| CPC H04L 63/205 (2013.01) [H04L 63/102 (2013.01); H04L 63/1425 (2013.01); H04L 2463/082 (2013.01)] | 20 Claims |

|
1. A method for identifying and preventing suspicious activity occurring within a messaging software executed via an enterprise system, the method comprising:
detecting a current message sent from a particular user account of the messaging software executed via the enterprise system at a user computing device;
comparing the current message and user account activity associated with the current message with a behavior profile corresponding to the particular user account, wherein the behavior profile is generated based on prior user account activity that includes one or more prior messages sent from the particular user account via the enterprise system, wherein the prior user account activity occurs prior to the current message, and wherein the prior user account activity includes, relative to the one or more prior messages sent from the particular user account, textual analysis of language used in the prior messages and an analysis of characteristics associated with entry of the one or more prior messages into the enterprise system;
determining, based on the comparing and a set of predetermined risk levels, a risk level of the current message; and
performing, based on the determined risk level of the current message, one or more preventative actions with respect to the particular user account.
|