Invention Grant
- Patent Title: Detecting of business email compromise
-
Application No.: US16917197Application Date: 2020-06-30
-
Publication No.: US11595336B2Publication Date: 2023-02-28
- Inventor: Bjorn Markus Jakobsson
- Applicant: ZapFraud, Inc.
- Applicant Address: US CA Portola Valley
- Assignee: ZapFraud, Inc.
- Current Assignee: ZapFraud, Inc.
- Current Assignee Address: US CA Portola Valley
- Agency: Schwabe, Williamson & Wyatt, PC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L51/00 ; H04L9/40 ; H04L51/48 ; H04L51/58

Abstract:
A system for detection of email risk automatically determines that a first party is considered by the system to be trusted by a second party, based on at least one of determining that the first party is on a whitelist and that the first party is in an address book associated with the second party. A message addressed to the second party from a third party is received. A risk determination of the message is performed by determining whether the message comprises a hyperlink and by determining whether a display name of the first party and a display name of third party are the same or that a domain name of the first party and a domain name of the third party are similar, wherein similarity is determined based on having a string distance below a first threshold or being conceptually similar based on a list of conceptually similar character strings. Responsive to determining that the message poses a risk, a security action is automatically performed comprising at least one of marking the message up with a warning, quarantining the message, performing a report generating action comprising including information about the message in a report accessible to an admin of the system, and replacing the hyperlink in the message with a proxy hyperlink.
Public/Granted literature
- US20200336451A1 DETECTING OF BUSINESS EMAIL COMPROMISE Public/Granted day:2020-10-22
Information query