US 12,470,599 B2
Abuse mailbox for facilitating discovery, investigation, and analysis of email-based threats
Evan Reiser, San Francisco, CA (US); Jeremy Kao, San Francisco, CA (US); Cheng-Lin Yeh, San Francisco, CA (US); Yea So Jung, San Mateo, CA (US); Kai Jing Jiang, San Francisco, CA (US); Abhijit Bagri, San Francisco, CA (US); Su Li Debbie Tan, San Francisco, CA (US); Venkatram Krishnamoorthi, San Francisco, CA (US); and Fang Shuo Deng, San Francisco, CA (US)
Assigned to Abnormal AI, Inc., Las Vegas, NV (US)
Filed by Abnormal AI, Inc., Las Vegas, NV (US)
Filed on Feb. 15, 2024, as Appl. No. 18/443,055.
Application 18/443,055 is a continuation of application No. 17/550,848, filed on Dec. 14, 2021, granted, now 11,949,713.
Application 17/550,848 is a continuation of application No. 17/155,843, filed on Jan. 22, 2021, granted, now 11,252,189, issued on Feb. 15, 2022.
Claims priority of provisional application 62/984,098, filed on Mar. 2, 2020.
Prior Publication US 2024/0187450 A1, Jun. 6, 2024
Int. Cl. H04L 9/40 (2022.01); G06F 16/9035 (2019.01); G06Q 10/107 (2023.01)
CPC H04L 63/1483 (2013.01) [G06F 16/9035 (2019.01); G06Q 10/107 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method comprising:
determining that a first email is present in an abuse mailbox where emails of deemed suspicious are placed for analysis;
in response to determining that the first email is present in the abuse mailbox, determining whether the first email is representative of a threat to an enterprise based at least in part by applying a trained model to extract a plurality of characterizing features from the first email; and
in response to determining that the first email represents a threat to the enterprise:
generating a record of the threat by populating a data structure with the plurality of characterizing features determined from the first email, the plurality of characterizing features including at least an identified threat type and sender characteristics; and
applying the data structure including the characterizing features to inboxes of a plurality of employees of the enterprise by searching for other emails within the inboxes exhibiting a similarity to the characterizing features, thereby determining whether the first email is part of a campaign including the other emails, and in response to determining that the first email is part of the campaign, applying a filter derived from and associated with the data structure, the filter configured to identify matching emails exhibiting the characterizing features, to inbound emails addressed to employees of the enterprise.