IP Library › Granted Patent US 11,757,914
Granted Patent B1
US 11,757,914 · App. 16/361,765 · Granted Sep 12, 2023

Automated responsive message to determine a security risk of a message sender

Inventors: Bjorn Markus Jakobsson (Portola Valley, CA); Jacob Rudee Rideout (Raleigh, NC)
Assignee: AGARI DATA, INC.
H04L63/1433H04L51/212H04L51/42H04L63/1425H04L12/66H04L61/5007H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,757,914
App. No.
16/361,765
Filed
Mar 22, 2019
Granted
Sep 12, 2023
Kind
B1
Art Unit
2438
USPC
726/22
Abstract

A received message sent from a first message account to a second message account is received. A security risk associated with the received message is determined. It is determined that the security risk associated with the received message meets one or more criteria. Based on the determination that the security risk associated with the received message meets the one or more criteria, a responsive message in response to the received message is automatically generated and sent. An interaction with the responsive message is analyzed. Based on a result of the analysis of the interaction with the responsive message, a security risk associated with the first message account is classified.

Claims (39)

1. A method, comprising:

receiving a received electronic message sent from a first electronic message account to a second electronic message account;

determining a security risk associated with the received electronic message; determining that the security risk associated with the received electronic message meets one or more criteria;

based on the determination that the security risk associated with the received electronic message meets the one or more criteria, automatically generating a responsive electronic message in response to the received electronic message and sending the responsive electronic message to the first electronic message account, wherein the responsive electronic message includes a request to access a message repository of the first electronic message account;

automatically analyzing an interaction, by the first electronic message account, with the responsive electronic message; and

based on receiving access to the requested message repository and a result of the analysis of the interaction of the first electronic message account with the responsive electronic message, classifying a security risk associated with the first electronic message account.

2. The method of claim 1 , wherein generating the responsive electronic message includes automatically selecting a message template among a plurality of message templates based on an identifier associated with the first electronic message account or the second electronic message account.

3. The method of claim 1 , wherein the generating and sending of the responsive electronic message includes sending a plurality of related electronic messages.

4. The method of claim 1 , wherein the responsive electronic message is generated based at least in part on a specified workflow.

5. The method of claim 1 , wherein analyzing the interaction with the responsive electronic message includes determining a number of times a tracker associated with the responsive electronic message has been activated.

6. The method of claim 1 , wherein analyzing the interaction with the responsive electronic message includes determining a number of different IP addresses associated with accesses to content of the responsive electronic message.

7. The method of claim 1 , wherein analyzing the interaction with the responsive electronic message includes determining a number of different devices associated with accesses to content of the responsive electronic message.

8. The method of claim 1 , wherein classifying the security risk associated with the first electronic message account includes determining a security risk score associated with an identity of the first electronic message account.

9. The method of claim 1 , wherein classifying the security risk associated with the first electronic message account includes determining a security risk level range that corresponds to a metric of the result of the analysis.

10. The method of claim 1 , wherein the responsive electronic message references content included in the received electronic message sent from the first electronic message account.

11. The method of claim 1 , wherein determining that the security risk associated with the received electronic message meets the one or more criteria includes determining that a security risk score exceeds a threshold value.

12. The method of claim 1 , wherein the responsive electronic message includes a content reference identified as referring to a content for a user of the first electronic message account, wherein in response to receiving a request made using the content reference, a request to accept terms of an agreement is provided.

13. The method of claim 1 , wherein the responsive electronic message includes a URL that references a server that tracks the interaction.

14. The method of claim 1 , wherein determining the security risk associated with the received electronic message includes comparing a mail user agent of the received electronic message with a reference profile.

15. The method of claim 1 , wherein determining the security risk associated with the received electronic message includes identifying whether a domain associated with the first electronic message account enforces a Domain-based Message Authentication, Reporting, and Conformance (DMARC) policy.

16. The method of claim 1 , wherein determining the security risk associated with the received electronic message includes determining whether a display name of the first electronic message account is similar to any other trusted message accounts of the second electronic message account.

17. The method of claim 1 , wherein the determined security risk associated with the received electronic message is utilized in determining whether to modify the received electronic message prior to delivering the received electronic message to a message repository of the second electronic message account.

18. A system, comprising:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to:

receive a received electronic message sent from a first electronic message account to a second electronic message account;

determine a security risk associated with the received electronic message;

determine that the security risk associated with the received electronic message meets one or more criteria;

based on the determination that the security risk associated with the received electronic message meets the one or more criteria, automatically generate a responsive electronic message in response to the received electronic message and send the responsive electronic message to the first electronic message account, wherein the responsive electronic message includes a request to access a message repository of the first electronic message account;

automatically analyze an interaction, by the first electronic message account, with the responsive electronic message; and

based on receiving access to the requested message repository and a result of the analysis of the interaction of the first electronic message account with the responsive electronic message, classify a security risk associated with the first electronic message account.

19. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a received electronic message sent from a first electronic message account to a second electronic message account;

determining a security risk associated with the received electronic message;

determining that the security risk associated with the received electronic message meets one or more criteria;

based on the determination that the security risk associated with the received electronic message meets the one or more criteria, automatically generating a responsive electronic message in response to the received electronic message and sending the responsive electronic message to the first electronic message account, wherein the responsive electronic message includes a request to access a message repository of the first electronic message account;

automatically analyzing an interaction, by the first electronic message account, with the responsive electronic message; and

based on receiving access to the requested message repository and a result of the analysis of the interaction of the first electronic message account with the responsive electronic message, classifying a security risk associated with the first electronic message account.

20. The method of claim 1 , wherein the received electronic message and the responsive electronic message each comprise one of an electronic mail, an instant message, a text message, a Short Message Service (SMS) message, and a Multimedia Messaging Service (MMS) message.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2019
From: JAKOBSSON, BJORN MARKUS; RIDEOUT, JACOB RUDEE
To: AGARI DATA, INC.
Reel/Frame 049922/0777 →
Continuity (4)
Continuation In Part 15992752 · May 30, 2018
Provisional Application 62647528 · Mar 23, 2018
Provisional Application 62543801 · Aug 10, 2017
Provisional Application 62516535 · Jun 7, 2017
Cited By (34)
US 12,212,543 US 12,218,948 US 12,223,077 US 12,261,890 US 12,267,250 US 12,284,196 US 12,323,463 US 12,326,851 US 12,333,038 US 12,388,870 US 12,399,862 US 12,401,656 US 12,407,504 US 12,407,723 US 12,418,562 US 12,432,257 US 12,450,370 US 12,457,230 US 12,495,013 US 12,513,180 US 12,519,804 US 12,526,311 US 12,531,903 US 12,563,077 US 12,572,525 US 12,608,471 US 12,627,709 US 12,641,117 US 12,659,291 US 12,659,333 US 12,665,946 US 12,694,031 US 12,730,881 US 12,737,477