IP Library › Granted Patent US 12,603,905
Granted Patent B2
US 12,603,905 · App. 18/192,236 · Granted Apr 14, 2026

Detecting multi-segment malicious email attacks

Inventors: Jan Brabec (Prague, CZ); Tomas Sixta (Prague, CZ)
Assignee: Cisco Technology, Inc.
H04L63/1425H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,905
App. No.
18/192,236
Granted
Apr 14, 2026
Kind
B2
Abstract

A method to perform the techniques described herein includes receiving a first email from a first sender to a first receiver. The method may include determining a first maliciousness prediction that indicates a first likelihood that the first email is malicious. The method may include determining that the first maliciousness prediction fails to satisfy a maliciousness pattern associated with malicious emails. The method may include receiving a second email from the first sender to the first receiver. The method may include determining that the first email and second email were received within a threshold period of time. The method may include determining an overall maliciousness prediction that indicates an overall likelihood that the first email and second email in combination are malicious. The method may include determining that the overall maliciousness prediction satisfies the maliciousness pattern.

Claims (82)

1 . A method for malicious email detection, the method comprising:

receiving a first email from a first sender to a first receiver, wherein the first email is an incoming email;

determining a first maliciousness prediction that indicates a first determination about whether the first email is malicious;

based on determining that the first maliciousness prediction indicates that the first email is non-malicious, determining an overall maliciousness prediction indicating whether a temporal sequence of past related emails is malicious, wherein each of the temporal sequence of past related emails is from the first sender to the first receiver, wherein the temporal sequence of past related emails is based on timestamp, and wherein determining the overall maliciousness prediction comprises:

determining the temporal sequence of past related emails, the temporal sequence of past related emails comprising the first email, a second email, and a third email, and wherein the second email and the third email are past emails from the first sender to the first receiver;

determining or receiving a second maliciousness prediction that indicates a second determination about whether the second email is malicious;

determining or receiving a third maliciousness prediction that indicates a third determination about whether the third email is malicious;

determining that the second email and the third email were received within a threshold period of a receipt time of the first email;

based at least in part on the second email and the third email being received from the first sender by the first receiver within the threshold period of time, providing, to a machine learning model, input data representing:

the first maliciousness prediction, the second maliciousness prediction, and the third maliciousness prediction,

a first position indicator representing a first position of the first email in the temporal sequence of past related emails,

a second position indicator representing a second position of the second email in the temporal sequence of past related emails; and

a third position indicator representing a third position of the third email in the temporal sequence of past related emails; and

receiving, from the machine learning model, output data representing the overall maliciousness prediction; and

determining that the overall maliciousness prediction satisfies a maliciousness pattern.

2 . The method of claim 1 , further comprising:

based at least in part on the overall maliciousness prediction satisfying the maliciousness pattern, determining a maliciousness verdict that indicates a remedial action for at least one of the first email, the second email, or the third email.

3 . The method of claim 1 , further comprising:

storing the first maliciousness prediction in a first record of a database, wherein the first record indicates the first maliciousness prediction, the first sender, and the first receiver.

4 . The method of claim 3 , further comprising:

based on determining that the second email is from the first sender to the first receiver, querying the database in accordance with the first sender and the first receiver to retrieve the first record; and

extracting the first maliciousness prediction from the first record.

5 . The method of claim 1 , wherein:

the second email is sent from the first sender to the first receiver and a second receiver, and

the method further comprises:

based at least in part on the overall maliciousness prediction satisfying the maliciousness pattern, determining a maliciousness verdict that indicates a remedial action for the second email, wherein the remedial action comprises blocking the second email from being provided to the first receiver and the second receiver.

6 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving a first email from a first sender to a first receiver, wherein the first email is an incoming email;

determining a first maliciousness prediction that indicates a first determination about whether the first email is malicious;

based on determining that the first maliciousness prediction indicates that the first email is non-malicious, determining an overall maliciousness prediction indicating whether a temporal sequence of past related emails is malicious, wherein each of the temporal sequence of past related emails is from the first sender to the first receiver, and wherein determining the overall maliciousness prediction comprises:

determining the temporal sequence of past related emails, the temporal sequence of past related emails comprising the first email, a second email, and a third email, and wherein the second email and the third email are past emails from the first sender to the first receiver;

determining or receiving a second maliciousness prediction that indicates a second determination about whether the second email is malicious;

determining or receiving a third maliciousness prediction that indicates a third determination about whether the third email is malicious;

determining that the second email and the third email were received within a threshold period of a receipt time of the first email;

based at least in part on the second email and the third email being received from the first sender by the first receiver within the threshold period of time, providing, to a machine learning model, input data representing:

the first maliciousness prediction, the second maliciousness prediction, and the third maliciousness prediction,

a first position indicator representing a first position of the first email in the temporal sequence of past related emails,

a second position indicator representing a second position of the second email in the temporal sequence of past related emails; and

a third position indicator representing a third position of the third email in the temporal sequence of past related emails; and

receiving, from the machine learning model, output data representing the overall maliciousness prediction; and

determining that the overall maliciousness prediction satisfies a maliciousness pattern.

7 . The system of claim 6 , further comprising:

based at least in part on the overall maliciousness prediction satisfying the maliciousness pattern, determining a maliciousness verdict that indicates a remedial action for at least one of the first email, the second email, or the third email.

8 . The system of claim 6 , further comprising:

storing the first maliciousness prediction in a first record of a database, wherein the first record indicates the first maliciousness prediction, the first sender, and the first receiver.

9 . The system of claim 8 , the operations further comprising:

determining that the second email is from the first sender to the first receiver;

based on determining that the second email is from the first sender to the first receiver, querying the database in accordance with the first sender and the first receiver to retrieve the first record; and

extracting the first maliciousness prediction from the first record.

10 . The system of claim 6 , wherein:

the second email is sent from the first sender to the first receiver and a second receiver, and

the operations further comprise:

based at least in part on the overall maliciousness prediction satisfying the maliciousness pattern, determining a maliciousness verdict that indicates a remedial action for the second email, wherein the remedial action comprises blocking the second email from being provided to the first receiver and the second receiver.

11 . One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving a first email from a first sender to a first receiver, wherein the first email is an incoming email;

determining a first maliciousness prediction that indicates a first determination about whether the first email is malicious;

based on determining that the first maliciousness prediction indicates that the first email is non-malicious, determining an overall maliciousness prediction indicating whether a temporal sequence of past related emails is malicious, wherein each of the temporal sequence of past related emails is from the first sender to the first receiver, and wherein determining the overall maliciousness prediction comprises:

determining the temporal sequence of past related emails, the temporal sequence of past related emails comprising the first email, a second email, and a third email, and wherein the second email and the third email are past emails from the first sender to the first receiver;

determining or receiving a second maliciousness prediction that indicates a second determination about whether the second email is malicious;

determining or receiving a third maliciousness prediction that indicates a third determination about whether the third email is malicious;

determining that the second email and the third email were received within a threshold period of a receipt time of the first email;

based at least in part on the second email and the third email being received from the first sender by the first receiver within the threshold period of time, providing, to a machine learning model, input data representing:

the first maliciousness prediction, the second maliciousness prediction, and the third maliciousness prediction,

a first position indicator representing a first position of the first email in the temporal sequence of past related emails,

a second position indicator representing a second position of the second email in the temporal sequence of past related emails; and

a third position indicator representing a third position of the third email in the temporal sequence of past related emails; and

receiving, from the machine learning model, output data representing the overall maliciousness prediction; and

determining that the overall maliciousness prediction satisfies a maliciousness pattern.

12 . The one or more non-transitory computer-readable media of claim 11 , further comprising:

based at least in part on the overall maliciousness prediction satisfying the maliciousness pattern, determining a maliciousness verdict that indicates a remedial action for at least one of the first email, the second email, or the third email.

13 . The one or more non-transitory computer-readable media of claim 11 , the operations further comprising:

storing the first maliciousness prediction in a first record of a database, wherein the first record indicates the first maliciousness prediction, the first sender, and the first receiver.

14 . The one or more non-transitory computer-readable media of claim 13 , the operations further comprising:

determining that the second email is from the first sender to the first receiver;

based on determining that the second email is from the first sender to the first receiver, querying the database in accordance with the first sender and the first receiver to retrieve the first record; and

extracting the first maliciousness prediction from the first record.

15 . The one or more non-transitory computer-readable media of claim 11 , wherein:

the second email is sent from the first sender to the first receiver and a second receiver, and

the operations further comprise:

based at least in part on the overall maliciousness prediction satisfying the maliciousness pattern, determining a maliciousness verdict that indicates a remedial action for the second email, wherein the remedial action comprises blocking the second email from being provided to the first receiver and the second receiver.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2023
From: BRABEC, JAN; SIXTA, TOMAS
To: CISCO TECHNOLOGY, INC.
Reel/Frame 063151/0650 →
Continuity (1)
Related Publication 20240333738A1 · Oct 3, 2024
References Cited (12)
US 8601064B1 · Liao · 2013 [cited by examiner]
US 10834127B1 · Yeh · 2020 [cited by examiner]
US 11075930B1 · Xavier · 2021 [cited by examiner]
US 20200067861A1 · Leddy · 2020 [cited by examiner]
US 20200084228A1 · Goutal · 2020 [cited by examiner]
US 20200344251A1 · Jeyakumar · 2020 [cited by examiner]
US 20220021700A1 · Devlin · 2022 [cited by examiner]
US 20220086179A1 · Levin · 2022 [cited by examiner]
US 20220230142A1 · Batchu · 2022 [cited by examiner]
US 20220255961A1 · Reiser · 2022 [cited by examiner]
US 20220286432A1 · Chechik · 2022 [cited by examiner]
EP 4044503 · 2022 [cited by applicant]