IP Library › Granted Patent US 12,732,510
Granted Patent B2
US 12,732,510 · App. 18/385,614 · Granted Sep 8, 2026

Dynamic message analysis platform for enhanced enterprise security

Inventor: J. Trent Adams (Highlands Ranch, CO)
Assignee: Proofpoint, Inc.
H04L63/123G06N20/00H04L61/4511H04L63/0227H04L63/1416H04L63/1425H04L63/166H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,510
App. No.
18/385,614
Granted
Sep 8, 2026
Kind
B2
Abstract

Aspects of the disclosure relate to dynamic message analysis using machine learning. A computing platform may monitor a messaging server associated with an enterprise organization. Based on monitoring the messaging server, the computing platform may identify bi-directional messaging traffic between enterprise domains associated with the enterprise organization and external domains not associated with the enterprise organization. Based on identifying the bi-directional messaging traffic, the computing platform may select external domains for a conversation detection process. The computing platform may compute an initial set of rank-ordered external domains by: determining, based on a number of messages sent to and received from each enterprise domain/external domain pair, weighted difference values and ranking the plurality of external domains selected for the conversation detection process based the weighted difference values. The computing platform may remove, from the initial set of rank-ordered external domains, known outlier domains, and may execute enhanced protection actions.

Claims (60)

1 . A computing platform, comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

monitor an electronic messaging server associated with an enterprise organization;

based on monitoring the electronic messaging server associated with the enterprise organization, identify bi-directional messaging traffic between one or more enterprise domains associated with the enterprise organization and one or more external domains not associated with the enterprise organization;

based on identifying the bi-directional messaging traffic between the one or more enterprise domains associated with the enterprise organization and the one or more external domains not associated with the enterprise organization, select a plurality of external domains for a conversation detection process;

compute an initial set of rank-ordered external domains;

remove, from the initial set of rank-ordered external domains, a set of one or more known outlier domains, resulting in a final set of rank-ordered external domains;

select a subset of external domains from the final set of rank-ordered external domains based on a threshold ranking value, wherein each of the subset of external domains has a rank above the threshold ranking value, the subset of external domains being less than all of the final set of rank-ordered external domains;

apply a security scoring process to the selected subset of external domains to compute a weighted security score for at least one external domain of the selected subset of external domains, wherein computing the weighted security score comprises: determining a domain score corresponding to the at least one external domain, determining a sender score corresponding to a sender of one or more messages originating from the at least one external domain, determining a message score corresponding to the one or more messages originating from the at least one external domain, and generating the weighted security score by combining the domain score, the sender score, and the message score using a weighted aggregation;

determine a weighted grade for the at least one external domain based on the weighted security score for the at least one external domain; and

execute one or more enhanced protection actions based on comparing the weighted grade to first and second thresholds, the one or more enhanced protection actions including:

a) an informative protection action when the weighted grade does not exceed the first threshold;

b) an active protection action, different from the informative protection action, when the weighted grade exceeds the first threshold but not the second threshold; and

c) an automatic protection action, different from the active protection action and informative protection action, when the weighted grade exceeds the second threshold.

2 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

send, to an internal enterprise user device, a request for one or more manually identified domains for the security scoring process; and

receive, from the internal enterprise user device, one or more enterprise resource planning (ERP) export files or one or more curated lists that specify the one or more manually identified domains, wherein executing the one or more enhanced protection actions comprises executing at least one enhanced protection action on at least one of the one or more manually identified domains.

3 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

apply one or more additional automated methods to identify one or more automatically identified domains, wherein the one or more additional automated methods comprise one or more of: inspecting domain name system (DNS) records, applying one or more heuristics, applying machine learning algorithms, using methods for domain identification, applying natural language processing algorithms, or extrapolating based on common industry data, wherein the one or more enhanced protection actions are further associated with at least one of the one or more automatically identified domains.

4 . The computing platform of claim 1 , wherein applying the security scoring process comprises evaluating the at least one external domain based on one or more of: a security posture corresponding to the at least one external domain, historical threat information corresponding to the at least one external domain, trust metrics, reputation data, or external data corresponding to security of the at least one external domain.

5 . The computing platform of claim 1 , wherein executing the informative protection action further comprises:

generating one or more alerts, reports, or security guidelines, the one or more alerts, reports, or security guidelines corresponding to electronic messaging security.

6 . The computing platform of claim 1 , wherein the automatic protection action includes enforcing an inbound email authentication verification for email.

7 . The computing platform of claim 6 , wherein enforcing the inbound email authentication verification for email comprises enforcing one or more of: SPF, DKIM, DMARC, or TLS, and

wherein executing the automatic protection action further comprises monitoring an enterprise network gateway to enforce the inbound email authentication verification.

8 . A method, comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

monitoring an electronic messaging server associated with an enterprise organization;

based on monitoring the electronic messaging server associated with the enterprise organization, identifying bi-directional messaging traffic between one or more enterprise domains associated with the enterprise organization and one or more external domains not associated with the enterprise organization;

based on identifying the bi-directional messaging traffic between the one or more enterprise domains associated with the enterprise organization and the one or more external domains not associated with the enterprise organization, selecting a plurality of external domains for a conversation detection process;

computing an initial set of rank-ordered external domains;

removing, from the initial set of rank-ordered external domains, a set of one or more known outlier domains, resulting in a final set of rank-ordered external domains;

selecting a subset of external domains from the final set of rank-ordered external domains based on a threshold ranking value, wherein each of the subset of external domains has a rank above the threshold ranking value, the subset of external domains being less than all of the final set of rank-ordered external domains;

applying a security scoring process to the selected subset of external domains to compute a weighted security score for at least one external domain of the selected subset of external domains, wherein computing the weighted security score comprises; determining a domain score corresponding to the at least one external domain, determining a sender score corresponding to a sender of one or more messages originating from the at least one external domain, determining a message score corresponding to the one or more messages originating from the at least one external domain, and generating the weighted security score by combining the domain score, the sender score, and the message score using a weighted aggregation;

determining a weighted grade for the at least one external domain based on the weighted security score for the at least one external domain; and

executing one or more enhanced protection actions based on comparing the weighted grade to first and second thresholds, the one or more enhanced protection actions including:

a) an informative protection action when the weighted grade does not exceed the first threshold;

b) an active protection action, different from the informative protection action, when the weighted grade exceeds the first threshold but not the second threshold; and

c) an automatic protection action, different from the active protection action and informative protection action, when the weighted grade exceeds the second threshold.

9 . The method of claim 8 , further comprising:

sending, to an internal enterprise user device, a request for one or more manually identified domains for the security scoring process; and

receiving, from the internal enterprise user device, one or more enterprise resource planning (ERP) export files or one or more curated lists that specifies the one or more manually identified domains, wherein executing the one or more enhanced protection actions comprises executing at least one enhanced protection action on at least one of the one or more manually identified domains.

10 . The method of claim 8 , further comprising:

applying one or more additional automated methods to identify one or more automatically identified domains, wherein the one or more additional automated methods comprises one or more of: inspecting domain name system (DNS) records, applying one or more heuristics, applying machine learning algorithms, using methods for domain identification, applying natural language processing algorithms, or extrapolating based on common industry data, wherein the one or more enhanced protection actions are further associated with at least one of the one or more automatically identified domains.

11 . The method of claim 8 , wherein applying the security scoring process comprises evaluating the at least one external domain based on one or more of: a security posture corresponding to the at least one external domain, historical threat information corresponding to the at least one external domain, trust metrics, reputation data, or external data corresponding to security of the at least one external domain.

12 . One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

monitor an electronic messaging server associated with an enterprise organization;

based on monitoring the electronic messaging server associated with the enterprise organization, identify bi-directional messaging traffic between one or more enterprise domains associated with the enterprise organization and one or more external domains not associated with the enterprise organization;

based on identifying the bi-directional messaging traffic between the one or more enterprise domains associated with the enterprise organization and the one or more external domains not associated with the enterprise organization, select a plurality of external domains for a conversation detection process;

compute an initial set of rank-ordered external domains;

remove, from the initial set of rank-ordered external domains, a set of one or more known outlier domains, resulting in a final set of rank-ordered external domains;

select a subset of external domains from the final set of rank-ordered external domains based on a threshold ranking value, wherein each of the subset of external domains has a rank above the threshold ranking value, the subset of external domains being less than all of the final set of rank-ordered external domains;

apply a security scoring process to the selected subset of external domains to compute a weighted security score for at least one external domain of the selected subset of external domains, wherein computing the weighted security score comprises: determining a domain score corresponding to the at least one external domain, determining a sender score corresponding to a sender of one or more messages originating from the at least one external domain, determining a message score corresponding to the one or more messages originating from the at least one external domain, and generating the weighted security score by combining the domain score, the sender score, and the message score using a weighted aggregation;

determine a weighted grade for the at least one external domain based on the weighted security score for the at least one external domain; and

execute one or more enhanced protection actions based on comparing the weighted grade to first and second thresholds, the one or more enhanced protection actions including:

a) an informative protection action when the weighted grade does not exceed the first threshold;

b) an active protection action, different from the informative protection action, when the weighted grade exceeds the first threshold but not the second threshold; and

c) an automatic protection action, different from the active protection action and informative protection action, when the weighted grade exceeds the second threshold.

Assignments (3)
INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Dec 9, 2025
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 073910/0027 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2023
From: ADAMS, J. TRENT
To: PROOFPOINT, INC.
Reel/Frame 065405/0855 →
Continuity (3)
Continuation 17016980 · Sep 10, 2020
Provisional Application 62947050 · Dec 12, 2019
Related Publication 20240064153A1 · Feb 22, 2024
References Cited (50)
US 9294497B1 · Ben-Or et al. · 2016 [cited by applicant]
US 9635049B1 · Oprea · 2017 [cited by examiner]
US 10021134B2 · Goutal · 2018 [cited by examiner]
US 10104029B1 · Chambers · 2018 [cited by examiner]
US 10154056B2 · Kennedy et al. · 2018 [cited by applicant]
US 10181957B2 · Srivastava · 2019 [cited by examiner]
US 10868825B1 · Dominessy et al. · 2020 [cited by applicant]
US 11063897B2 · Kessler et al. · 2021 [cited by applicant]
US 11178168B1 · Lin et al. · 2021 [cited by applicant]
US 11411990B2 · Pandey et al. · 2022 [cited by applicant]
US 20050204009A1 · Hazarika et al. · 2005 [cited by applicant]
US 20060168024A1 · Mehr et al. · 2006 [cited by applicant]
US 20060268024A1 · Youn · 2006 [cited by applicant]
US 20090122704A1 · DeVal et al. · 2009 [cited by applicant]
US 20090216842A1 · Risher et al. · 2009 [cited by applicant]
US 20100192224A1 · Ferri et al. · 2010 [cited by applicant]
US 20120174219A1 · Hernandez et al. · 2012 [cited by applicant]
US 20130333026A1 · Starink et al. · 2013 [cited by applicant]
US 20160094566A1 · Parekh · 2016 [cited by applicant]
US 20160330219A1 · Hasan · 2016 [cited by applicant]
US 20180013790A1 · Xavier et al. · 2018 [cited by applicant]
US 20180103047A1 · Turgeman · 2018 [cited by examiner]
US 20180152471A1 · Jakobsson · 2018 [cited by examiner]
US 20180288078A1 · Balasundaram · 2018 [cited by examiner]
US 20190312729A1 · Sachtjen et al. · 2019 [cited by applicant]
US 20200410894A1 · May et al. · 2020 [cited by applicant]
US 20210185075A1 · Adams · 2021 [cited by applicant]
Suman Patro, Comparative study of middleware solutions for control and monitoring systems, Nov. 23, 2017 (Year: 2017). [cited by examiner]
Jan. 25, 2024—(US) Notice of Allowance—U.S. Appl. No. 18/213,323. [cited by applicant]
Feng, Yu, et al. “Automated systhesis of semantic malware signatures using maximum satisfiability.” arXiv preprint arXiv: 1608.06254 (2016). [cited by applicant]
Arora, Anshul and Sateesh K. Peddoju. “Minimizing network traffice features for android mobile malware detection.” Proceedings of the 18th international conference on distributed computing and networking, 2017. [cited by applicant]
Feb. 16, 2024—(US) Final Office Action—U.S. Appl. No. 17/199,964. [cited by applicant]
May 10, 2021 (EP) Extended European Search Report—U.S. Appl. No. 20/213,925. [cited by applicant]
May 6, 2021 (EP) Extended European Search Report—App. 20213921.8. [cited by applicant]
May 7, 2021 (EP) Extended European Search Report—App. 20213922.6. [cited by applicant]
Aug. 2, 2022—(US) Non-Final Office Action—U.S. Appl. No. 17/016,980. [cited by applicant]
Apr. 11, 2023—(EP) Office Action—App 20213921.8. [cited by applicant]
Apr. 11, 2023—(EP) Office Action—App 20213922.6. [cited by applicant]
Apr. 12, 2023—(EP) Office Action—App 20213925.9. [cited by applicant]
Jul. 19, 2023—(US) Non-Final Office Action—U.S. Appl. No. 17/119,964. [cited by applicant]
Mar. 23, 2023—(US) Notice of Allowance—U.S. Appl. No. 17/016,819. [cited by applicant]
Alsubhi et al., “Alert Prioritization in Intrusion Detection Systems”, NOMS 2008-2008 IEEE Network Operations and Management Symposium. IEEE, 2008 (Year: 2008). [cited by applicant]
Antonakakis, et al. “Detecting Malware Domains at the Upper DNS Hierarchy” USENIX Security Symposium, vol. 11.2011. (Year: 2011). [cited by applicant]
Rsa: “How the Libraesva URLSand sandboxing service works”, Sep. 15, 2016, pp. 1-9, XP093036672, Retrieved from the Internet: URL:https://docs.libraesva.com/knowledgebase/how-the-esva-uri-sandboxing-service-works/ [retri… [cited by applicant]
Jun. 6, 2024—(US) Office Action—U.S. Appl. No. 17/119,964. [cited by applicant]
Charles Reis et al. “Site Isolation: Process Separation for Web Sites within the Browser” Usenix The Advanced Computing Systems Association, https://www.usenix.org/conference/usenixsecurity19/presentation/reis, Aug. 14-… [cited by applicant]
Jan. 10, 2025—(US) Notice of Allowance—U.S. Appl. No. 17/119,964. [cited by applicant]
Jul. 24, 2025—(EP) Summons to Attend Oral Proceedings—App 20213921.8. [cited by applicant]
Jul. 24, 2024—(EP) Summons to Attend Oral Proceedings—App 20213922.6. [cited by applicant]
Jan. 2, 2026—(EP) Decision to Refuse—App 20213921.8. [cited by applicant]