IP Library › Granted Patent US 12,701,135
Granted Patent B2
US 12,701,135 · App. 18/480,913 · Granted Aug 4, 2026

System and method for omnichannel social engineering attack avoidance

Inventors: Damien Phelan Stolarz (Los Angeles, CA); Johanna Dwyer (Brookline, MA); Ronald J. Pollack (Tampa, FL)
Assignee: Telepathy Labs, Inc.
H04L63/1441G06N3/084G06N5/02G06N5/043G06N20/00G10L15/26H04L63/10H04L63/1408H04L63/1416H04L63/1425H04L63/1483H04L67/306H04W12/08H04W12/12H04W4/21H04W12/67
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,701,135
App. No.
18/480,913
Filed
Oct 4, 2023
Granted
Aug 4, 2026
Kind
B2
Art Unit
2433
USPC
726/23
Abstract

A method, computer program product, and computer system for identifying social engineering activity associated with at least one of a first communication and a second communication based upon, at least in part, correlation to a predetermined rule. Characteristics of the communications are compared to the predetermined rule to determine if there is a correlation.

Claims (32)

1 . A computer-implemented method comprising:

identifying, by a computing device, a first characteristic of a first communication received on a first communication channel and sent on the first communication channel;

identifying a second characteristic of a second communication received on a second communication channel, and sent on the second communication channel, wherein both the first communication channel and the second communication channel are different communication platforms;

comparing, with a rule, both the first characteristic of the first communication received on the first communication channel and the second characteristic of the second communication received on the second communication channel;

determining whether both the first characteristic of the first communication received on the first communication channel and the second characteristic of the second communication received on the second communication channel correlates to the rule by detecting a pattern between both the first communication received on the first communication channel and the second communication received on the second communication channel; and

identifying, as potential social engineering activity, activity associated with at least one of the first communication or the second communication in response to both the first characteristic of the first communication received on the first communication channel and the second characteristic of the second communication received on the second communication channel correlates to the rule to detect the pattern, wherein identifying at least one of the first characteristic of the first communication received on the first communication channel or the second characteristic of the second communication received on the second communication channel includes one or more of voice analysis and text analysis, and further includes analyzing aggregated information about a user participating with one of the first communication channel and the second communication channel.

2 . The computer-implemented method of claim 1 , wherein the rule includes receiving the first communication and the second communication by the user.

3 . The computer-implemented method of claim 1 , wherein the rule includes receiving the first communication by the user and receiving the second communication by a second user related to the user.

4 . The computer-implemented method of claim 1 , wherein the pattern is one of an implicit pattern or an explicit pattern.

5 . The computer-implemented method of claim 1 , wherein the first communication channel is a first communication platform and the second communication channel is a second communication platform.

6 . The computer-implemented method of claim 1 further comprising providing an indication of the activity that is identified as potential social engineering activity to at least one of a user participating in the first communication received on the first communication channel or a third party based upon, at least in part, identifying the potential social engineering activity.

7 . A computer program product residing on a non-transitory computer readable storage medium having a plurality of instructions stored thereon which, when executed across one or more processors, causes at least a portion of the one or more processors to perform operations comprising:

identifying, by a computing device, a first characteristic of a first communication received on a first communication channel and sent on the first communication channel;

identifying a second characteristic of a second communication received on a second communication channel, and sent on the second communication channel, wherein both the first communication channel and the second communication channel are different communication platforms;

comparing, with a rule, both the first characteristic of the first communication received on the first communication channel and the second characteristic of the second communication received on the second communication channel;

determining whether both the first characteristic of the first communication received on the first communication channel and the second characteristic of the second communication received on the second communication channel correlates to the rule by detecting a pattern between both the first communication received on the first communication channel and the second communication received on the second communication channel; and

identifying, as potential social engineering activity, activity associated with at least one of the first communication or the second communication in response to both the first characteristic of the first communication received on the first communication channel and the second characteristic of the second communication received on the second communication channel correlates to the rule to detect the pattern, wherein identifying at least one of the first characteristic of the first communication received on the first communication channel or the second characteristic of the second communication received on the second communication channel includes one or more of voice analysis and text analysis, and further includes analyzing aggregated information about a user participating with one of the first communication channel and the second communication channel.

8 . The computer program product of claim 7 , wherein the rule includes receiving the first communication and the second communication by the user.

9 . The computer program product of claim 7 , wherein the pattern is one of an implicit pattern or an explicit pattern.

10 . The computer program product of claim 7 , wherein the first communication channel is a first communication platform and the second communication channel is a second communication platform.

11 . The computer program product of claim 7 , wherein the operations further comprise providing an indication of the activity that is identified as potential social engineering activity to at least one of a user participating in the first communication received on the first communication channel or a third party based upon, at least in part, identifying the potential social engineering activity.

12 . A computing system including one or more processors and one or more memories configured to perform operations comprising:

identifying, by a computing device, a first characteristic of a first communication received on a first communication channel and sent on the first communication channel;

identifying a second characteristic of a second communication received on a second communication channel, and sent on the second communication channel, wherein both the first communication channel and the second communication channel are different communication platforms;

comparing, with a rule, both the first characteristic of the first communication received on the first communication channel and the second characteristic of the second communication received on the second communication channel;

determining whether both the first characteristic of the first communication received on the first communication channel and the second characteristic of the second communication received on the second communication channel correlates to the rule by detecting a pattern between both the first communication received on the first communication channel and the second communication received on the second communication channel; and

identifying, as potential social engineering activity, activity associated with at least one of the first communication or the second communication in response to both the first characteristic of the first communication received on the first communication channel and the second characteristic of the second communication received on the second communication channel correlates to the rule to detect the pattern, wherein identifying at least one of the first characteristic of the first communication received on the first communication channel or the second characteristic of the second communication received on the second communication channel includes one or more of voice analysis and text analysis, and further includes analyzing aggregated information about a user participating with one of the first communication channel and the second communication channel.

13 . The computing system of claim 12 , wherein the rule includes receiving the first communication and the second communication by the user.

14 . The computing system of claim 12 , wherein the pattern is one of an implicit pattern or an explicit pattern.

15 . The computing system of claim 12 , wherein the first communication channel is a first communication platform and the second communication channel is a second communication platform.

16 . The computing system of claim 12 , wherein the operations further comprise providing an indication of the activity that is identified as potential social engineering activity to at least one of a user participating in the first communication received on the first communication channel or a third party based upon, at least in part, identifying the potential social engineering activity.

17 . The computing system of claim 12 , wherein the operations further comprise at least one of monitoring and controlling the operations by a virtual agent.

Continuity (8)
Continuation 17502377 · Oct 15, 2021
Continuation 15719920 · Sep 29, 2017
Provisional Application 62403691 · Oct 3, 2016
Provisional Application 62403687 · Oct 3, 2016
Provisional Application 62403693 · Oct 3, 2016
Provisional Application 62403696 · Oct 3, 2016
Provisional Application 62403688 · Oct 3, 2016
Related Publication 20240031399A1 · Jan 25, 2024
References Cited (143)
US 7231378B2 · Lawson et al. · 2007 [cited by applicant]
US 7356585B1 · Brook et al. · 2008 [cited by applicant]
US 7730092B2 · Lawson et al. · 2010 [cited by applicant]
US 7895649B1 · Brook et al. · 2011 [cited by applicant]
US 7934103B2 · Kidron · 2011 [cited by applicant]
US 8161288B2 · Newman et al. · 2012 [cited by applicant]
US 8364120B2 · Kuhlman et al. · 2013 [cited by applicant]
US 8381292B1 · Warner et al. · 2013 [cited by applicant]
US 8621614B2 · Vaithilingam et al. · 2013 [cited by applicant]
US 8713646B2 · Stuntebeck · 2014 [cited by applicant]
US 8856936B2 · Datta Ray et al. · 2014 [cited by applicant]
US 8924488B2 · Bobotek · 2014 [cited by applicant]
US 8997232B2 · Be'ery et al. · 2015 [cited by applicant]
US 9009832B2 · Be'ery et al. · 2015 [cited by applicant]
US 9027136B2 · Be'ery et al. · 2015 [cited by applicant]
US 9027137B2 · Be'ery et al. · 2015 [cited by applicant]
US 9123027B2 · Srivastava et al. · 2015 [cited by applicant]
US 9183387B1 · Altman et al. · 2015 [cited by applicant]
US 9183596B2 · Carrier et al. · 2015 [cited by applicant]
US 9253208B1 · Koshelev · 2016 [cited by applicant]
US 9311480B2 · Teddy et al. · 2016 [cited by applicant]
US 9407652B1 · Kesin et al. · 2016 [cited by applicant]
US 9479528B2 · Deng et al. · 2016 [cited by applicant]
US 9503472B2 · Laidlaw et al. · 2016 [cited by applicant]
US 9537840B2 · Schutz et al. · 2017 [cited by applicant]
US 9537841B2 · Schutz et al. · 2017 [cited by applicant]
US 9699196B1 · Kolman et al. · 2017 [cited by applicant]
US 9763097B2 · Robinson et al. · 2017 [cited by applicant]
US 9798795B2 · Raichelgauz et al. · 2017 [cited by applicant]
US 9852736B2 · Sharma et al. · 2017 [cited by applicant]
US 9888037B1 · Sharifi Mehr · 2018 [cited by applicant]
US 9912486B1 · Sharifi Mehr · 2018 [cited by applicant]
US 10055562B2 · Lerner et al. · 2018 [cited by applicant]
US 10171474B2 · Tseng et al. · 2019 [cited by applicant]
US 20020161766A1 · Lawson et al. · 2002 [cited by applicant]
US 20050022006A1 · Bass et al. · 2005 [cited by applicant]
US 20050097595A1 · Lipsanen et al. · 2005 [cited by applicant]
US 20050132070A1 · Redlich et al. · 2005 [cited by applicant]
US 20050273442A1 · Bennett et al. · 2005 [cited by applicant]
US 20060069697A1 · Shraim et al. · 2006 [cited by applicant]
US 20060212934A1 · Cameron · 2006 [cited by applicant]
US 20060265760A1 · Daemke et al. · 2006 [cited by applicant]
US 20070169204A1 · Janakiraman et al. · 2007 [cited by applicant]
US 20080163339A1 · Janakiraman · 2008 [cited by applicant]
US 20080267091A1 · Parkkinen et al. · 2008 [cited by applicant]
US 20080276315A1 · Shuster · 2008 [cited by applicant]
US 20080301810A1 · Lehane et al. · 2008 [cited by applicant]
US 20090043818A1 · Raichelgauz et al. · 2009 [cited by applicant]
US 20090205018A1 · Ferraiolo et al. · 2009 [cited by applicant]
US 20090254970A1 · Agarwal et al. · 2009 [cited by applicant]
US 20090324025A1 · Camp, Jr. et al. · 2009 [cited by applicant]
US 20100037284A1 · Sachs · 2010 [cited by applicant]
US 20100169486A1 · McCormack et al. · 2010 [cited by applicant]
US 20110197070A1 · Mizrah · 2011 [cited by applicant]
US 20110211682A1 · Singh · 2011 [cited by examiner]
US 20120096553A1 · Srivastava et al. · 2012 [cited by applicant]
US 20120254333A1 · Chandramouli et al. · 2012 [cited by applicant]
US 20130138428A1 · Chandramouli et al. · 2013 [cited by applicant]
US 20130198383A1 · Tseng · 2013 [cited by applicant]
US 20130347116A1 · Flores · 2013 [cited by applicant]
US 20140173726A1 · Varenhorst · 2014 [cited by applicant]
US 20140230064A1 · Higbee et al. · 2014 [cited by applicant]
US 20150113631A1 · Lerner et al. · 2015 [cited by applicant]
US 20150128274A1 · Giokas · 2015 [cited by applicant]
US 20150172311A1 · Freedman et al. · 2015 [cited by applicant]
US 20150207806A1 · Be'ery et al. · 2015 [cited by applicant]
US 20150222667A1 · Nayshtut et al. · 2015 [cited by applicant]
US 20150229664A1 · Hawthorn · 2015 [cited by applicant]
US 20150281287A1 · Gill et al. · 2015 [cited by applicant]
US 20150373428A1 · Trollope et al. · 2015 [cited by applicant]
US 20160057167A1 · Bach · 2016 [cited by applicant]
US 20160078225A1 · Ray et al. · 2016 [cited by applicant]
US 20160080399A1 · Harris et al. · 2016 [cited by applicant]
US 20160080417A1 · Thomas et al. · 2016 [cited by applicant]
US 20160080418A1 · Ray et al. · 2016 [cited by applicant]
US 20160080419A1 · Schiappa et al. · 2016 [cited by applicant]
US 20160080420A1 · Ray et al. · 2016 [cited by applicant]
US 20160099963A1 · Mahaffey et al. · 2016 [cited by applicant]
US 20160127402A1 · Veeramachaneni et al. · 2016 [cited by applicant]
US 20160173520A1 · Foster et al. · 2016 [cited by applicant]
US 20160191465A1 · Thomas et al. · 2016 [cited by applicant]
US 20160191476A1 · Schutz et al. · 2016 [cited by applicant]
US 20160191548A1 · Smith et al. · 2016 [cited by applicant]
US 20160205094A1 · Harthattu et al. · 2016 [cited by applicant]
US 20160261618A1 · Koshelev · 2016 [cited by applicant]
US 20160323303A1 · Thomas · 2016 [cited by applicant]
US 20160381077A1 · Bassias et al. · 2016 [cited by applicant]
US 20170019419A1 · Kholidy et al. · 2017 [cited by applicant]
US 20170053108A1 · Jakobsson et al. · 2017 [cited by applicant]
US 20170272468A1 · Chechani · 2017 [cited by applicant]
US 20200067861A1 · Leddy · 2020 [cited by examiner]
CN 102082792A · 2011 [cited by applicant]
CN 101667979A · 2012 [cited by applicant]
KR 20090001505A · 2009 [cited by applicant]
KR 101264255A · 2013 [cited by applicant]
KR 101328389A · 2013 [cited by applicant]
KR 20140108830A · 2014 [cited by applicant]
KR 101450009A · 2014 [cited by applicant]
Zou, et al., “A Firewall Network System for Worm Defense in Enterprise Networks”; University of Massachusetts, Amherst, Technical Report: TR-04-CSE-01, Feb. 4, 2004. [cited by applicant]
Lindstrom, “Attacking and Defending Web Services”, A Spire Research Report, 2004. Print. [cited by applicant]
Bisht, et al, “CANDID: Dynamic Candidate Evaluations for Automatic Prevention of SQL Injection Attacks”; ACM Journal Name, vol. V. No. N. Month 20YY, pp. 1-38. [cited by applicant]
Wood, et al, “Denial of Service in Sensor Networks”, Computer 0018-9162/02, 2002 IEEE. [cited by applicant]
Tuck, et al., “Deterministic Memory-Efficient String Matching Algorithms for Instrusion Detection”, 0-7803-8356-7/04 © 2004 IEEE INFOCOM 2004. [cited by applicant]
Dickerson, et al., “Fuzzy Intrusion Detection”, Electrical and Computer Engineering Department, Iowa State University, Ames, IA. [cited by applicant]
Dickerson, “Fuzzy Network Profiling for Intrusion Detection”, Electrical and Computer Engineering Department, Iowa State University, Ames, Iowa 50011. [cited by applicant]
Carpenter, et al., “Magic Quadrant for Security Awareness Computer-Based Training”, Published: Oct. 25, 2016, ID: G00293102, Gartner, Inc. [cited by applicant]
Jajodia, et al, “Cauldron, Mission-Centric Cyber Situational Awareness with Defense in Depth”, Supported in part by Army Research Office MURI 2911NF-09-10525, MILCOM 2011 Military Communications Conference, 2011. [cited by applicant]
Reynolds et al., “On-Line Intrustion Detection and Attack Prevention Using Diversity, Generate-and-Test, and Generalization”, Teknowledge Corporation, Proceedings of the 36th Hawaii Conference on System Sciences, 2003. [cited by applicant]
Lippmann et al., “Recent International Advances in Intrustion Detection”, 11th International Symposium, RAID 2008, Cambridge, MA, USA, Sep. 15-17, 2008 Proceedings. [cited by applicant]
Bakshi et al., “Securing cloud from DDOS Attacks using Intrusion Detection System in virtual machine”, 2010 Second International Conference on Communication Software and Networks, 2010. [cited by applicant]
Singhal et al., “Security Risk Analysis of Enterprise Networks Using Probabilistic Attack Graphs”, NIST Interagency Report 7788, National Institute of Standards and Technology, U.S. Department of Commerce, Aug. 2011. [cited by applicant]
McHugh et al., “Defending Yourself: The Role of Intrusion Detection Systems”, IEEE Software 17.5, 2000, pp. 42-51, Web. [cited by applicant]
Lippmann et al., “Validating and Restoring Defense in Depth Using Attack Graphs”, MIT Lincoln Laboratory, Milcom 2006. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/720,009 mailed Dec. 18, 2017. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/720,186 mailed Jan. 11, 2018. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/720,064 mailed Feb. 7, 2018. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2017/054262 mailed Jan. 10, 2018. [cited by applicant]
Final Office Action for U.S. Appl. No. 15/720,186 mailed Jun. 13, 2018. [cited by applicant]
Final Office Action for U.S. Appl. No. 15/720,009 mailed Jun. 8, 2018. [cited by applicant]
Final Office Action for U.S. Appl. No. 15/720,064 mailed Aug. 9, 2018. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/720,009 mailed Sep. 20, 2018. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/720,186 mailed Oct. 16, 2018. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/720,064 mailed Jan. 14, 2019. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/720,186 mailed Mar. 4, 2019. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/719,900 mailed Jun. 14, 2019. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/719,882 mailed Jul. 11, 2019. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/719,920 mailed Aug. 6, 2019. [cited by applicant]
Final Office Action for U.S. Appl. No. 15/719,900 mailed Nov. 20, 2019. [cited by applicant]
Final Office Action for U.S. Appl. No. 15/719,882 mailed Nov. 22, 2019. [cited by applicant]
Final Office Action for U.S. Appl. No. 15/719,920 mailed Feb. 26, 2020. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/719,900 mailed May 1, 2020. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/719,882 mailed May 12, 2020. [cited by applicant]
Extended Supplementary European Search Report for European Patent Application No. 17858934.7 mailed Mar. 31, 2020. [cited by applicant]
Written Opinion for Singapore Patent Application No. 11201902444Q mailed Apr. 20, 2020. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/719,920 mailed Jul. 22, 2020. [cited by applicant]
Final Office Action for U.S. Appl. No. 15/719,900 mailed Oct. 9, 2020. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/719,882 mailed Dec. 24, 2020. [cited by applicant]
Final Office Action for U.S. Appl. No. 15/719,920 mailed Dec. 28, 2020. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/719,900 mailed May 14, 2021. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/719,920 mailed Jun. 30, 2021. [cited by applicant]
Extended European Search Report for European Application No. 22159418.7 mailed Jun. 24, 2022. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/502,377 mailed Mar. 28, 2023, ## pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/502,377 mailed Jul. 6, 2023, ## pages. [cited by applicant]