US 11,949,713 B2
Abuse mailbox for facilitating discovery, investigation, and analysis of email-based threats
Evan Reiser, San Francisco, CA (US); Jeremy Kao, San Francisco, CA (US); Cheng-Lin Yeh, San Francisco, CA (US); Yea So Jung, San Francisco, CA (US); Kai Jing Jiang, San Francisco, CA (US); Abhijit Bagri, San Francisco, CA (US); Su Li Debbie Tan, San Francisco, CA (US); Venkatram Kishnamoorthi, San Francisco, CA (US); and Feng Shuo Deng, San Francisco, CA (US)
Assigned to Abnormal Security Corporation, San Francisco, CA (US)
Filed by Abnormal Security Corporation, San Francisco, CA (US)
Filed on Dec. 14, 2021, as Appl. No. 17/550,848.
Application 17/550,848 is a continuation of application No. 17/155,843, filed on Jan. 22, 2021, granted, now 11,252,189.
Claims priority of provisional application 62/984,098, filed on Mar. 2, 2020.
Prior Publication US 2022/0255961 A1, Aug. 11, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/40 (2022.01); G06F 16/9035 (2019.01); G06Q 10/107 (2023.01)
CPC H04L 63/1483 (2013.01) [G06F 16/9035 (2019.01); G06Q 10/107 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01)] 42 Claims
OG exemplary drawing
 
1. A method comprising:
determining, via an application programming interface, that a first email is present in a mailbox to which employees of an enterprise are able to forward emails deemed suspicious for analysis, and in response to determining that the first email is present in the mailbox, determining whether the first email is representative of a threat to the enterprise based at least in part by applying a trained model to the first email; and
in response to establishing that the first email represents a threat to the enterprise:
generating a record of the threat by populating a data structure with information related to the first email; and
applying the data structure to inboxes of a plurality of the employees to determine whether the first email is part of a campaign, and in response to determining that the first email is part of a campaign, applying the data structure as a filter to inbound emails addressed to the employees.