IP Library Granted Patent US 12,470,599
Granted Patent B2
US 12,470,599 · App. 18/443,055 · Granted Nov 11, 2025

Abuse mailbox for facilitating discovery, investigation, and analysis of email-based threats

Inventors: Evan Reiser (San Francisco, CA); Jeremy Kao (San Francisco, CA); Cheng-Lin Yeh (San Francisco, CA); Yea So Jung (San Mateo, CA); Kai Jing Jiang (San Francisco, CA); Abhijit Bagri (San Francisco, CA); Su Li Debbie Tan (San Francisco, CA); Venkatram Krishnamoorthi (San Francisco, CA); Fang Shuo Deng (San Francisco, CA)
Assignee: Abnormal AI, Inc.
H04L63/1483G06F16/9035G06Q10/107H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,599
App. No.
18/443,055
Granted
Nov 11, 2025
Kind
B2
Abstract

It is determined that a first email is present in a mailbox where emails deemed suspicious are placed for analysis. In response to determining that the first email is present in the mailbox, it is determined whether the first email is representative of a threat to an enterprise based at least in part by applying a trained model to the first email. In response to determining that the first email represents a threat to the enterprise, a record of the threat is generated by populating a data structure with information related to the first email. The data structure is applied to inboxes of a plurality of the employees to determine whether the first email is part of a campaign. In response to determining that the first email is part of a campaign, a filter associated with the data structure is applied to inbound emails addressed to employees of the enterprise.

Claims (57)

1 . A method comprising:

determining that a first email is present in an abuse mailbox where emails of deemed suspicious are placed for analysis;

in response to determining that the first email is present in the abuse mailbox, determining whether the first email is representative of a threat to an enterprise based at least in part by applying a trained model to extract a plurality of characterizing features from the first email; and

in response to determining that the first email represents a threat to the enterprise:

generating a record of the threat by populating a data structure with the plurality of characterizing features determined from the first email, the plurality of characterizing features including at least an identified threat type and sender characteristics; and

applying the data structure including the characterizing features to inboxes of a plurality of employees of the enterprise by searching for other emails within the inboxes exhibiting a similarity to the characterizing features, thereby determining whether the first email is part of a campaign including the other emails, and in response to determining that the first email is part of the campaign, applying a filter derived from and associated with the data structure, the filter configured to identify matching emails exhibiting the characterizing features, to inbound emails addressed to employees of the enterprise.

2 . The method of claim 1 , wherein the mailbox is associated with an address with which only addresses corresponding to a domain associated with the enterprise are permitted to communicate.

3 . The method of claim 1 , further comprising:

storing the record in a database in which threats are systematically logged over time,

wherein the database includes a series of records, each of which corresponds to a different email forwarded to the mailbox.

4 . The method of claim 3 , further comprising:

receiving input indicative of a query that specifies a criterion;

searching the series of records to identify a matching record whose corresponding email satisfies the criterion; and

causing display of the matching record on an interface.

5 . The method of claim 4 , wherein the criterion is a sender domain, a sender address, a sender identity, a threat type, or a target.

6 . The method of claim 1 , further comprising:

discovering, in at least one inbox included in inboxes of employees, a series of emails that are similar to the first email; and

defining the campaign by programmatically associating the first email and the series of emails.

7 . The method of claim 1 , wherein the first email is addressed to a first employee, and wherein the model is trained using past emails addressed to the first employee that were previously verified as non-malicious.

8 . The method of claim 1 , further comprising

notifying, in response to determining that the first email is part of the campaign, an analyst responsible for monitoring security of the enterprise of the threat.

9 . The method of claim 1 , wherein applying the data structure to the inboxes of the plurality of the employees including identifying one or more past emails in the inboxes of those plurality of the employees that share at least some of the characterizing features in common with the first email, and wherein applying the data structure as the filter includes identifying of one or more inbound emails that share at least some of the characterizing features in common with the first email.

10 . A system comprising:

one or more processors configured to:

determine that a first email is present in an abuse mailbox where emails deemed suspicious are placed for analysis;

in response to the determination that the first email is present in the abuse mailbox, determine whether the first email is representative of a threat to an enterprise based at least in part by applying a trained model to extract a plurality of characterizing features from the first email; and

in response to the determination that the first email represents a threat to the enterprise:

generate a record of the threat by populating a data structure with the plurality of characterizing features determined from the first email, the plurality of characterizing features including at least an identified threat type and sender characteristics; and

apply the data structure including the characterizing features to inboxes of a plurality of employees of the enterprise by searching for other emails within the inboxes exhibiting a similarity to the characterizing features, thereby determining whether the first email is part of a campaign including the other emails, and in response to determining that the first email is part of the campaign, applying a filter derived from and associated with the data structure, the filter configured to identify matching emails exhibiting the characterizing features, to inbound emails addressed to employees of the enterprise; and

a memory coupled to the one or more processors, wherein the memory is configured to provide the one or more processors with instructions.

11 . The system of claim 10 , wherein the mailbox is associated with an address with which only addresses corresponding to a domain associated with the enterprise are permitted to communicate.

12 . The system of claim 10 , wherein the one or more processors are further configured to:

store the record in a database in which threats are systematically logged over time,

wherein the database includes a series of records, each of which corresponds to a different email forwarded to the mailbox.

13 . The system of claim 12 , wherein the one or more processors are further configured to:

receive input indicative of a query that specifies a criterion;

search the series of records to identify a matching record whose corresponding email satisfies the criterion; and

cause display of the matching record on an interface.

14 . The system of claim 13 , wherein the criterion is a sender domain, a sender address, a sender identity, a threat type, or a target.

15 . The system of claim 10 , wherein the one or more processors are further configured to:

discover, in at least one inbox included in inboxes of employees, a series of emails that are similar to the first email; and

define the campaign by programmatically associating the first email and the series of emails.

16 . The system of claim 10 , wherein the first email is addressed to a first employee, and wherein the model is trained using past emails addressed to the first employee that were previously verified as non-malicious.

17 . The system of claim 10 , wherein the one or more processors are further configured to:

notify, in response to the determination that the first email is part of a campaign, an analyst responsible for monitoring security of the enterprise of the threat.

18 . A method comprising:

determining that a first email of a first employee of an enterprise has been placed in an abuse mailbox for analysis;

establishing that the first email was delivered as part of a business email compromise (BEC) campaign, wherein said establishing includes applying a trained model to extract a plurality of characterizing features from the first email, the plurality of characterizing features including at least an identified threat type and sender characteristics;

examining, in response to said establishing, an inbox associated with a second employee of the enterprise to identify a second email delivered as part of the BEC campaign by searching for the second email within the inbox exhibiting a similarity to the characterizing features; and

remediating the BEC campaign in an automated manner by applying a filter derived from and associated with a data structure populated with the plurality of characterizing features to extract the second email from the inbox to prevent further interaction with the second email by the second employee.

19 . The method of claim 18 , wherein said establishing comprises:

applying a first model to the first email to produce a first output, the first output indicating that the first email is malicious, and

applying a second model to the first email to produce a second output, the second output indicating that the first email is a particular type of malicious email.

20 . The method of claim 18 , further comprising:

obtaining information regarding the BEC campaign from the first and second emails;

generating a report summarizing a threat posed by the BEC campaign that includes the information; and

providing the report to an analyst responsible for monitoring security of the enterprise.

Continuity (4)
Continuation 17550848 · Dec 14, 2021
Continuation 17155843 · Jan 22, 2021
Provisional Application 62984098 · Mar 2, 2020
Related Publication 20240187450A1 · Jun 6, 2024
References Cited (237)
US 5999932A · Paul · 1999 [cited by applicant]
US 6023723A · McCormick · 2000 [cited by applicant]
US 6088717A · Reed · 2000 [cited by applicant]
US 7263506B2 · Lee · 2007 [cited by applicant]
US 7451487B2 · Oliver · 2008 [cited by applicant]
US 7610344B2 · Mehr · 2009 [cited by applicant]
US 7953814B1 · Chasin · 2011 [cited by applicant]
US 8112484B1 · Sharma · 2012 [cited by applicant]
US 8244532B1 · Begeja · 2012 [cited by applicant]
US 8566938B1 · Prakash · 2013 [cited by applicant]
US 8819819B1 · Johnston · 2014 [cited by applicant]
US 8935788B1 · Diao · 2015 [cited by applicant]
US 9009824B1 · Chen · 2015 [cited by applicant]
US 9154514B1 · Prakash · 2015 [cited by applicant]
US 9213827B2 · Li · 2015 [cited by applicant]
US 9245115B1 · Jakobsson · 2016 [cited by applicant]
US 9245225B2 · Winn · 2016 [cited by applicant]
US 9264418B1 · Crosley · 2016 [cited by applicant]
US 9348981B1 · Hearn · 2016 [cited by applicant]
US 9473437B1 · Jakobsson · 2016 [cited by applicant]
US 9516053B1 · Muddu · 2016 [cited by applicant]
US 9537880B1 · Jones · 2017 [cited by applicant]
US 9571512B2 · Ray · 2017 [cited by applicant]
US 9686308B1 · Srivastava · 2017 [cited by applicant]
US 9756007B1 · Stringhini · 2017 [cited by applicant]
US 9774626B1 · Himler · 2017 [cited by applicant]
US 9781152B1 · Mistratov · 2017 [cited by applicant]
US 9847973B1 · Jakobsson · 2017 [cited by applicant]
US 9940394B1 · Grant · 2018 [cited by applicant]
US 9946789B1 · Li · 2018 [cited by applicant]
US 9954805B2 · Nigam · 2018 [cited by applicant]
US 9961096B1 · Pierce · 2018 [cited by applicant]
US 9967268B1 · Hewitt · 2018 [cited by applicant]
US 10015182B1 · Shintre · 2018 [cited by applicant]
US 10044745B1 · Jones · 2018 [cited by applicant]
US 10091312B1 · Khanwalkar · 2018 [cited by applicant]
US 10104029B1 · Chambers · 2018 [cited by applicant]
US 10129194B1 · Jakobsson · 2018 [cited by applicant]
US 10129288B1 · Xie · 2018 [cited by applicant]
US 10243989B1 · Ding · 2019 [cited by applicant]
US 10250624B2 · Mixer · 2019 [cited by applicant]
US 10277628B1 · Jakobsson · 2019 [cited by applicant]
US 10362057B1 · Wu · 2019 [cited by applicant]
US 10397272B1 · Bruss · 2019 [cited by applicant]
US 10419468B2 · Glatfelter · 2019 [cited by applicant]
US 10523609B1 · Subramanian · 2019 [cited by applicant]
US 10601865B1 · Mesdaq · 2020 [cited by applicant]
US 10616272B2 · Chambers · 2020 [cited by applicant]
US 10673880B1 · Pratt · 2020 [cited by applicant]
US 10721195B2 · Jakobsson · 2020 [cited by applicant]
US 10834127B1 · Yeh · 2020 [cited by applicant]
US 10911489B1 · Chechik · 2021 [cited by applicant]
US 10972483B2 · Thomas · 2021 [cited by applicant]
US 10972485B2 · Ladnai · 2021 [cited by applicant]
US 11019076B1 · Jakobsson · 2021 [cited by applicant]
US 11252189B2 · Reiser · 2022 [cited by examiner]
US 11494421B1 · Ghafourifar · 2022 [cited by applicant]
US 11949713B2 · Reiser · 2024 [cited by examiner]
US 20020002520A1 · Gatto · 2002 [cited by applicant]
US 20020116463A1 · Hart · 2002 [cited by applicant]
US 20030204569A1 · Andrews · 2003 [cited by applicant]
US 20040030913A1 · Liang · 2004 [cited by applicant]
US 20040117450A1 · Campbell · 2004 [cited by applicant]
US 20040128355A1 · Chao · 2004 [cited by applicant]
US 20040215977A1 · Goodman · 2004 [cited by applicant]
US 20040260922A1 · Goodman · 2004 [cited by applicant]
US 20050039019A1 · Delany · 2005 [cited by applicant]
US 20050187934A1 · Motsinger · 2005 [cited by applicant]
US 20050198518A1 · Kogan · 2005 [cited by applicant]
US 20060036698A1 · Hebert · 2006 [cited by applicant]
US 20060053203A1 · Mijatovic · 2006 [cited by applicant]
US 20060191012A1 · Banzhof · 2006 [cited by applicant]
US 20060253581A1 · Dixon · 2006 [cited by applicant]
US 20070074169A1 · Chess · 2007 [cited by applicant]
US 20070276851A1 · Friedlander · 2007 [cited by applicant]
US 20080005249A1 · Hart · 2008 [cited by applicant]
US 20080086532A1 · Cunningham · 2008 [cited by applicant]
US 20080114684A1 · Foster · 2008 [cited by applicant]
US 20080201401A1 · Pugh · 2008 [cited by applicant]
US 20090037350A1 · Rudat · 2009 [cited by applicant]
US 20090132490A1 · Okraglik · 2009 [cited by applicant]
US 20100115040A1 · Sargent · 2010 [cited by applicant]
US 20100211641A1 · Yih · 2010 [cited by applicant]
US 20100318614A1 · Sager · 2010 [cited by applicant]
US 20110173142A1 · Dasgupta · 2011 [cited by applicant]
US 20110179126A1 · Wetherell · 2011 [cited by applicant]
US 20110213869A1 · Korsunsky · 2011 [cited by applicant]
US 20110214157A1 · Korsunsky · 2011 [cited by applicant]
US 20110231510A1 · Korsunsky · 2011 [cited by applicant]
US 20110231564A1 · Korsunsky · 2011 [cited by applicant]
US 20110238855A1 · Korsunsky · 2011 [cited by applicant]
US 20120028606A1 · Bobotek · 2012 [cited by applicant]
US 20120110672A1 · Judge · 2012 [cited by applicant]
US 20120137367A1 · Dupont · 2012 [cited by applicant]
US 20120233662A1 · Scott-Cowley · 2012 [cited by applicant]
US 20120278887A1 · Vitaldevara · 2012 [cited by applicant]
US 20120290712A1 · Walter · 2012 [cited by applicant]
US 20120297484A1 · Srivastava · 2012 [cited by applicant]
US 20130041955A1 · Chasin · 2013 [cited by applicant]
US 20130086180A1 · Midgen · 2013 [cited by applicant]
US 20130086261A1 · Lim · 2013 [cited by applicant]
US 20130097709A1 · Basavapatna · 2013 [cited by applicant]
US 20130167207A1 · Davis · 2013 [cited by applicant]
US 20130191759A1 · Bhogal · 2013 [cited by applicant]
US 20140013441A1 · Hencke · 2014 [cited by applicant]
US 20140032589A1 · Styler · 2014 [cited by applicant]
US 20140181223A1 · Homsany · 2014 [cited by applicant]
US 20140325662A1 · Foster · 2014 [cited by applicant]
US 20140365303A1 · Vaithilingam · 2014 [cited by applicant]
US 20140379825A1 · Speier · 2014 [cited by applicant]
US 20140380478A1 · Canning · 2014 [cited by applicant]
US 20150026027A1 · Priess · 2015 [cited by applicant]
US 20150128274A1 · Giokas · 2015 [cited by applicant]
US 20150143456A1 · Raleigh · 2015 [cited by applicant]
US 20150161609A1 · Christner · 2015 [cited by applicant]
US 20150161611A1 · Duke · 2015 [cited by applicant]
US 20150228004A1 · Bednarek · 2015 [cited by applicant]
US 20150234831A1 · Prasanna Kumar · 2015 [cited by applicant]
US 20150237068A1 · Sandke · 2015 [cited by applicant]
US 20150295942A1 · Tao · 2015 [cited by applicant]
US 20150295945A1 · Canzanese, Jr. · 2015 [cited by applicant]
US 20150319157A1 · Sherman · 2015 [cited by applicant]
US 20150339477A1 · Abrams · 2015 [cited by applicant]
US 20160014151A1 · Prakash · 2016 [cited by applicant]
US 20160036829A1 · Sadeh-Koniecpol · 2016 [cited by applicant]
US 20160057167A1 · Bach · 2016 [cited by applicant]
US 20160063277A1 · Vu · 2016 [cited by applicant]
US 20160156654A1 · Chasin · 2016 [cited by applicant]
US 20160227367A1 · Alsehly · 2016 [cited by applicant]
US 20160253598A1 · Yamada · 2016 [cited by applicant]
US 20160262128A1 · Hailpern · 2016 [cited by applicant]
US 20160301705A1 · Higbee · 2016 [cited by applicant]
US 20160306812A1 · Mchenry · 2016 [cited by applicant]
US 20160321243A1 · Walia · 2016 [cited by applicant]
US 20160328526A1 · Park · 2016 [cited by applicant]
US 20160344770A1 · Verma · 2016 [cited by applicant]
US 20160380936A1 · Gunasekara · 2016 [cited by applicant]
US 20170041296A1 · Ford · 2017 [cited by applicant]
US 20170048273A1 · Bach · 2017 [cited by applicant]
US 20170098219A1 · Peram · 2017 [cited by applicant]
US 20170111506A1 · Strong · 2017 [cited by applicant]
US 20170186112A1 · Polapala · 2017 [cited by applicant]
US 20170214701A1 · Hasan · 2017 [cited by applicant]
US 20170222960A1 · Agarwal · 2017 [cited by applicant]
US 20170223046A1 · Singh · 2017 [cited by applicant]
US 20170230323A1 · Jakobsson · 2017 [cited by applicant]
US 20170230403A1 · Kennedy · 2017 [cited by applicant]
US 20170237754A1 · Todorovic · 2017 [cited by applicant]
US 20170237776A1 · Higbee · 2017 [cited by applicant]
US 20170251006A1 · Larosa · 2017 [cited by applicant]
US 20170289191A1 · Thioux · 2017 [cited by applicant]
US 20170324767A1 · Srivastava · 2017 [cited by applicant]
US 20170346853A1 · Wyatt · 2017 [cited by applicant]
US 20180026926A1 · Nigam · 2018 [cited by applicant]
US 20180027006A1 · Zimmermann · 2018 [cited by applicant]
US 20180084003A1 · Uriel · 2018 [cited by applicant]
US 20180084013A1 · Dalton · 2018 [cited by applicant]
US 20180091453A1 · Jakobsson · 2018 [cited by applicant]
US 20180091476A1 · Jakobsson · 2018 [cited by applicant]
US 20180159808A1 · Pal · 2018 [cited by applicant]
US 20180189347A1 · Ghafourifar · 2018 [cited by applicant]
US 20180196942A1 · Kashyap · 2018 [cited by applicant]
US 20180219888A1 · Apostolopoulos · 2018 [cited by applicant]
US 20180227324A1 · Chambers · 2018 [cited by applicant]
US 20180295146A1 · Kovega · 2018 [cited by applicant]
US 20180324297A1 · Kent · 2018 [cited by applicant]
US 20180375814A1 · Hart · 2018 [cited by applicant]
US 20190014143A1 · Syme · 2019 [cited by applicant]
US 20190026461A1 · Cidon · 2019 [cited by applicant]
US 20190028509A1 · Cidon · 2019 [cited by applicant]
US 20190052655A1 · Benishti · 2019 [cited by applicant]
US 20190065748A1 · Foster · 2019 [cited by applicant]
US 20190068616A1 · Woods · 2019 [cited by applicant]
US 20190081983A1 · Teal · 2019 [cited by applicant]
US 20190087428A1 · Crudele · 2019 [cited by applicant]
US 20190089711A1 · Faulkner · 2019 [cited by applicant]
US 20190104154A1 · Kumar · 2019 [cited by applicant]
US 20190109863A1 · Traore · 2019 [cited by applicant]
US 20190141183A1 · Chandrasekaran · 2019 [cited by applicant]
US 20190166161A1 · Anand · 2019 [cited by applicant]
US 20190166162A1 · Anand · 2019 [cited by applicant]
US 20190190929A1 · Thomas · 2019 [cited by applicant]
US 20190190936A1 · Thomas · 2019 [cited by applicant]
US 20190199745A1 · Jakobsson · 2019 [cited by applicant]
US 20190205511A1 · Zhan · 2019 [cited by applicant]
US 20190222606A1 · Schweighauser · 2019 [cited by applicant]
US 20190238571A1 · Adir · 2019 [cited by applicant]
US 20190260780A1 · Matthew · 2019 [cited by applicant]
US 20190311121A1 · Martin · 2019 [cited by applicant]
US 20190319905A1 · Baggett · 2019 [cited by applicant]
US 20190319987A1 · Levy · 2019 [cited by applicant]
US 20190349400A1 · Bruss · 2019 [cited by applicant]
US 20190384911A1 · Caspi · 2019 [cited by applicant]
US 20200007502A1 · Everton · 2020 [cited by applicant]
US 20200021609A1 · Kuppanna · 2020 [cited by applicant]
US 20200044851A1 · Everson · 2020 [cited by applicant]
US 20200053111A1 · Jakobsson · 2020 [cited by applicant]
US 20200053120A1 · Wilcox · 2020 [cited by applicant]
US 20200068031A1 · Kursun · 2020 [cited by applicant]
US 20200074078A1 · Saxe · 2020 [cited by applicant]
US 20200076825A1 · Vallur · 2020 [cited by applicant]
US 20200125725A1 · Petersen · 2020 [cited by applicant]
US 20200127962A1 · Chuhadar · 2020 [cited by applicant]
US 20200162483A1 · Farhady · 2020 [cited by applicant]
US 20200204572A1 · Jeyakumar · 2020 [cited by applicant]
US 20200287936A1 · Nguyen · 2020 [cited by applicant]
US 20200344251A1 · Jeyakumar · 2020 [cited by applicant]
US 20200358804A1 · Crabtree · 2020 [cited by applicant]
US 20200374251A1 · Warshaw · 2020 [cited by applicant]
US 20200389486A1 · Jeyakumar · 2020 [cited by applicant]
US 20200396190A1 · Pickman · 2020 [cited by applicant]
US 20200396258A1 · Jeyakumar · 2020 [cited by applicant]
US 20200412767A1 · Crabtree · 2020 [cited by applicant]
US 20210021612A1 · Higbee · 2021 [cited by applicant]
US 20210058395A1 · Jakobsson · 2021 [cited by applicant]
US 20210091962A1 · Finke · 2021 [cited by applicant]
US 20210092154A1 · Kumar · 2021 [cited by applicant]
US 20210168161A1 · Dunn · 2021 [cited by applicant]
US 20210240836A1 · Hazony · 2021 [cited by applicant]
US 20210272066A1 · Bratman · 2021 [cited by applicant]
US 20210273976A1 · Reiser · 2021 [cited by examiner]
US 20210295179A1 · Eyal Altman · 2021 [cited by applicant]
US 20210329035A1 · Jeyakumar · 2021 [cited by applicant]
US 20210336983A1 · Lee · 2021 [cited by applicant]
US 20210360027A1 · Boyer · 2021 [cited by applicant]
US 20210374679A1 · Bratman · 2021 [cited by applicant]
US 20210374680A1 · Bratman · 2021 [cited by applicant]
US 20220021700A1 · Devlin · 2022 [cited by applicant]
US 20220255961A1 · Reiser · 2022 [cited by examiner]
CN 107315954 · 2017 [cited by applicant]
Proofpoint (Proofpoint Threat Response Auto-Pull, Feb. 2020, 2 pages) (Year: 2020). [cited by examiner]
Barngrover, Adam, ‘Vendor Access Management with IGA’, Saviynt Inc. Apr. 24, 2019 (Apr. 24, 2019) Retrieved on Apr. 17, 2021 (Apr. 17, 2021) from <https://saviynt.com/vendor-access-management-with-iga/> entire document,… [cited by applicant]
Information Security Media Group, ‘Multi-Channel Fraud: A Defense Plan’, Retrieved on Apr. 18, 2021 (Apr. 18, 2021) from <https ://www .bankInfosecurity.com/Interviews/multi-channel-fraud-defense-plan-i-1799>, Feb. 20, … [cited by applicant]
International Search Report and Written Opinion mailed Apr. 24, 2020 of PCT/US2019/067279 (14 pages). [cited by applicant]
Mahajan, et al., ‘Finding HTML Presentation Failures Using Image Comparison Techniques’, ASE'14, pp. 91-98 (Year: 2014). [cited by applicant]
Mont, Marco Casassa, ‘Towards accountable management of identity and privacy: Sticky policies and enforceable tracing services’, 14th International Workshop on Database and Expert Systems Applications, 2003. Proceedings… [cited by applicant]
Proofpoint (Proofpoint Closed-Loop Email Analysis and Response, Aug. 2018, 2 pages) (Year: 2018). [cited by applicant]