US 12,081,503 B2
Determining authenticity of reported user action in cybersecurity risk assessment
Kurt Wescoe, Pittsburgh, PA (US); Trevor T. Hawthorn, Ashburn, VA (US); Alan Himler, Pittsburgh, PA (US); Patrick H. Veverka, Virginia Beach, VA (US); John T. Campbell, Bridgeville, PA (US); Dustin D. Brungart, Imperial, PA (US); and Norman Sadeh-Koniecpol, Pittsburgh, PA (US)
Assigned to Proofpoint, Inc., Sunnyvale, CA (US)
Filed by Proofpoint, Inc., Sunnyvale, CA (US)
Filed on Jul. 29, 2020, as Appl. No. 16/942,023.
Application 16/942,023 is a continuation of application No. 16/266,467, filed on Feb. 4, 2019, granted, now 10,778,626.
Application 16/266,467 is a continuation of application No. 15/607,071, filed on May 26, 2017, granted, now 10,243,904, issued on Mar. 26, 2019.
Prior Publication US 2021/0058354 A1, Feb. 25, 2021
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 51/212 (2022.01); G06F 21/56 (2013.01); H04L 9/40 (2022.01)
CPC H04L 51/212 (2022.05) [G06F 21/566 (2013.01); H04L 63/1433 (2013.01); G06F 21/562 (2013.01); H04L 63/14 (2013.01); H04L 63/1441 (2013.01)] 12 Claims
OG exemplary drawing
 
1. A method comprising:
at a device configured to provide an electronic message application for a first user, the device comprising at least one processor, a communication device, and memory:
receiving, via the communication device, a message addressed to the first user;
receiving, from the first user, a request to send the message to a second user;
prior to sending any message to the second user in response to the request, determining that the message is a simulated malicious message;
responsive to determining that the message is a simulated malicious message:
identifying, by the at least one processor, an actuatable element in the message, wherein the actuatable element comprises a uniform resource locator (URL);
modifying, by the at least one processor, the message by modifying the actuatable element within the message to include a user identifier of the first user and a user identifier of the second user, resulting in a modified message, wherein modifying the actuatable element within the message to include the user identifier of the first user and the user identifier of the second user includes inserting the user identifier of the first user and the user identifier of the second user into the URL; and
causing transmission of the modified message to the second user.