The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Feb. 28, 2023

Filed:

Jun. 30, 2020
Applicant:

Zapfraud, Inc., Portola Valley, CA (US);

Inventor:

Bjorn Markus Jakobsson, Portola Valley, CA (US);

Assignee:

ZAPFRAUD, INC., Portola Valley, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 51/00 (2022.01); H04L 9/40 (2022.01); H04L 51/48 (2022.01); H04L 51/58 (2022.01);
U.S. Cl.
CPC ...
H04L 51/12 (2013.01); H04L 51/28 (2013.01); H04L 51/38 (2013.01); H04L 63/0227 (2013.01); H04L 63/08 (2013.01); H04L 63/083 (2013.01); H04L 63/145 (2013.01); H04L 63/1433 (2013.01); H04L 63/1483 (2013.01); H04L 2463/082 (2013.01);
Abstract

A system for detection of email risk automatically determines that a first party is considered by the system to be trusted by a second party, based on at least one of determining that the first party is on a whitelist and that the first party is in an address book associated with the second party. A message addressed to the second party from a third party is received. A risk determination of the message is performed by determining whether the message comprises a hyperlink and by determining whether a display name of the first party and a display name of third party are the same or that a domain name of the first party and a domain name of the third party are similar, wherein similarity is determined based on having a string distance below a first threshold or being conceptually similar based on a list of conceptually similar character strings. Responsive to determining that the message poses a risk, a security action is automatically performed comprising at least one of marking the message up with a warning, quarantining the message, performing a report generating action comprising including information about the message in a report accessible to an admin of the system, and replacing the hyperlink in the message with a proxy hyperlink.


Find Patent Forward Citations

Loading…