IP Library › Granted Patent US 12,506,778
Granted Patent B2
US 12,506,778 · App. 18/185,221 · Granted Dec 23, 2025

Techniques for detecting and mitigating spoofed email communications

Inventors: Suresh Gopathy (Alpharetta, GA); Gajendar Pandey (Delhi, IN)
Assignee: Cisco Technology, Inc.
H04L63/1483G06V10/74G06V30/19H04L51/21
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,778
App. No.
18/185,221
Granted
Dec 23, 2025
Kind
B2
Abstract

Techniques are described herein for detecting an authorization status for an email based on content included in that email. In embodiments, such techniques may comprise receiving an electronic communication associated with an origination address, identifying, within the electronic communication, information indicating a claimed source entity, determining, based on the information, a claimed source entity, determining a number of authorized addresses associated with the claimed source entity, determining whether the electronic communication is authorized by the claimed source entity based on whether the origination address is included within the number of authorized addresses, updating the electronic communication to include an indication of whether the electronic communication is authorized by the claimed source entity, and transmitting the electronic communication to its intended recipient.

Claims (49)

1 . A method comprising:

maintaining multiple registry records, individual registry records of the multiple registry records including associations between at least one image and at least one source entity, individual images of the multiple images associated with one or more source entity of the at least one source entity;

receiving, by a service provider computing device, an electronic communication associated with an origination address;

identifying, by the service provider computing device within the electronic communication, image information indicating a claimed source entity;

determining, by the service provider computing device using one or more computer vision and/or optical character recognition techniques a claimed source entity from the multiple source entities;

retrieving, an individual registry record of the multiple registry records associated with the claimed source entity;

determining, by the service provider computing device based on comparing the image information to the at least one image of the individual registry record, a number of authorized addresses associated with the claimed source entity;

determining, by the service provider computing device, whether the electronic communication is authorized by the claimed source entity based on whether the origination address is included within the number of authorized addresses;

updating, by the service provider computing device, the electronic communication to include an indication of whether the electronic communication is authorized by the claimed source entity; and

transmitting, by the service provider computing device, the electronic communication to its intended recipient.

2 . The method of claim 1 , wherein the image information comprises one or more images included in the electronic communication.

3 . The method of claim 2 , wherein the one or more images included in the electronic communication are determined to correspond to a logo for a brand entity, the claimed source entity determined to be the brand entity.

4 . The method of claim 1 , wherein the claimed source entity is further determined based on information included as text in a body of the electronic communication.

5 . The method of claim 4 , wherein the claimed source entity is determined to be a brand entity based on a context in which a reference to the brand entity is presented within the text.

6 . The method of claim 1 , wherein the origination address is determined from one of a sender address included in a header of the electronic communication or a return-path address for the electronic communication.

7 . The method of claim 1 , wherein the number of authorized addresses associated with the claimed source entity is determined by communicating with at least one second computing device.

8 . The method of claim 7 , wherein the at least one second computing device comprises a Domain Name Service (DNS) registry server.

9 . The method of claim 8 , wherein the number of authorized addresses are determined based on sender policy frameworks (SPF) stored by the DNS registry server in relation to the claimed source entity.

10 . The method of claim 1 , wherein an individual registry record of the multiple registry records further include an indication of a period of time over which the individual registry record is valid.

11 . An email security system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the email security system to perform operations comprising:

maintaining multiple registry records, individual registry records of the multiple registry records including associations between at least one image and at least one source entity, individual images of the multiple images associated with one or more source entity of the at least one source entity;

receiving an electronic communication associated with an origination address;

identifying, within the electronic communication, image information indicating a claimed source entity;

determining, using one or more computer vision and/or optical character recognition techniques, a claimed source entity from the multiple source entities;

retrieving, an individual registry record of the multiple registry records associated with the claimed source entity;

determining, based on comparing the image information to the at least one image of the individual registry record, a number of authorized addresses associated with the claimed source entity;

determining whether the electronic communication is authorized by the claimed source entity based on whether the origination address is included within the number of authorized addresses;

updating the electronic communication to include an indication of whether the electronic communication is authorized by the claimed source entity; and

transmitting the electronic communication to its intended recipient.

12 . The email security system of claim 11 , wherein updating the electronic communication to include the indication comprises adding an image or watermark to the electronic communication that indicates an authorization status.

13 . The email security system of claim 11 , wherein the image information comprises an image included in the electronic communication, and the number of authorized addresses indicates entities authorized to use the image.

14 . The email security system of claim 13 , wherein the image information is determined from the image included in the electronic communication using one or more optical character recognition techniques.

15 . The email security system of claim 11 , wherein the number of authorized addresses correspond to the at least one image in the individual registry record.

16 . The email security system of claim 11 , wherein the number of authorized addresses associated with the claimed source entity is determined by communicating with a DNS registry server.

17 . One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

maintaining multiple registry records, individual registry records of the multiple registry records including associations between at least one image and at least one source entity, individual images of the multiple images associated with one or more source entity of the at least one source entity;

receiving an electronic communication associated with an origination address;

identifying, within the electronic communication, image information indicating a claimed source entity;

determining, using one or more computer vision and/or optical character recognition techniques, a claimed source entity from the multiple source entities;

retrieving, an individual registry record of the multiple registry records associated with the claimed source entity;

determining based on comparing the image information to the at least one image of the individual registry record, a number of authorized addresses associated with the claimed source entity;

determining whether the electronic communication is authorized by the claimed source entity based on whether the origination address is included within the number of authorized addresses;

updating the electronic communication to include an indication of whether the electronic communication is authorized by the claimed source entity; and

transmitting the electronic communication to its intended recipient.

18 . The one or more non-transitory computer-readable media of claim 17 , wherein the image information comprises one or more images corresponding to a logo for a brand entity included in the electronic communication, and wherein the claimed source entity is determined to be the brand entity.

19 . The one or more non-transitory computer-readable media of claim 17 , wherein the claimed source entity is further determined based on a context in which a reference to a brand entity is presented within a body of the electronic communication, and wherein the claimed source entity is determined to be the brand entity.

20 . The one or more non-transitory computer-readable media of claim 17 , wherein the number of authorized addresses associated with the claimed source entity is determined by communicating with a DNS registry server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: GOPATHY, SURESH; PANDEY, GAJENDAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 063007/0020 →
Continuity (1)
Related Publication 20240314163A1 · Sep 19, 2024
References Cited (17)
US 10755095B1 · Cunningham · 2020 [cited by examiner]
US 10999322B1 · Yuan · 2021 [cited by examiner]
US 11729211B2 · Jakobsson · 2023 [cited by examiner]
US 20060259561A1 · Takahashi · 2006 [cited by examiner]
US 20190319905A1 · Baggett · 2019 [cited by examiner]
US 20190387004A1 · Parekh · 2019 [cited by examiner]
US 20200067976A1 · Jakobsson · 2020 [cited by examiner]
US 20210097119A1 · Komada · 2021 [cited by examiner]
US 20210112024A1 · Everton · 2021 [cited by applicant]
US 20210152565A1 · Greevy · 2021 [cited by examiner]
US 20210344711A1 · Cleveland et al. · 2021 [cited by applicant]
US 20220086133A1 · Killoran, Jr. · 2022 [cited by examiner]
US 20220353242A1 · Goldstein · 2022 [cited by applicant]
US 20230328034A1 · Behera · 2023 [cited by examiner]
US 20240022432A1 · Spanier · 2024 [cited by examiner]
US 20240177512A1 · Gils · 2024 [cited by examiner]
Panda, et al., “A Novel Logo Identification Technique for Logo-Based Phising Detection in Cyber-Physical Systems”, MDPI, Publisehd on Aug. 15, 2022, 17 pages. [cited by applicant]