IP Library Granted Patent US 10,419,475
Granted Patent B2
US 10,419,475 · App. 15/720,009 · Granted Sep 17, 2019

System and method for social engineering identification and alerting

Inventors: Damien Phelan Stolarz (Los Angeles, CA); Johanna Dwyer (Brookline, MA); Ronald J. Pollack (Clearwater, FL)
Assignee: Telepathy Labs, Inc.
H04L63/1441G06N3/0445G06N3/084G06N5/02G06N5/043G06N20/00G10L15/26G10L15/265H04L63/10H04L63/1408H04L63/1416H04L63/1425H04L63/1483H04L67/306H04W12/08H04W12/12H04W4/21H04W12/00505
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,419,475
App. No.
15/720,009
Granted
Sep 17, 2019
Kind
B2
Abstract

A method, computer program product, and computer system for identifying potential social engineering activity associated with one or more communications on a first communication channel of a plurality of communication channels. Restriction of at least partial access to at least a second communication channel of the plurality of communication channels may be requested based upon, at least in part, the identification of the potential social engineering activity associated with the one or more communications on the first communication channel.

Claims (29)

1. A computer-implemented method for defense against social engineering attack comprising:

identifying, by a computing device, potential social engineering activity associated with one or more communications on a first communication channel of a plurality of communication channels, wherein the potential social engineering activity is directed towards a user target on the first communication channel, wherein the user target is a first user, wherein the first communication channel includes a first type of communication;

requesting a restriction of at least partial access to at least a second communication channel of the plurality of communication channels based upon, at least in part, the identification of the potential social engineering activity associated with the one or more communications on the first communication channel, wherein the second communication channel includes a second type of communication;

restricting at least the partial access of the user target to at least the second type of communication on the second communication channel of the plurality of communication channels based upon, at least in part, requesting the restriction; and

performing an action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the action includes implementing a quarantine action, wherein implementing the quarantine action includes changing permissions associated with one of a file and an application.

2. The computer-implemented method of claim 1 wherein identifying the potential social engineering activity occurs in real-time.

3. The computer-implemented method of claim 1 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the second action includes automatically connecting a second user to at least partially participate in the one or more communications on the first communication channel.

4. The computer-implemented method of claim 1 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the second action includes providing one or more characteristics of the one or more communications used to identify the potential social engineering activity.

5. The computer-implemented method of claim 1 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the second action includes providing aggregated information about at least one user participating with the one or more communications on the first communication channel.

6. The computer-implemented method of claim 1 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the second action includes verifying social engineering activity associated with the potential social engineering activity.

7. A computer program product residing on a non-transitory computer readable storage medium having a plurality of instructions stored thereon which, when executed across one or more processors, causes at least a portion of the one or more processors to perform operations comprising:

identifying potential social engineering activity associated with one or more communications on a first communication channel of a plurality of communication channels, wherein the potential social engineering activity is directed towards a user target on the first communication channel, wherein the user target is a first user, wherein the first communication channel includes a first type of communication;

requesting a restriction of at least partial access to at least a second communication channel of the plurality of communication channels based upon, at least in part, the identification of the potential social engineering activity associated with the one or more communications on the first communication channel, wherein the second communication channel includes a second type of communication;

restricting at least the partial access of the user target to at least the second type of communication on the second communication channel of the plurality of communication channels based upon, at least in part, requesting the restriction; and

performing an action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the action includes implementing a quarantine action, wherein implementing the quarantine action includes changing permissions associated with one of a file and an application.

8. The computer program product of claim 7 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the second action includes automatically connecting a second user to at least partially participate in the one or more communications on the first communication channel.

9. The computer program product of claim 7 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the action second includes providing one or more characteristics of the one or more communications used to identify the potential social engineering activity.

10. The computer program product of claim 7 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the second action includes providing aggregated information about at least one user participating with the one or more communications on the first communication channel.

11. The computer program product of claim 7 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the second action includes verifying social engineering activity associated with the potential social engineering activity.

12. A computing system including one or more processors and one or more memories configured to perform operations comprising:

identifying potential social engineering activity associated with one or more communications on a first communication channel of a plurality of communication channels, wherein the potential social engineering activity is directed towards a user target on the first communication channel, wherein the user target is a first user, wherein the first communication channel includes a first type of communication;

requesting a restriction of at least partial access to at least a second communication channel of the plurality of communication channels based upon, at least in part, the identification of the potential social engineering activity associated with the one or more communications on the first communication channel, wherein the second communication channel includes a second type of communication;

restricting at least the partial access of the user target to at least the second type of communication on the second communication channel of the plurality of communication channels based upon, at least in part, requesting the restriction; and

performing an action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the action includes implementing a quarantine action, wherein implementing the quarantine action includes changing permissions associated with one of a file and an application.

13. The computing system of claim 12 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the second action includes automatically connecting a second user to at least partially participate in the one or more communications on the first communication channel.

14. The computing system of claim 12 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the second action includes providing one or more characteristics of the one or more communications used to identify the potential social engineering activity.

15. The computing system of claim 12 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the second action includes providing aggregated information about at least one user participating with the one or more communications on the first communication channel.

16. The computing system of claim 12 further comprising performing a second action based upon, at least in part, identifying the potential social engineering activity associated with the one or more communications on the first communication channel, wherein performing the second action includes verifying social engineering activity associated with the potential social engineering activity.

17. The computing system of claim 12 further comprising a virtual agent for at least one of monitoring and controlling the operations.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2022
From: TELEPATHY IP HOLDINGS
To: TELEPATHY LABS, INC.
Reel/Frame 062026/0304 →
RELEASE OF SECURITY INTEREST Recorded Mar 31, 2020
From: CIRCINUS-UAE, LLC
To: TELEPATHY LABS, INC.
Reel/Frame 052278/0217 →
SECURITY INTEREST Recorded Feb 19, 2019
From: TELEPATHY LABS, INC.
To: CIRCINUS-UAE, LLC
Reel/Frame 048372/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2018
From: TELEPATHY LABS, INC.
To: TELEPATHY IP HOLDINGS
Reel/Frame 046252/0022 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2017
From: STOLARZ, DAMIEN PHELAN; DWYER, JOHANNA; POLLACK, RONALD J.
To: TELEPATHY LABS, INC.
Reel/Frame 043739/0352 →
Continuity (6)
Provisional Application 62403691 · Oct 3, 2016
Provisional Application 62403687 · Oct 3, 2016
Provisional Application 62403693 · Oct 3, 2016
Provisional Application 62403688 · Oct 3, 2016
Provisional Application 62403696 · Oct 3, 2016
Related Publication 20180097837A1 · Apr 5, 2018