IP Library › Granted Patent US 12,309,200
Granted Patent B2
US 12,309,200 · App. 18/177,434 · Granted May 20, 2025

Detecting phishing attacks

Inventors: Andrew J. Thomas (Oxfordshire, GB); Karl Ackerman (Topsfield, MA); James Douglas Bean (Portland, OR); Kenneth D. Ray (Seattle, WA); Daniel Stutz (Karlsruhe, DE)
Assignee: Sophos Limited
H04L63/1483G06F11/00G06F21/40G06F21/43G06F21/44G06F21/45G06F21/554G06F21/566G06F21/57G06F21/64H04L9/3213H04L41/0631H04L41/142H04L43/10H04L51/212H04L63/02H04L63/0209H04L63/0227H04L63/0236H04L63/0254H04L63/0428H04L63/08H04L63/0807H04L63/10H04L63/14H04L63/1408H04L63/1416H04L63/1425H04L63/1441H04L63/1466H04L63/1491H04L63/164H04L63/20H04L67/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,200
App. No.
18/177,434
Filed
Mar 2, 2023
Granted
May 20, 2025
Kind
B2
Art Unit
2436
USPC
726/4
Abstract

Disclosed herein is a technique for detecting potential phishing attacks by monitoring outbound web traffic from an endpoint, along with inbound electronic mail traffic addressed to a user of the endpoint. With this information, a search can be performed for possible sources in the web traffic of a request for a hyperlink located in the inbound mail traffic, and when no source is located, phishing remediation can be performed, including restrictions on access to the hyperlink at an endpoint operated by the user.

Claims (39)

1. A computer program product for preventing phishing attacks, the computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, causes the one or more computing devices to perform:

monitoring, with a local security agent executing on an endpoint, outbound web traffic originating from a web browser executing on the endpoint, wherein:

the endpoint is coupled in a communicating relationship with a threat management facility,

the endpoint is associated with an enterprise network managed by the threat management facility,

the endpoint further associated with a user of the enterprise network, and

the local security agent is configured to communicate information about the outbound web traffic to the threat management facility;

monitoring, with the threat management facility, inbound electronic mail traffic addressed to the user of the endpoint;

in response to a hyperlink to an external resource detected in an electronic mail in the inbound electronic mail traffic addressed to the user, performing a search of the outbound web traffic originating from the web browser before receipt of the electronic mail for one or more possible sources of a request for the electronic mail by the user; and

in response to the search failing to identify the one or more possible sources of the request for the electronic mail by the user in the outbound web traffic from the web browser, restricting, with the local security agent, access from the endpoint, via the hyperlink in the electronic mail, to the external resource.

2. The computer program product of claim 1 , further comprising code that causes the one or more computing devices to perform, in response to the search identifying the one or more possible sources of the request for the electronic mail by the user in the outbound web traffic, allowing access to the external resource from the endpoint via the hyperlink in the electronic mail.

3. The computer program product of claim 1 , wherein the outbound web traffic includes a user registration process associated with the electronic mail.

4. A method for preventing phishing attacks comprising:

monitoring outbound web traffic originating from a web browser executing on an endpoint;

monitoring inbound electronic mail traffic addressed to a user associated with the endpoint;

in response to a hyperlink to an external resource detected in an electronic mail in the inbound electronic mail traffic addressed to the user, performing a search of the outbound web traffic originating from the web browser before receipt of the electronic mail for one or more possible sources of a request for the electronic mail by the user; and

in response to the search failing to identify the one or more possible sources of the request for the electronic mail by the user in the outbound web traffic from the web browser, restricting access from the endpoint, via the hyperlink in the electronic mail, to the external resource.

5. The method of claim 4 , wherein monitoring outbound web traffic includes monitoring outbound web traffic with at least one of a local security agent executing on the endpoint and a threat management facility for an enterprise network.

6. The method of claim 4 , wherein monitoring inbound electronic mail traffic includes monitoring inbound electronic mail traffic with at least one of a local security agent executing on the endpoint and a threat management facility for an enterprise network.

7. The method of claim 4 , wherein restricting access to the external resource from the endpoint includes permitting access to the external resource according to a security policy of an enterprise network if the external resource has a known, good reputation.

8. The method of claim 4 , wherein performing the search includes searching an historical log of outbound web traffic stored at a threat management facility for an enterprise network, and wherein performing the search includes searching for a correspondence between a URL of the hyperlink and a second URL of a remote web site in the outbound web traffic.

9. The method of claim 4 , wherein the monitoring inbound electronic mail traffic includes analyzing a displayed message within the inbound electronic mail traffic for text indicating that the electronic mail is responsive to a user registration process.

10. The method of claim 4 , wherein restricting access includes preventing submission of credentials for the user to the external resource.

11. The method of claim 4 , wherein the monitoring inbound electronic mail traffic includes monitoring activity by a local electronic mail client executing on the endpoint.

12. The method of claim 4 , wherein the monitoring inbound electronic mail traffic includes monitoring activity within a web mail client displayed within the web browser executing on the endpoint.

13. The method of claim 4 , wherein restricting access includes notifying the user of an unsolicited electronic mail and requesting an explicit authorization from the user before permitting use of the hyperlink to access the external resource.

14. The method of claim 4 , wherein monitoring outbound web traffic includes restricting the outbound web traffic according to a security policy for an enterprise network.

15. The method of claim 4 , wherein the monitoring inbound electronic mail traffic includes restricting the inbound electronic mail traffic according to a security policy for an enterprise network.

16. The method of claim 4 , wherein at least one of monitoring inbound electronic mail traffic and the monitoring outbound web traffic includes remotely monitoring network communications at a firewall coupled between the endpoint and a gateway for an enterprise network.

17. A device configured to prevent phishing attacks, the device comprising:

a memory; and

a processor configured by computer executable code stored in the memory to perform:

monitoring outbound web traffic originating from a web browser executing on an endpoint, the endpoint associated with an enterprise network, and the endpoint further associated with a user of the enterprise network,

monitoring inbound electronic mail traffic addressed to the user of the endpoint,

in response to a hyperlink to an external resource detected in an electronic mail in the inbound electronic mail traffic addressed to the user,

performing a search of the outbound web traffic originating from the web browser before receipt of the electronic mail for one or more possible sources of a request for the electronic mail by the user, and

in response to the search failing to identify the one or more possible sources of the request for the electronic mail by the user in the outbound web traffic from the web browser, restricting access from the endpoint, via the hyperlink in the electronic mail, to the external resource.

18. The device of claim 17 , wherein the processor is further configured to conditionally allow access to the external resource based on a security policy of the enterprise network.

19. The device of claim 17 , wherein the device includes a threat management facility for the enterprise network.

20. The device of claim 17 , wherein the device includes a firewall between the endpoint and a network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2023
From: THOMAS, ANDREW J.; ACKERMAN, KARL; BEAN, JAMES DOUGLAS; RAY, KENNETH D.; STUTZ, DANIEL
To: SOPHOS LIMITED
Reel/Frame 062873/0891 →
Continuity (3)
Continuation 16224352 · Dec 18, 2018
Continuation PCTUS2016040397 · Jun 30, 2016
Related Publication 20230208879A1 · Jun 29, 2023
References Cited (63)
US 6463474B1 · Fuh et al. · 2002 [cited by applicant]
US 7307996B2 · Forbes et al. · 2007 [cited by applicant]
US 7516488B1 · Kienzle · 2009 [cited by examiner]
US 8181244B2 · Boney · 2012 [cited by applicant]
US 8418250B2 · Morris et al. · 2013 [cited by applicant]
US 8726389B2 · Morris et al. · 2014 [cited by applicant]
US 8763123B2 · Morris et al. · 2014 [cited by applicant]
US 8850567B1 · Hsieh et al. · 2014 [cited by applicant]
US 8856505B2 · Schneider · 2014 [cited by applicant]
US 8990891B1 · Chickering et al. · 2015 [cited by applicant]
US 9137209B1 · Brandwine et al. · 2015 [cited by applicant]
US 9413721B2 · Morris et al. · 2016 [cited by applicant]
US 9578045B2 · Jaroch et al. · 2017 [cited by applicant]
US 9680860B1 · Wallace et al. · 2017 [cited by applicant]
US 10051001B1 · Ashley · 2018 [cited by examiner]
US 10091235B1 · Kushwaha et al. · 2018 [cited by applicant]
US 10257224B2 · Jaroch et al. · 2019 [cited by applicant]
US 10601865B1 · Mesdaq et al. · 2020 [cited by applicant]
US 20030158921A1 · Hare et al. · 2003 [cited by applicant]
US 20060062141A1 · Oran et al. · 2006 [cited by applicant]
US 20060140181A1 · Eldar et al. · 2006 [cited by applicant]
US 20070079379A1 · Sprosts et al. · 2007 [cited by applicant]
US 20070094325A1 · Ih et al. · 2007 [cited by applicant]
US 20070192855A1 · Hulten et al. · 2007 [cited by applicant]
US 20070199054A1 · Florencio et al. · 2007 [cited by applicant]
US 20080082662A1 · Dandliker et al. · 2008 [cited by applicant]
US 20080282335A1 · Abzarian et al. · 2008 [cited by applicant]
US 20090089859A1 · Cook et al. · 2009 [cited by applicant]
US 20100293610A1 · Beachem et al. · 2010 [cited by applicant]
US 20100306845A1 · Vaithilingam et al. · 2010 [cited by applicant]
US 20100332664A1 · Yevmenkin et al. · 2010 [cited by applicant]
US 20110314546A1 · Aziz et al. · 2011 [cited by applicant]
US 20120240185A1 · Kapoor et al. · 2012 [cited by applicant]
US 20120240224A1 · Payne et al. · 2012 [cited by applicant]
US 20140129920A1 · Sheretov et al. · 2014 [cited by applicant]
US 20150312268A1 · Ray et al. · 2015 [cited by applicant]
US 20160308762A1 · Teng et al. · 2016 [cited by applicant]
US 20170046506A1 · Fujii et al. · 2017 [cited by applicant]
US 20170206351A1 · Jay et al. · 2017 [cited by applicant]
US 20170237753A1 · Manning Dawson · 2017 [cited by applicant]
US 20170302535A1 · Lee · 2017 [cited by applicant]
US 20170310703A1 · Ackerman et al. · 2017 [cited by applicant]
US 20180332079A1 · Ashley et al. · 2018 [cited by applicant]
US 20190149574A1 · Thomas et al. · 2019 [cited by applicant]
US 20190312839A1 · Grimm et al. · 2019 [cited by applicant]
US 20240214420A1 · Thomas et al. · 2024 [cited by applicant]
WO WO2018004600 · 2018 [cited by applicant]
“U.S. Appl. No. 16/224,398 Final Office Action mailed Dec. 6, 2023”, 29 pages. [cited by applicant]
“U.S. Appl. No. 15/945,346 Non-Final Office Action mailed Feb. 24, 2020”, 18 pages. [cited by applicant]
“U.S. Appl. No. 15/945,346 Notice of Allowance mailed Nov. 25, 2020”, 11 pages. [cited by applicant]
“U.S. Appl. No. 16/224,352 Final Office Action mailed Mar. 18, 2022”, 24 pages. [cited by applicant]
“U.S. Appl. No. 16/224,352 Final Office Action mailed Apr. 9, 2021”, 23 pages. [cited by applicant]
“U.S. Appl. No. 16/224,352 Non-Final Office Action mailed Oct. 5, 2021”, 23 pages. [cited by applicant]
“U.S. Appl. No. 16/224,352 Non-Final Office Action mailed Dec. 1, 2020”, 25 pages. [cited by applicant]
“U.S. Appl. No. 16/224,352 Notice of Allowance mailed Oct. 13, 2022”, 13 pages. [cited by applicant]
“U.S. Appl. No. 16/224,352 Notice of Allowance mailed Dec. 9, 2022”, 13 pages. [cited by applicant]
WIPO, “Application No. PCT/US19/25710 International Preliminary Report on Patentability mailed Oct. 15, 2020”, 16 pages. [cited by applicant]
“U.S. Appl. No. 15/945,346 Notice of Allowance mailed Aug. 12, 2020”, 13 pages. [cited by applicant]
WIPO, “PCT Application No. PCT/US16/40397 International Preliminary Report on Patentability mailed Jan. 11, 2019”, 9 pages. [cited by applicant]
ISA, “PCT Application No. PCT/US16/40397 International Search Report and Written Opinion mailed Nov. 7, 2016”, 13 pages. [cited by applicant]
ISA, “PCT Application No. PCT/US19/25710 International Search Report and Written Opinion mailed Aug. 6, 2019”, 19 pages. [cited by applicant]
“U.S. Appl. No. 18/364,902 Non-Final Office Action mailed Apr. 25, 2024”, 14 pages. [cited by applicant]
“U.S. Appl. No. 16/224,398 Notice of Allowance mailed Dec. 5, 2024”, 10 pages. [cited by applicant]