other employees of the enterprise or accounts external to the enterprise. The method may include parsing the data to identify an attribute of each email communication. The method may include generating a series of records populating a data structure with a record of each email communication comprising the respective attribute. The method may include generating a digital profile for the employee based on the series of records. The method may include obtaining a real time email communication on the channel corresponding to an account associated with the employee. The method may include determining a deviation between the real time email communication and the normal email communications.

Claims (49)

1 . A method for behavior-based threat investigation, comprising:

obtaining data that is related to a series of email communications performed with accounts on a channel through which employees of an enterprise can communicate with other employees of the enterprise or accounts external to the enterprise;

parsing the data to identify an attribute of each email communication;

generating a series of records by populating a data structure with a record of each email communication comprising the respective attribute;

generating, for an employee of the enterprise, a digital profile based on the series of records, the digital profile comprising a historical summary of conduct on the channel that indicates normal email communications of the employee on the channel;

obtaining a real time email communication on the channel corresponding to an account associated with the employee; and

determining, based on the digital profile and the real time email communication, a deviation between the real time email communication and the normal email communications.

2 . The method of claim 1 , wherein determining the deviation between the real time email communication and the normal email communications comprises:

parsing data of the real time email communication to identify an attribute of the real time email communication; and

providing, as input, the attribute of the real time email communication to a model that is trained to determine the deviation.

3 . The method of claim 1 , wherein the series of email communications comprises a plurality of communications, wherein the attribute of a communication of the plurality of communications comprises at least one of (i) a reception date, (ii) a transmission date, (iii) a subject of the communication, (iv) an identifier of an account from which the communication originates, or (v) content of the communication.

4 . The method of claim 1 , wherein determining the deviation comprises:

generating a value that is indicative of a difference between an attribute associated with the real time email communication and an attribute associated with the normal email communications; and

assigning a threat classification to the real time email communication based on the value.

5 . The method of claim 4 , wherein in response to the value exceeding a deviation threshold, the threat classification indicates that the account associated with the employee may be compromised.

6 . The method of claim 5 , further comprising:

in response to the threat classification indicating that the account associated with the employee may be compromised, performing one or more remediation actions to the account associated with the employee.

7 . The method of claim 6 , wherein the one or more remediation actions comprises moving communications originating from the account associated with the employee into a hidden folder, preventing the account associated with the employee from accessing resources associated with the enterprise on the channel, sending notifications to a different account associated with the employee, resetting a password of the account associated with the employee, or ending an active session of the account associated with the employee.

8 . The method of claim 1 , wherein the series of email communications includes at least one of receptions of communications, transmissions of communications, creations of mail filters, or occurrences of sign-in events.

9 . The method of claim 1 , wherein each email communication of the series of email communications comprises an indicator indicating a threat classification associated with the respective email communication.

10 . The method of claim 1 , wherein records of the series of records are deleted from the digital profile upon exceeding a certain age such that the digital profile includes records of email communications occurring over a predetermined interval of time.

11 . A system, comprising:

one or more memory devices configured to store instructions thereon that, when executed by one or more processors, cause the one or more processors to:

obtain data that is related to a series of email communications performed with accounts on a channel through which an employee of an enterprise can communicate with other employees of the enterprise or accounts external to the enterprise;

parse the data to identify an attribute of each email communication;

generate a series of records by populating a data structure with a record of each email communication comprising the respective attribute;

generate a digital profile for the employee based on the series of records, the digital profile comprising a historical summary of conduct on the channel that indicates normal email communications of the employee on the channel;

obtain a first email communication on the channel corresponding to an account associated with the employee; and

determine, based on the digital profile and the first email communication, a deviation between the first email communication and the normal email communications.

12 . The system of claim 11 , wherein the instructions cause the one or more processors to determine the deviation between the first email communication and the normal email communications by:

parsing data of the first email communication to identify an attribute of the first email communication; and

providing, as input, the attribute of the first email communication to a model that is trained to determine the deviation.

13 . The system of claim 11 , wherein the series of email communications comprises a plurality of communications, wherein the attribute of a communication of the plurality of communications comprises at least one of (i) a reception date, (ii) a transmission date, (iii) a subject of the communication, (iv) an identifier of an account from which the communication originates, or (v) content of the communication.

14 . The system of claim 11 , wherein the instructions cause the one or more processors to determine the deviation by:

generating a value that is indicative of a difference between an attribute associated with the first email communication and an attribute associated with the normal email communications; and

assigning a threat classification to the first email communication based on the value.

15 . The system of claim 14 , wherein in response to the value exceeding a deviation threshold, the threat classification indicates that the account associated with the employee may be compromised.

16 . The system of claim 15 , wherein the instructions cause the one or more processors to:

in response to the threat classification indicating that the account associated with the employee may be compromised, perform one or more remediation actions to the account associated with the employee.

17 . The system of claim 16 , wherein the one or more remediation actions comprises moving communications originating from the account associated with the employee into a hidden folder, preventing the account associated with the employee from accessing resources associated with the enterprise, sending a notification to a different account associated with the employee, resetting a password of the account associated with the employee, or ending an active session of the account associated with the employee.

18 . The system of claim 11 , wherein the series of email communications includes at least one of receptions of communications, transmissions of communications, creations of mail filters, or occurrences of sign-in events.

19 . The system of claim 11 , wherein each email communication of the series of email communications comprises an indicator indicating a threat classification associated with the respective email communication.

20 . One or more non-transitory computer readable media storing instructions thereon that, when executed by one or more processors, causes the one or more processors to:

obtain data that is related to a series of email communications performed with accounts on a channel through which a user associated with an enterprise can communicate with other users associated with the enterprise or accounts external to the enterprise;

parse the data to identify an attribute of each email communication;

generate a series of records by populating a data structure with a record of each email communication comprising the respective attribute;

generate a digital profile for the user based on the series of records, the digital profile comprising a historical summary of conduct on the channel that indicates normal email communications of the user on the channel;

obtain a first email communication on the channel corresponding to an account associated with the user; and

determine, based on the digital profile and the first email communication, a deviation between the first email communication and the normal email communications.