DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Objections
Claims 1, 7, 8, 9, 12, 13, 14, 16, 17, 19, and 20 are objected to because of the following informalities: “sequence of… words” and “sequence of words” . Examiner suggests changing sequence of words to sequence of language signals because it will make logically more cohesive. Within the specifications and claims language signals and words seem to be synonymous to each other, so to avoid confusion there should be only one terms that should be referring to the linguistics of the email. Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claim 1-20 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Regarding claims 1 and 12:
“scanning a body of inbound email for language signals, in a set of language signals, associated with fraudulent email attempts” is recited in claims 1 and 12, and “scanning a body of the first inbound email for language signals in a set of language signals” in claim 16. The specification fails to demonstrate that the applicant possessed the steps of scanning a body of an email for “language signals” in response to detecting a first external document. The specification mentions generalized language analysis models and example techniques, but does not disclose a sufficiently specific algorithm, procedure, or ordered method for performing the claimed scanning and correlation-based withholding as recited. Although the term “language analysis model” might be read broadly to include machine learning models, that reading is at best a long shot and is not clearly supported by the specification. And even if one were to assume a machine learning implementation, the specification still does not disclose any particular known technique, such as a classifier, neural network, support vector machine, decision tree, embedding model, transformer, hidden Markov model, topic model implementation, or any other concrete training or inference methodology. In addition, the specification does refer to Figure 8 as additional support for such limitations, but steps do not include the body of the email being scanned for language signals. Figure 8 instead disclose in response in detecting external content in email (S130) the email scans the external document for language signal (S122). The specifications do not disclose the scanning of an email body in response to the external document being detected. In the end, the specification must disclose the computer and the algorithm, steps, or procedure for performing the claimed function in sufficient detail to show possession of that functionality. See Ariad Pharm., Inc. v. Eli Lilly & Co., 598 F.3d 1336, 1351 (Fed. Cir. 2010); LizardTech, Inc. v. Earth Res. Mapping, Inc., 424 F.3d 1336, 1345-46 (Fed. Cir. 2005); Vasudevan Software, Inc. v. MicroStrategy, Inc., 782 F.3d 671, 681-83 (Fed. Cir. 2015); Finisar Corp. v. DirecTV Grp., 523 F.3d 1323, 1340 (Fed. Cir. 2008).
Regarding claims 1, 12, and 16:
“a set of verified email addresses associated with authentic email attempts within an organization” is recited in claims 1, 12, and 16, but the specification does not describe what constitutes as “authentic” for an email attempt. The specification fails to demonstrate that the applicant possessed the step of making the determination by the prediction unit whether the storage operation is indicative of a malicious enumeration. As explained in MPEP §2161.01, the written description requirement is separate and distinct from enablement, and requires that the specification describe the claimed invention in sufficient detail that one of ordinary skill in the art can reasonably conclude that the inventor had possession of the claimed invention at the time of filing. This requirement applies to computer-implemented inventions recited in functional terms, and simply restating the claimed function or a desired result is not sufficient. There is no definition, no rule, and no algorithm within the specification disclosed for how an authentic email attempt is determined based on previous email attempts or how an authentic email attempt is classified.
Regarding claim 7:
“accessing a set of verified addresses associated with authentic audio message attempts within the organization” is recited in claim 7, but the specification does not describe what constitutes as “authentic” for an audio message attempt. The specification fails to demonstrate that the applicant possessed the step of making the determination by the prediction unit whether the storage operation is indicative of a malicious enumeration. As explained in MPEP §2161.01, the written description requirement is separate and distinct from enablement, and requires that the specification describe the claimed invention in sufficient detail that one of ordinary skill in the art can reasonably conclude that the inventor had possession of the claimed invention at the time of filing. This requirement applies to computer-implemented inventions recited in functional terms, and simply restating the claimed function or a desired result is not sufficient. There is no definition, no rule, and no algorithm within the specification disclosed for how an authentic audio message attempt is determined based on previous audio message attempts or how an audio message attempt is classified.
Regarding claims 9, 12, 14, 16, 17, 18, 19, and 20:
“…calculating…risk score…” is recited in claims 1, 12, and 16. The specification fails
to demonstrate that the applicant possessed the step of calculating a risk score. As explained in MPEP §2161.01, the written description requirement is separate and distinct from enablement, and requires that the specification describe the claimed invention in sufficient detail that one of ordinary skill in the art can reasonably conclude that the inventor had possession of the claimed invention at the time of filing. This requirement applies to computer-implemented inventions recited in functional terms, and simply restating the claimed function or a desired result is not sufficient. The specification must disclose the computer and the algorithm, steps, or procedure for performing the claimed function in sufficient detail to show possession of that functionality. See Ariad Pharm., Inc. v. Eli Lilly & Co., 598 F.3d 1336, 1351 (Fed. Cir. 2010); LizardTech, Inc. v. Earth Res. Mapping, Inc., 424 F.3d 1336, 1345-46 (Fed. Cir. 2005); Vasudevan Software, Inc. v. MicroStrategy, Inc., 782 F.3d 671, 681-83 (Fed. Cir. 2015); Finisar Corp. v. DirecTV Grp., Inc., 523 F.3d 1323, 1340 (Fed. Cir. 2008). The specification does identify some inputs and clues. It says the risk score is represented by a percentage and from a correlation between words. Those paragraphs support that the risk score is being calculated, but the specification does not disclose the possession of how the risk score is being calculated from the correlations of language signals .Under MPEP §2161.01 and the cited case law, identifying relevant inputs or factors does not by itself provide adequate written description support for a functionally claimed determination unless the specification also explains how those factors are actually used to perform the determination.
Claims 2-11, 13-15, and 17-20 do not overcome the rejections of their respective base claims that have been rejected above, and therefore rejected under the same grounds provided to claims 1, 12, and 16.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1-20 are rejected under 35 U.S.C. § 112(b) as being indefinite because the claims recite “language signals” without defining the term with objective metes and bounds such that a person having ordinary skill in the art would be able to determine the scope of the claims with reasonable certainty. The specification does not provide a clear definition of “language signals,” but instead describes the term using open-ended examples and subjective categories. For example, paragraph 62 states that “language signals” may include keywords, such as “invoice,” “payment,” “transaction,” and “urgent,” or “content associated with spoofing attempts,” but the specification does not explain what all is included within “content associated with spoofing attempts” or where the boundaries of that category begin and end. Paragraph 66 further refers to “financial language signals,” “action language signals,” and “urgency language signals,” but does not provide objective criteria for determining what makes a particular word, phrase, tone, or cue a financial language signal, an action language signal, or an urgency language signal, or how a person having ordinary skill in the art would distinguish between those categories. Paragraph 67 also describes “language signals” as indicating “a tone and/or a linguistic cue typical of phishing (and/or spoofing) attempts,” and gives an example of detecting a sequence of words, such as “You need to buy,” and calculating a correlation between that sequence of words and a language signal, such as “need” or “to buy.” However, the specification does not explain how the claimed correlation is calculated, what metric or model is used, what degree of similarity is required, or what objective standard determines when a sequence of words corresponds to a “language signal.” Accordingly, the term “language signals” is broad, subjective, and dependent on undefined categories of spoofing-related content, tone, linguistic cues, and correlations, such that a person having ordinary skill in the art would not be able to determine what is included within the term or the scope of the claims with reasonable certainty.
Claim 3 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being incomplete for omitting essential steps, such omission amounting to a gap between the steps. See MPEP § 2172.01.
Claim 3 recites the steps of, “…scanning the first inbound email for presence of hyperlinks within the second inbound email; and in response to detecting a second link to a second external document within the first inbound email…” The omitted step is scanning of a second link to a second external document.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Hassanzadeh et al. (US PGPub No.20210352093-A1) and Leddy et al. (US PGPub No. 20200067861-A1).
With respect to claim 1, Marino teaches a method comprising: intercepting a first inbound email received from a first sender at a first inbound email address and addressed to a first recipient associated with an organization; (¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
accessing a whitelist associated with the organization and comprising a set of verified email addresses associated with authentic email attempts within the organization; and (¶0136: The continuation of the first phase of the process shown in Figure 5A is illustrated in Figure 5B. If, no virus is found or if the message may contain encrypted attachments, the operations of the system proceeds to step 513, whereupon the sender of the message, which is identified in the corresponding “From” record, is compared with entries in the whitelist table. This table contains a list of sender email addresses from which email correspondence should be allowed without further inspection. );
in response to the set of verified email addresses omitting the first inbound email address: scanning the first inbound email for presence of external content linked to the first inbound email; and in response to detecting a first link to a first external document within the first inbound email: (¶0138: On the other hand, if the message sender email address does not match any entries in the whitelist, the system checks the recipient of the email message identified does not match any entries in the whitelist, the system checks the recipient of the email message identified in the “To” field of the message header against entries in the parental control profile. If no matching entries in the parental control profile exist, the system proceeds with step 516, whereupon the identity fraud analysis algorithm inspects the header of the email message for possible phishing scam (omitting the first inbound email address) . Upon passing of the phishing scam inspection, the message header pattern is analyzed at step 517 for SPAM content. If SPAM is not detected in the header, at step 518, the system checks whether the message header indicates presence of encrypted email message. The encrypted content is indicated, for example, by presence of "Content-Type: application/x-pkcs7-mime" record in the header of the email (scanning presence of external content linked to the first inbound email) . If the content is not encrypted, the system inspects the body of the message for SPAM content at step 519. If the content is not encrypted, the system inspects the body of the message for SPAM content at 519 (in response to detecting a first link to a first external document within inbound email). );
Marino does not disclose:
scanning a body of the first inbound email for language signals, in a set of language signals, associated with fraudulent email attempts; and in response to detecting a correlation between a first sequence of words, in the body of the first inbound email, with a first language signal in the set of language signals, withholding transmission of the first inbound email to the first recipient.
It is noted that Marino disclose the scanning the body of the email in response to an external link, but does not Marino do not explicitly disclose scanning a body of the first inbound email for language signals. However, Hassanzadeh teaches scanning a body of the first inbound email for language signals, in a set of language signals, associated with fraudulent email attempts; (¶0055-0058: To extract the relevant features of the model 540, at least a portion of the e-mail may be processed by input processing logic 510 of the model processor 500. The input processing logic 510 may be configured to condition at least the portion of the e-mail for analysis by feature extraction logic 520. In aspect, the input processing logic 510 may perform natural language processing (NLP) on text data included in the e-mail 400, such as the body portion 420. Based on the NLP processing, the body portion 420 of the e-mail 400 may be transformed into a list of words in a standardized format that may be analyzed by the feature extraction logic 520 (scanning a body of the email for language signals). The candidate features derived from the body portion 420 may be provided to the feature processing logic 530 where the candidate features may be analyzed and used to update values within the model 540. For example, the feature processing logic 530 may analyze the candidate features derived from the body portion 420 to determine whether any keywords associated with malicious e-mails are present (set of language signals associated with fraudulent email). );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Hassanzadeh with regards to scanning the body of an email for language signals, in a set of language signals, associated with fraudulence to the method of Marino in order to better detect and mitigate malicious e-mails (Hassanzadeh: ¶0004-0005)
Marino in view of Hassanzadeh does not disclose:
and in response to detecting a correlation between a first sequence of words, in the body of the first inbound email, with a first language signal in the set of language signals, withholding transmission of the first inbound email to the first recipient.
It is noted that Hassanzadeh does discloses the correlate the first sequence of words in the body first inbound email, with the first language signal in set of language signals, as seen in ¶0055-0058, but Hassanzadeh does not disclose the withholding transmission of the first inbound email to the first recipient. However, Leddy teaches and in response to detecting a correlation between a first sequence of words, in the body of the first inbound email, with a first language signal in the set of language signals, withholding transmission of the first inbound email to the first recipient. (¶0132: By detecting that the email comes from an untrusted sender (i.e., not from a friend); that the sender address is deceptive (e.g., it is a close match with a party who is trusted by the recipient); and that the subject line, email body, or an attachment contain high-risk keywords or a storyline known to correspond to scam—by detecting such a combination of properties, it is determined that this email is high-risk, and should not be delivered, or should be marked up, quarantined, or otherwise processed in a way that limits the risk associated with the email.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Leddy with regards to withholding transmission of the first inbound email to the first recipient in response to the correlation of words to the method of Marino in view of Hassanzadeh in order to better detect business email compromise attack (Leddy: ¶0132).
With respect to claim 11, the combination of Marino in view of Hassanzadeh and Leddy teaches the method of claim 1 (see the rejection of claim 1), further comprising intercepting a second inbound email received from a second sender at a second inbound email address and addressed to a second recipient; and (Marino ¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
in response to the set of verified email addresses omitting the second inbound email address: scanning the second inbound email for presence of external content linked to the second inbound email; and in response to detecting a second link within the second inbound email: (Marino ¶0138: On the other hand, if the message sender email address does not match any entries in the whitelist, the system checks the recipient of the email message identified does not match any entries in the whitelist, the system checks the recipient of the email message identified in the “To” field of the message header against entries in the parental control profile. If no matching entries in the parental control profile exist, the system proceeds with step 516, whereupon the identity fraud analysis algorithm inspects the header of the email message for possible phishing scam (omitting the first inbound email address) . Upon passing of the phishing scam inspection, the message header pattern is analyzed at step 517 for SPAM content. If SPAM is not detected in the header, at step 518, the system checks whether the message header indicates presence of encrypted email message. The encrypted content is indicated, for example, by presence of "Content-Type: application/x-pkcs7-mime" record in the header of the email (scanning presence of external content linked to the first inbound email) . If the content is not encrypted, the system inspects the body of the message for SPAM content at step 519. If the content is not encrypted, the system inspects the body of the message for SPAM content at 519 (in response to detecting a first link to a first external document within inbound email). );
scanning a second body of the second inbound email for language signals in the set of language signals associated with fraudulent email attempts; and (Hassanzadeh ¶0055-0058: To extract the relevant features of the model 540, at least a portion of the e-mail may be processed by input processing logic 510 of the model processor 500. The input processing logic 510 may be configured to condition at least the portion of the e-mail for analysis by feature extraction logic 520. In aspect, the input processing logic 510 may perform natural language processing (NLP) on text data included in the e-mail 400, such as the body portion 420. Based on the NLP processing, the body portion 420 of the e-mail 400 may be transformed into a list of words in a standardized format that may be analyzed by the feature extraction logic 520 (scanning a body of the email for language signals). The candidate features derived from the body portion 420 may be provided to the feature processing logic 530 where the candidate features may be analyzed and used to update values within the model 540. For example, the feature processing logic 530 may analyze the candidate features derived from the body portion 420 to determine whether any keywords associated with malicious e-mails are present (set of language signals associated with fraudulent email). );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Hassanzadeh with regards to scanning the body of an email for language signals, in a set of language signals, associated with fraudulence to the method of Marino in view of Leddy in order to better detect and mitigate malicious e-mails (Hassanzadeh: ¶0004-0005).
in response to detecting absence of a second correlation between sequences of words in the second body of the second inbound email with language signals in the set of language signals, passing the second inbound email to the second recipient. (Leddy ¶0132: By detecting that the email comes from an untrusted sender (i.e., not from a friend); that the sender address is deceptive (e.g., it is a close match with a party who is trusted by the recipient); and that the subject line, email body, or an attachment contain high-risk keywords or a storyline known to correspond to scam—by detecting such a combination of properties, it is determined that this email is high-risk, and should not be delivered, or should be marked up, quarantined, or otherwise processed in a way that limits the risk associated with the email (implying that if there are no high-risk words transmission would be allowed). In ¶0086-0087 shows the parts of filtering an email wherein b. If no to (2), then does the email have high-risk content (an attachment, presence of high-risk key-words, etc.)? If yes to (2b), then perform in-depth filtering to it as described below, and perform a conditional action. (which implies there is no more further analysis actions being performing therefore implying the email has been passed to the recipient) );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Leddy with regards to allowing the email pass if there was an absence of high risk words to the method of Marino in view of Hassanzadeh in order to better detect business email compromise attack (Leddy: ¶0132).
Claim 2 is rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Hassanzadeh et al. (US PGPub No.20210352093-A1), Leddy et al. (US PGPub No. 20200067861-A1), and Loughmiller et a. (US Pat No.7257564-B2).
With respect to claim 2, the combination of Marino in view of Hassanzadeh and Leddy teaches method of claim 1 (see rejection of claim 1 above) further comprising accessing a blacklist associated with the organization and comprising a first set of flagged email addresses associated with fraudulent email attempts; (Marino ¶0136: Upon the retrieval of the message, the system first checks if the sender of the message identified in the "From" field thereof matches an existing entry in the blacklist table. This table lists all senders, the email correspondence from which should be blocked. If the match in the blacklist table is found, the corresponding email message is blocked at step 521. );
wherein scanning the first inbound email for presence of external content linked to the first inbound email comprises scanning the first inbound email for presence of external content linked to the first inbound email in response to the first set of flagged email addresses omitting the first inbound email address; and (Marino ¶0136: As further seen in Figure 5B, wherein header e-mail address/domain has “NO” existent entry in the blacklist text file moves on to step 512. At step 512, the appliance checks whether the content of the message, as described by “Content -Type” field of the message header, may include encrypted attachments (scanning for presence of external content linked to the first inbound email). );
further comprising, in response to withholding transmission of the first inbound email to the first recipient based on the correlation between the first sequence of words, in the body of the first inbound email, with the first language signal in the set of language signals, (Leddy ¶0132: By detecting that the email comes from an untrusted sender (i.e., not from a friend); that the sender address is deceptive (e.g., it is a close match with a party who is trusted by the recipient); and that the subject line, email body, or an attachment contain high-risk keywords or a storyline known to correspond to scam—by detecting such a combination of properties, it is determined that this email is high-risk, and should not be delivered, or should be marked up, quarantined, or otherwise processed in a way that limits the risk associated with the email.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Leddy with regards to withholding transmission of the first inbound email to the first recipient in response to the correlation of words to the method of Marino in view of Hassanzadeh in order to better detect business email compromise attack (Leddy: ¶0132).
Marino in view of Hassanzadeh and Leddy does not disclose:
updating the blacklist to include the first sender and the first inbound email address.
It is noted that Marino in view of Hassanzadeh and Leddy does disclose a blacklist and withholding transmission of an email in response to the correlation of words. However, Longhmiller teaches updating the blacklist to include the first sender and the first inbound email address. (¶0070: In one embodiment, the whitelists and blacklists can be dynamically maintained based on the classification of messages associated with those identifiers. Likewise, any sender for whom at least a threshold number (preferably four) of messages are rejected as spam can be automatically added to the blacklist of known spammers, so that messages from those senders need not to be checked as through as from);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Loughmiller with regards to updating the blacklist to the method of Marino in view of Hassanzadeh and Leddy in order to reduces the number of messages erroneously identified as spam and enable for faster execution (Loughmiller: ¶0012-0013)
Claims 3, 4, 9, and 10 are rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Hassanzadeh et al. (US PGPub No.20210352093-A1), Leddy et al. (US PGPub No. 20200067861-A1), and Srivastava et a. (US PGPub No. 20160012223-A1).
With respect to claim 3, the combination of Marino in view of Hassanzadeh and Leddy teaches method of claim 1 (see rejection of claim 1 above) further comprising: intercepting a second inbound email received from a second sender at a second inbound email address and addressed to a second recipient associated with the organization; and (¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
in response to the set of verified email addresses omitting the second inbound email address: (¶0138: On the other hand, if the message sender email address does not match any entries in the whitelist, the system checks the recipient of the email message identified does not match any entries in the whitelist, the system checks the recipient of the email message identified in the “To” field of the message header against entries in the parental control profile. If no matching entries in the parental control profile exist, the system proceeds with step 516, whereupon the identity fraud analysis algorithm inspects the header of the email message for possible phishing scam. Upon passing of the phishing scam inspection, the message header pattern is analyzed at step 517 for SPAM content. If SPAM is not detected in the header, at step 518, the system checks whether the message header indicates presence of encrypted email message. The encrypted content is indicated, for example, by presence of "Content-Type: application/x-pkcs7-mime" record in the header of the email (scanning presence of external content linked to the first inbound email) . If the content is not encrypted, the system inspects the body of the message for SPAM content at step 519. If the content is not encrypted, the system inspects the body of the message for SPAM content at 519 (in response to detecting a first link to a first external document within inbound email). );
Marino in view of Hassanzadeh and Leddy but does not disclose:
scanning the first inbound email for presence of hyperlinks within the second inbound email; and in response to detecting a second link to a second external document within the first inbound email: scanning the second external document for presence of malicious content; and
in response to detecting malicious content in the second external document, withholding transmission of the second inbound email to the second recipient.
However, Srivastava teaches scanning the first inbound email for presence of hyperlinks within the second inbound email; and in response to detecting a second link to a second external document within the first inbound email: (¶0074-0075: Device 630 analyzes the content 610 of email 600 for both semantic and non-semantic data. In some embodiments, “non-semantic data” may be data that can be easily harvested from the content of an email and compared with identification information—for example, URLs (detecting hyperlinks) , domain names, IP addresses, email addresses, etc.—to obtain accurate, objective comparisons or matches with previously archived identification information.);
scanning the second external document for presence of malicious content; and (¶0062: Figure 2, is an exemplary flow schematic illustrating a process for performing routine collection of information associated with suspect activity, as further depicted in Figures 3 and 4. In step 210, a collection process accesses an initial webpage, such as through a standard HTTP request, and downloads its content for analysis.);
in response to detecting malicious content in the second external document, (¶0066: In step 220, the downloaded webpage content is analyzed, either by the process that collected the data or by another process, such as a process devoted entirely to content analysis. The webpage content is analyzed for indications of potential malicious activity.);
withholding transmission of the second inbound email to the second recipient. (¶0073-0088: As further depicted in Figure 5 and 6, the information collection in Figures 2-4 (detecting malicious content in second external document) may then be used to proactively identify and guard against social engineering attacks, such as “phishing” email attempts. After analyzing all non-semantic data, for example by querying against database 640 and by using behavioral analysis, one or more numerical or other kinds of scores may be generated to determine whether a sufficient threshold has been met to consider the email malicious in nature (step 540). If the email's non-semantic score meets or exceeds a threshold score, the email may be flagged as potentially suspect, quarantined, and forwarded for analysis (step 580) (detecting malicious content in the document contributed to withholding transmission of the email ) .);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Srivastava with regards to scanning the presence of hyperlinks and in response to detecting a second to a second external document to the method of Marino in view of Hassanzadeh and Leddy in order to better detect phishing and bad actors attempts against the user/client (Srivastava: ¶0002-0005)
With respect to claim 4, the combination of Marino in view of Hassanzadeh, Leddy, and Srivastava teaches method of claim 3 (see rejection of claim 3 above) wherein scanning the second external document for presence of malicious content comprises: scanning the second external document for presence of a third external document linked to the second external document; and (¶0070: In step 250, the web page 310 may be further analyzed to obtain links to other web pages (third external linked to the second external document), websites, objects, domains, servers, or other resources for potential malicious activity. “Links” may include, for example, hyperlinks, URLs, and any other information that may be used to identify additional data or items in a network for analysis.
in response to detecting presence of the third external document, scanning the third external document for presence of malicious content; and (¶0071:As seen in Figure 3 the web page 310 (second external document) displays several hyperlinks 311-314, from which additional URLs 320, 330, and 340 may be gleaned. HTTP requests may be made to each such URL to analyze the content of each associated website. URL 320, in particular, links to an executable program file 450. Executable program file 450 may be downloaded and analyzed to determine whether it contains any malware or similar malicious characteristics (scanning the third external document for presence of malicious content).);
wherein withholding transmission of the second inbound email to the second recipient comprises withholding transmission of the second inbound email to the second recipient in response to detecting malicious content in the third external document. (¶0073-0088: As further depicted in Figure 5 and 6, the information collection in Figures 2-4 (detecting malicious content in second external document and third external document) may then be used to proactively identify and guard against social engineering attacks, such as “phishing” email attempts. After analyzing all non-semantic data, for example by querying against database 640 and by using behavioral analysis, one or more numerical or other kinds of scores may be generated to determine whether a sufficient threshold has been met to consider the email malicious in nature (step 540). If the email's non-semantic score meets or exceeds a threshold score, the email may be flagged as potentially suspect, quarantined, and forwarded for analysis (step 580) (detecting malicious content in the document contributed to withholding transmission of the email ) .);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Srivastava with regards to scanning the second external document for a third external document to the method of Marino in view of Hassanzadeh and Leddy in order to better detect phishing and bad actors attempts against the user/client (Srivastava: ¶0002-0005).
Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Hassanzadeh et al. (US PGPub No.20210352093-A1), Leddy et al. (US PGPub No. 20200067861-A1), and Hazony et a. (US PGPub No. 20210240836-A1).
With respect to claim 5, the combination of Marino in view of Hassanzadeh and Leddy teaches the method of claim 1 (see the rejection of claim 1) but does not disclose wherein scanning the first inbound email for presence of external content linked to the first inbound email comprises scanning the first inbound email for presence of attachments; and further comprising, in response to detecting the first link to the first external document comprising a first attachment within the first inbound email: scanning the first attachment for presence of malicious content; scanning the first attachment for language signals in the set of language signals; and in response to detecting a second language signal, in the set of language signals, in the first attachment, withholding transmission of the first inbound email to the first recipient.
However, Hazony teaches wherein scanning the first inbound email for presence of external content linked to the first inbound email comprises scanning the first inbound email for presence of attachments; and (¶0036: Figure 2, illustrates a system 200 may include a user device 210 that includes a correspondence analysis unit (CAU) 211 and a correspondence processing and presentation unit (CPPU) 212. Other metrics or aspects indicated in metrices and weights 232 may related to content in messages e.g., whether an attachment is being sent with an email message and if so the type attachment. );
further comprising, in response to detecting the first link to the first external document comprising a first attachment within the first inbound email: (¶0036: Specifically, CAU 211 or CSU 221 may analyze content of each specific attachment e.g., based on the type of the attachment, for example, text (e.g., in Word document documents) is analyzed. );
scanning the first attachment for presence of malicious content; (¶0036: Specifically, CAU 211 or CSU 221 may analyze content of each specific attachment e.g., based on the type of the attachment, for example, text (e.g., in Word document documents) is analyzed. );
scanning the first attachment for language signals in the set of language signals; and (¶0036: Rules, criteria or threshold may be used for analysis and scoring of content, e.g., finding of identifying specific words, phrases or language in content causes CAU 211 or CSU 221to score messages according to rules, criteria or thresholds in metrics and weights 232 (scanning the first attachment for language signals in the set of language signals) .);
in response to detecting a second language signal, in the set of language signals, in the first attachment, withholding transmission of the first inbound email to the first recipient. (¶0050: An automatic action may be based on a group, for example, bot 222 can block (withholding transmission) specific mail based on a group, an event and/or a specific content, e.g., upon being alerted that malicious content was found in a Word document (e.g., from one of CAU 211 (¶0035) or from an AV unit) (withholding transmission based on detecting second language signals ) , bot 222 blocks correspondence between users who typically exchange Word documents based on a group of such users.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Hazony with regards toto scanning an attachment for malicious content to the method of Marino in view of Hassanzadeh and Leddy in order to better identify undesirable correspondence and prevent phishing/attacker attempts to obtain sensitive data via computer system (Hazony: ¶0002-0007 & ¶0022).
With respect to claim 9, the combination of Marino in view of Hassanzadeh and Leddy teaches the method of claim 1 (see the rejection of claim 1), wherein withholding transmission of the first inbound email to the first recipient in response to detecting the correlation between the first sequence of words with the first language signal further comprises, (Leddy ¶0132: By detecting that the email comes from an untrusted sender (i.e., not from a friend); that the sender address is deceptive (e.g., it is a close match with a party who is trusted by the recipient); and that the subject line, email body, or an attachment contain high-risk keywords or a storyline known to correspond to scam—by detecting such a combination of properties, it is determined that this email is high-risk, and should not be delivered, or should be marked up, quarantined, or otherwise processed in a way that limits the risk associated with the email.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Leddy with regards to withholding transmission of the first inbound email to the first recipient in response to the correlation of words to the method of Marino in view of Hassanzadeh in order to better detect business email compromise attack (Leddy: ¶0132).
further comprising: intercepting a second inbound email received from a second sender at a second inbound email address and addressed to a second recipient; and( Marino ¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
in response to the set of verified email addresses omitting the second inbound email address: scanning the second inbound email for presence of external content linked to the second inbound email; and in response to detecting a second link to a second external document within the second inbound email: (Marino ¶0138: On the other hand, if the message sender email address does not match any entries in the whitelist, the system checks the recipient of the email message identified does not match any entries in the whitelist, the system checks the recipient of the email message identified in the “To” field of the message header against entries in the parental control profile. If no matching entries in the parental control profile exist, the system proceeds with step 516, whereupon the identity fraud analysis algorithm inspects the header of the email message for possible phishing scam (omitting the first inbound email address) . Upon passing of the phishing scam inspection, the message header pattern is analyzed at step 517 for SPAM content. If SPAM is not detected in the header, at step 518, the system checks whether the message header indicates presence of encrypted email message. The encrypted content is indicated, for example, by presence of "Content-Type: application/x-pkcs7-mime" record in the header of the email (scanning presence of external content linked to the first inbound email) . If the content is not encrypted, the system inspects the body of the message for SPAM content at step 519. If the content is not encrypted, the system inspects the body of the message for SPAM content at 519 (in response to detecting a first link to a first external document within inbound email). );
scanning a second body of the second inbound email for language signals in the set of language signals associated with fraudulent email attempts; (Hassanzadeh ¶0055-0058: To extract the relevant features of the model 540, at least a portion of the e-mail may be processed by input processing logic 510 of the model processor 500. The input processing logic 510 may be configured to condition at least the portion of the e-mail for analysis by feature extraction logic 520. In aspect, the input processing logic 510 may perform natural language processing (NLP) on text data included in the e-mail 400, such as the body portion 420. Based on the NLP processing, the body portion 420 of the e-mail 400 may be transformed into a list of words in a standardized format that may be analyzed by the feature extraction logic 520 (scanning a body of the email for language signals). The candidate features derived from the body portion 420 may be provided to the feature processing logic 530 where the candidate features may be analyzed and used to update values within the model 540. For example, the feature processing logic 530 may analyze the candidate features derived from the body portion 420 to determine whether any keywords associated with malicious e-mails are present (set of language signals associated with fraudulent email). );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Hassanzadeh with regards to scanning the body of an email for language signals, in a set of language signals, associated with fraudulence to the method of Marino in view of Leddy in order to better detect and mitigate malicious e-mails (Hassanzadeh: ¶0004-0005).
detecting a second correlation between a second sequence of words, in the second body of the second inbound email, with a second language signal in the set of language signals, (Leddy ¶0132: By detecting that the email comes from an untrusted sender (i.e., not from a friend); that the sender address is deceptive (e.g., it is a close match with a party who is trusted by the recipient); and that the subject line, email body, or an attachment contain high-risk keywords or a storyline known to correspond to scam—by detecting such a combination of properties, it is determined that this email is high-risk, and should not be delivered, or should be marked up, quarantined, or otherwise processed in a way that limits the risk associated with the email.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Leddy with regards to withholding transmission of the first inbound email to the first recipient in response to the correlation of words to the method of Marino in view of Hassanzadeh in order to better detect business email compromise attack (Leddy: ¶0132).
Marino in view of Hassanzadeh and Leddy does not disclose:
in response to detecting the correlation between the first sequence of words with the first language signal: calculating a first risk score for the first inbound email based on the correlation and the first external document; and
in response to the first risk score for the first inbound email exceeding a threshold score, withholding transmission of the first inbound email to the first recipient; and
calculating a second risk score for the second inbound email based on the second correlation and the second external document; and
in response to the second risk score for the second inbound email falling below the threshold score, passing the second inbound email to the second recipient.
However, Srivastava teaches in response to detecting the correlation between the first sequence of words with the first language signal: calculating a first risk score for the first inbound email based on the correlation and the first external document; and(¶0088-0091: If the email's non-semantic score does not meet the threshold score, semantic analysis (¶0076: Semantic information also comprise of various keywords typically associated with social engineering attacks & ¶0106: Word expressions often perform the “heavy lifting” of the scoring process. Word expressions are usually mathematical equations, where the variables in the equations might represent, for example, a number of occurrences of keywords, patterns, or otherwise identifiably potentially malicious trends in the digital media document text.) (correlating keywords) may then be performed on the email (step 550). For example, at least four semantic cues may be found in content 610 to indicate that email 600 may be fraudulent. Such semantic patterns may also be quantified and combined to produce a numerical or other type of score (calculating risk score) );
in response to the first risk score for the first inbound email exceeding a threshold score, withholding transmission of the first inbound email to the first recipient; and (¶0067: If the email still does not meet a particular threshold score (step 560) (implied that the opposite would be if the threshold is exceeded as seen in ¶0088 and the previous steps wherein the non-semantic score meets or exceeds a threshold score, the email may be flagged as potentially, suspect, quarantined, and forwarded for analysis (step 580)) , the email may be regarded as non-malicious and may be forwarded to its intended recipient (step 570).);
calculating a second risk score for the second inbound email based on the second correlation and the second external document; and (¶0088-0091: If the email's non-semantic score does not meet the threshold score, semantic analysis (¶0076: Semantic information also comprise of various keywords typically associated with social engineering attacks & ¶0106: Word expressions often perform the “heavy lifting” of the scoring process. Word expressions are usually mathematical equations, where the variables in the equations might represent, for example, a number of occurrences of keywords, patterns, or otherwise identifiably potentially malicious trends in the digital media document text.) (correlating keywords) may then be performed on the email (step 550). For example, at least four semantic cues may be found in content 610 to indicate that email 600 may be fraudulent. Such semantic patterns may also be quantified and combined to produce a numerical or other type of score (calculating risk score) ).
in response to the second risk score for the second inbound email falling below the threshold score, passing the second inbound email to the second recipient. (¶0067: If the email still does not meet a particular threshold score (step 560) (below) , the email may be regarded as non-malicious and may be forwarded to its intended recipient (step 570) (passing the second inbound email to the recipient).);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Srivastava with regards to implementing risk scores to the method of Marino in view of Hassanzadeh and Leddy in order to better evaluate the likelihood if the communication is directed to a various forms of social engineering attacks (Srivastava: ¶0084)
With respect to claim 10, the combination of Marino in view of Hassanzadeh and Leddy teaches the method of claim 1 (see the rejection of claim 1), further comprising: intercepting a second inbound email received from a second sender at a second inbound email address and addressed to a second recipient; and (Marino ¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
in response to the set of verified email addresses omitting the second inbound email address: scanning the second inbound email for presence of external content linked to the second inbound email; and in response to detecting a second link to a second external document within the second inbound email: (Marino ¶0138: On the other hand, if the message sender email address does not match any entries in the whitelist, the system checks the recipient of the email message identified does not match any entries in the whitelist, the system checks the recipient of the email message identified in the “To” field of the message header against entries in the parental control profile. If no matching entries in the parental control profile exist, the system proceeds with step 516, whereupon the identity fraud analysis algorithm inspects the header of the email message for possible phishing scam (omitting the first inbound email address) . Upon passing of the phishing scam inspection, the message header pattern is analyzed at step 517 for SPAM content. If SPAM is not detected in the header, at step 518, the system checks whether the message header indicates presence of encrypted email message. The encrypted content is indicated, for example, by presence of "Content-Type: application/x-pkcs7-mime" record in the header of the email (scanning presence of external content linked to the first inbound email) . If the content is not encrypted, the system inspects the body of the message for SPAM content at step 519. If the content is not encrypted, the system inspects the body of the message for SPAM content at 519 (in response to detecting a first link to a first external document within inbound email). );
Marino in view of Hassanzadeh and Leddy does not disclose:
scanning the second external document for presence of malicious content; and
in response to detecting presence of malicious content in the second external document, withholding transmission of the second inbound email to the second recipient.
However, Srivastava teaches scanning the second external document for presence of malicious content; and (¶0062: Figure 2, is an exemplary flow schematic illustrating a process for performing routine collection of information associated with suspect activity, as further depicted in Figures 3 and 4. In step 210, a collection process accesses an initial webpage, such as through a standard HTTP request, and downloads its content for analysis.);
in response to detecting presence of malicious content in the second external document, (¶0066: In step 220, the downloaded webpage content is analyzed, either by the process that collected the data or by another process, such as a process devoted entirely to content analysis. The webpage content is analyzed for indications of potential malicious activity.);
withholding transmission of the second inbound email to the second recipient. (¶0073-0088: As further depicted in Figure 5 and 6, the information collection in Figures 2-4 (detecting malicious content in second external document) may then be used to proactively identify and guard against social engineering attacks, such as “phishing” email attempts. After analyzing all non-semantic data, for example by querying against database 640 and by using behavioral analysis, one or more numerical or other kinds of scores may be generated to determine whether a sufficient threshold has been met to consider the email malicious in nature (step 540). If the email's non-semantic score meets or exceeds a threshold score, the email may be flagged as potentially suspect, quarantined, and forwarded for analysis (step 580) (detecting malicious content in the document contributed to withholding transmission of the email ) .);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Srivastava with regards to scanning the second external document for presence of malicious content to the method of Marino in view of Hassanzadeh and Leddy in order to better detect phishing and bad actors attempts against the user/client (Srivastava: ¶0002-0005).
Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Hassanzadeh et al. (US PGPub No.20210352093-A1), Leddy et al. (US PGPub No. 20200067861-A1), and Kumar et a. (US PGPub No. 20160140965-A1).
With respect to claim 6, the combination of Marino in view of Hassanzadeh and Leddy teaches the method of claim 1 (see the rejection of claim 1) but does not disclose wherein scanning the first inbound email for presence of external content linked to the first inbound email comprises scanning the first inbound email for presence of audio files linked to the first inbound email; further comprising: detecting the first link to the first external document comprising a first audio file within the first inbound email; transcribing the first audio file into a first transcription representing content from the first audio file; and inserting the first transcription into the body of the first inbound email; and wherein scanning the body of the first inbound email for language signals in the set of language signals comprises scanning the body of the first inbound email for language signals in the set of language signals in response to inserting the first transcription into the body of the first inbound email.
However, Kumar teaches wherein scanning the first inbound email for presence of external content linked to the first inbound email comprises scanning the first inbound email for presence of audio files linked to the first inbound email; (¶0015: The transmissions and recordings can include recorded audio conversations, presentations and programs, recorded video that includes audio, and text communications such as email and documents (scanning email for audio files).);
further comprising: detecting the first link to the first external document comprising a first audio file within the first inbound email; (¶0031: Figure 2 shows a method for multi-level content analysis and response. At S220, a communication is received over a communication network. The received communication may be a voice mail, a video clip that includes audio (first external document comprising a first audio file), or an audio clip. );
transcribing the first audio file into a first transcription representing content from the first audio file; and inserting the first transcription into the body of the first inbound email; and (¶0033: At S225, the communication is transcribed. As noted, the transcript may be a voicemail or broadcast audio. The transcription may occur based on the identification of the source communication address or the date/ time of the communication. Alternatively, the communication may be a broadcast transcribed as a service for the recipients of the broadcast (inserting the first transcription into the email), in which case recipients can set parameters of particular audio content for which they would like to receive notifications and so on.);
wherein scanning the body of the first inbound email for language signals in the set of language signals comprises scanning the body of the first inbound email for language signals in the set of language signals (¶0034: At S230, the transcript is analyzed for a trigger. As noted, a trigger in a transcript may be a word or phrase. The analysis at S230 can be performed locally on customer premise equipment such as on answering machine, or can be provided within a communications network such as at a voicemail servers (¶0070: This search and correlation functionality will take as input search criteria such as keyword/phrases provided as preset instructions.) .) in response to inserting the first transcription into the body of the first inbound email. (¶0037: At S245, the service is provided in accordance with the preset instructions. As described herein, a service may include providing a simple notification, or may include forwarding some or all of the audio or transcript of the audio to the intended recipient or an alternative designated by the intended recipient.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kumar with regards to scanning for an audio file within an email and transcribing the audio to the method of Marino in view of Hassanzadeh and Leddy in order to improve service because there is need to physically listen through audio/videos and enable smart analysis of audio (Kumar ¶0015-0016).
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Hassanzadeh et al. (US PGPub No.20210352093-A1), Leddy et al. (US PGPub No. 20200067861-A1), Kumar et a. (US PGPub No. 20160140965-A1), and Hazony et al. (US PGPub No. 20210240836-A1).
With respect to claim 7, the combination of Marino in view of Hassanzadeh and Leddy teaches the method of claim 1 (see the rejection of claim 1) further comprising: intercepting a first [inbound audio] message received from a second sender at a first originating address and addressed to a second recipient associated with the organization; (Marino ¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
accessing a set of verified addresses associated with authentic audio message attempts within the organization; and (Marino ¶0136: The continuation of the first phase of the process shown in Figure 5A is illustrated in Figure 5B. If, no virus is found or if the message may contain encrypted attachments, the operations of the system proceeds to step 513, whereupon the sender of the message, which is identified in the corresponding “From” record, is compared with entries in the whitelist table. This table contains a list of sender email addresses from which email correspondence should be allowed without further inspection. );
in response to the set of verified addresses omitting the first originating address: (Marino ¶0138: On the other hand, if the message sender email address does not match any entries in the whitelist, the system checks the recipient of the email message identified does not match any entries in the whitelist, the system checks the recipient of the email message identified in the “To” field of the message header against entries in the parental control profile. If no matching entries in the parental control profile exist, the system proceeds with step 516, whereupon the identity fraud analysis algorithm inspects the header of the email message for possible phishing scam. Upon passing of the phishing scam inspection, the message header pattern is analyzed at step 517 for SPAM content. If SPAM is not detected in the header, at step 518, the system checks whether the message header indicates presence of encrypted email message. The encrypted content is indicated, for example, by presence of "Content-Type: application/x-pkcs7-mime" record in the header of the email (scanning presence of external content linked to the first inbound email) . If the content is not encrypted, the system inspects the body of the message for SPAM content at step 519. If the content is not encrypted, the system inspects the body of the message for SPAM content at 519 (in response to detecting a first link to a first external document within inbound email). );
scanning the second body of the second email for language signals in the set of language signals associated with fraudulent email attempts; and ( Hassanzadeh ¶0055-0058: To extract the relevant features of the model 540, at least a portion of the e-mail may be processed by input processing logic 510 of the model processor 500. The input processing logic 510 may be configured to condition at least the portion of the e-mail for analysis by feature extraction logic 520. In aspect, the input processing logic 510 may perform natural language processing (NLP) on text data included in the e-mail 400, such as the body portion 420. Based on the NLP processing, the body portion 420 of the e-mail 400 may be transformed into a list of words in a standardized format that may be analyzed by the feature extraction logic 520 (scanning a body of the email for language signals). The candidate features derived from the body portion 420 may be provided to the feature processing logic 530 where the candidate features may be analyzed and used to update values within the model 540. For example, the feature processing logic 530 may analyze the candidate features derived from the body portion 420 to determine whether any keywords associated with malicious e-mails are present (set of language signals associated with fraudulent email). );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Hassanzadeh with regards to scanning the body of an email for language signals, in a set of language signals, associated with fraudulence to the method of Marino in view of Leddy in order to better detect and mitigate malicious e-mails (Hassanzadeh: ¶0004-0005)
in response to detecting a second correlation between a second sequence of words, in the second body of the second email, with a second language signal in the set of language signals, withholding transmission of the second email to the second recipient. (Leddy ¶0132: By detecting that the email comes from an untrusted sender (i.e., not from a friend); that the sender address is deceptive (e.g., it is a close match with a party who is trusted by the recipient); and that the subject line, email body, or an attachment contain high-risk keywords or a storyline known to correspond to scam—by detecting such a combination of properties, it is determined that this email is high-risk, and should not be delivered, or should be marked up, quarantined, or otherwise processed in a way that limits the risk associated with the email.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Leddy with regards to withholding transmission of the first inbound email to the first recipient in response to the correlation of words to the method of Marino in view of Hassanzadeh in order to better detect business email compromise attack (Leddy: ¶0133).
Marino in view of Hassanzadeh and Leddy:
inbound audio message
accessing a set of verified addresses associated with authentic audio message attempts
transcribing the first inbound audio message into a first audio message transcription;
inserting the first audio message transcription into a second body of a second email designating the second recipient;
However, Kumar teaches inbound audio message (¶0053: Figure 7 illustrates the main steps of the method, according to the invention, for confirming the reception of a file by the intended recipient ( receiving an inbound audio message) , for verifying the identity of the recipient, and for delivering the encryption key to the authorized recipient. );
accessing a set of verified addresses associated with authentic audio message attempts (¶0045: Voice check server 205 processes the voice sample, computes and stores the recipient's voiceprint, and assigns an identifier (ID) to the voiceprint. The voiceprint and the associated ID are locally stored in a voiceprint database 210 (accessing a set of verified addresses associated with authentic audio message attempts) . The voiceprint ID is then transmitted to the sender's computer 130 where it is locally stored. For example, the voiceprint ID can be stored within the recipient voice record 125 as discussed above. );
transcribing the first inbound audio message into a first audio message transcription; (¶0053: The received audio signal is converted to text by the voice check server (step 735) according to a standard speech recognition engine and a test is done to compare the converted text and the voice check text (step 740).);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to substitute the teachings of Kumar with regards to intercepting an audio message, comparing the audio message to a set of verified audio messages, transcription of the audio message, and the insertion of the audio message to the method of Marino in view of Hassanzadeh and Leddy in order to get the similar results of identifying and to aid verifying the sender of the transmitted communication (e.g., emails and voice messages) as corroborated in ¶0004.
Marino in view of Hassanzadeh, Leddy, and Kumar does not disclose:
inserting the first audio message transcription into a second body of a second email designating the second recipient;
However, Hazony inserting the first audio message transcription into a second body of a second email designating the second recipient; (¶0033: At S225, the communication is transcribed. As noted, the transcript may be a voicemail or broadcast audio. The transcription may occur based on the identification of the source communication address or the date/ time of the communication. Alternatively, the communication may be a broadcast transcribed as a service for the recipients of the broadcast (inserting the first transcription into the email), in which case recipients can set parameters of particular audio content for which they would like to receive notifications and so on.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Hazony with regards to inserting the first audio message transcription into the body of the email to the method of Marino in view of Hassanzadeh, Leddy, and Kumar in order to improve service because there is need to physically listen through audio/videos and enable smart analysis of audio (Hazony: ¶0015-0016).
Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Hassanzadeh et al. (US PGPub No.20210352093-A1), Leddy et al. (US PGPub No. 20200067861-A1), and Kurian et al. (US PGPub No.20190166128-A1).
With respect to claim 8, the combination of Marino in view of Hassanzadeh and Leddy teaches the method of claim 1 (see the rejection of claim 1), further comprising: intercepting a second inbound email received from a second sender at a second inbound email address and addressed to a second recipient; and (Marino ¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
in response to the set of verified email addresses [including the second inbound email address:] (Marino ¶0136: The continuation of the first phase of the process shown in Figure 5A is illustrated in Figure 5B. If, no virus is found or if the message may contain encrypted attachments, the operations of the system proceeds to step 513, whereupon the sender of the message, which is identified in the corresponding “From” record, is compared with entries in the whitelist table. This table contains a list of sender email addresses from which email correspondence should be allowed without further inspection. );
scanning the second inbound email for presence of external content linked to the second inbound email; and in response to detecting a second link to a second external document within the second inbound email: (Marino ¶0138: On the other hand, if the message sender email address does not match any entries in the whitelist, the system checks the recipient of the email message identified does not match any entries in the whitelist, the system checks the recipient of the email message identified in the “To” field of the message header against entries in the parental control profile. If no matching entries in the parental control profile exist, the system proceeds with step 516, whereupon the identity fraud analysis algorithm inspects the header of the email message for possible phishing scam (omitting the first inbound email address) . Upon passing of the phishing scam inspection, the message header pattern is analyzed at step 517 for SPAM content. If SPAM is not detected in the header, at step 518, the system checks whether the message header indicates presence of encrypted email message. The encrypted content is indicated, for example, by presence of "Content-Type: application/x-pkcs7-mime" record in the header of the email (scanning presence of external content linked to the first inbound email) . If the content is not encrypted, the system inspects the body of the message for SPAM content at step 519. If the content is not encrypted, the system inspects the body of the message for SPAM content at 519 (in response to detecting a first link to a first external document within inbound email). );
scanning a second body of the second inbound email for language signals in the set of language signals associated with fraudulent email attempts; and (Hassanzadeh ¶0055-0058: To extract the relevant features of the model 540, at least a portion of the e-mail may be processed by input processing logic 510 of the model processor 500. The input processing logic 510 may be configured to condition at least the portion of the e-mail for analysis by feature extraction logic 520. In aspect, the input processing logic 510 may perform natural language processing (NLP) on text data included in the e-mail 400, such as the body portion 420. Based on the NLP processing, the body portion 420 of the e-mail 400 may be transformed into a list of words in a standardized format that may be analyzed by the feature extraction logic 520 (scanning a body of the email for language signals). The candidate features derived from the body portion 420 may be provided to the feature processing logic 530 where the candidate features may be analyzed and used to update values within the model 540. For example, the feature processing logic 530 may analyze the candidate features derived from the body portion 420 to determine whether any keywords associated with malicious e-mails are present (set of language signals associated with fraudulent email). );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Hassanzadeh with regards to scanning the body of an email for language signals, in a set of language signals, associated with fraudulence to the method of Marino in view of Leddy in order to better detect and mitigate malicious e-mails (Hassanzadeh: ¶0004-0005).
in response to detecting a second correlation between a second sequence of words, in the second body of the second inbound email, with a second language signal in the set of language signals, withholding transmission of the second inbound email to the second recipient. (Leddy ¶0132: By detecting that the email comes from an untrusted sender (i.e., not from a friend); that the sender address is deceptive (e.g., it is a close match with a party who is trusted by the recipient); and that the subject line, email body, or an attachment contain high-risk keywords or a storyline known to correspond to scam—by detecting such a combination of properties, it is determined that this email is high-risk, and should not be delivered, or should be marked up, quarantined, or otherwise processed in a way that limits the risk associated with the email.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Leddy with regards to withholding transmission of the first inbound email to the first recipient in response to the correlation of words to the method of Marino in view of Hassanzadeh in order to better detect business email compromise attack (Leddy: ¶0132).
Marino in view of Hassanzadeh and Leddy but does not disclose:
in response to the set of verified email addresses including the second inbound email address:
However, Kurian in response to the set of verified email addresses including the second inbound email address: (¶0037: Figure 5 shows the authentication process 500. At step 502, one or more than one electronic address, such as an email address, may be associated with a first set of identity data, such as identifying information and/or an alphanumeric code. The address may include an address of a sender. In some embodiments, the associated between the address and first set of data be performed during registration of the address into a whitelist. At step 508, the submitted username and second set of identity data may be analyzed for a preestablished association, for example, in the whitelist. The whitelist may include a list of paired username(s) and identity data (in response to the set of verified email address including the inbound email address) . The analysis may involve checking if the submitted username matches the submitted identity data based on a whitelist pairing. As seen in Figure 5, even after the email address appears to be a part of the set of verified email addresses, the process still further analyzes the email address. )
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to substitute the teachings of Kurian with regards to checking the set of verified email addresses to include the email address to the method of Marino in view of Hassanzadeh and Leddy in order to obtain the similar results of withholding the transmission and aiding verification the email as seen in the steps of Figure 5.
Claims 12 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Golan et al. (US PGPub No. 20090307320-A1), Hassanzadeh et al. (US PGPub No. 20210352093-A1), Srivastava et al. (US PGPub No.20160012223-A1), and Song et al. (US PGPub No. 20210342848-A1).
With respect to claim 12, Marino teaches method comprising: intercepting a first inbound email received from a first sender at a first inbound email address and addressed to a first recipient; (¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
accessing a whitelist associated with the organization and comprising a set of verified email addresses associated with authentic email attempts within the organization; (¶0136: The continuation of the first phase of the process shown in Figure 5A is illustrated in Figure 5B. If, no virus is found or if the message may contain encrypted attachments, the operations of the system proceeds to step 513, whereupon the sender of the message, which is identified in the corresponding “From” record, is compared with entries in the whitelist table. This table contains a list of sender email addresses from which email correspondence should be allowed without further inspection. );
Marino does not disclose:
in response to the set of verified email addresses omitting the first inbound email address, accessing a blacklist associated with the organization and comprising a set of flagged email addresses associated with inauthentic email attempts; and in response to the set of flagged email addresses omitting the first inbound email address:
However, Golan teaches in response to the set of verified email addresses omitting the first inbound email address, accessing a blacklist associated with the organization and comprising a set of flagged email addresses associated with inauthentic email attempts; and in response to the set of flagged email addresses omitting the first inbound email address: (¶0020: In still another embodiment again of the method of the invention, the challenge response filtering process includes comparing the sender address of the allowed message to a whitelist of sender addresses, providing the allowed message to the recipient when the sender address of the allowed message is on the whitelist, comparing the sender address of the allowed message to a blacklist of sender addresses, rejecting the allowed message when the sender address of the allowed message is on a blacklist, sending a challenge message (responding with further analysis if the address is neither in the whitelist or the blacklist) to the sender address of the allowed message when the sender of the allowed message is neither on the whitelist or the blacklist. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Golan with regards to checking a whitelist then a blacklist to the method of Marino in order to lessen the amount of failures such as unwanted emails gaining access and increase reliability by further filtering the email with a blacklist and a whitelist (Golan: ¶0002-0003).
Marino in view of Golan does not disclose:
scanning a body of the first inbound email for language signals in a set of language signals associated with fraudulent email attempts;
However, Hassanzadeh teaches scanning a body of the first inbound email for language signals in a set of language signals associated with fraudulent email attempts; (¶0055-0058: To extract the relevant features of the model 540, at least a portion of the e-mail may be processed by input processing logic 510 of the model processor 500. The input processing logic 510 may be configured to condition at least the portion of the e-mail for analysis by feature extraction logic 520. In aspect, the input processing logic 510 may perform natural language processing (NLP) on text data included in the e-mail 400, such as the body portion 420. Based on the NLP processing, the body portion 420 of the e-mail 400 may be transformed into a list of words in a standardized format that may be analyzed by the feature extraction logic 520 (scanning a body of the email for language signals). The candidate features derived from the body portion 420 may be provided to the feature processing logic 530 where the candidate features may be analyzed and used to update values within the model 540. For example, the feature processing logic 530 may analyze the candidate features derived from the body portion 420 to determine whether any keywords associated with malicious e-mails are present (set of language signals associated with fraudulent email). );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Hassanzadeh with regards to scanning the body of an email for language signals, in a set of language signals, associated with fraudulence to the method of Marino in view of Golan in order to better detect and mitigate malicious e-mails (Hassanzadeh: ¶0004-0005).
Marino in view of Golan and Hassanzadeh does not disclose:
detecting a first correlation between a first sequence of words, in the body of the first inbound email, with a first language signal in the set of language signals; in response to the first correlation exceeding a threshold correlation,
calculating a first risk score for the first inbound email based on the first correlation; and in response to the first risk score exceeding a threshold risk score, withholding transmission of the first inbound email to the first recipient.
However, Srivastava teaches detecting a first correlation between a first sequence of words, in the body of the first inbound email, with a first language signal in the set of language signals; in response to the first correlation [exceeding] a threshold correlation, (¶0087: After analyzing all non-semantic data, for example querying against database 640 and by using behavioral analysis, one or more numerical or other kinds of scored may be generated to determine where a sufficient threshold has been met. If the email's non-semantic score meets or exceeds a threshold score, the email may be flagged as potentially suspect, quarantined, and forwarded for analysis (step 580). If the email's non-semantic score does not meet the threshold score, semantic analysis may then be performed on the email (step 550).);
calculating a first risk score for the first inbound email based on the first correlation; and in response to the first risk score exceeding a threshold risk score, withholding transmission of the first inbound email to the first recipient. (¶0091: Such semantic patterns may also be quantified and combined to produce a numerical or other type of score. If the email still does not meet a particular threshold score (step 560), the email may be regarded as non-malicious and may be forwarded to its intended recipient (step 570). And as further seen in Figure 5, in step 560, wherein the threshold is exceeded the email is sent to Quarantine and Forward for Analysis in step 580 );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Srivastava with regards to word correlation in relations with a risk score to the method of Marino in view of Golan and Hassanzadeh in order to better detect and mitigate malicious e-mails (Srivastava: ¶0004-0005).
Marino in view of Golan, Hassanzadeh, and Srivastava does not disclose:
in response to the first correlation exceeding a threshold correlation, calculating a first risk score
It is noted that Srivastava does disclose the calculation of a score in response to an initial threshold, but Srivastava does not disclose the initial threshold being exceeded and then doing another calculation. However, Song teaches in response to the first correlation exceeding a threshold correlation, calculating a first risk score(¶0063: As seen, in Figure 3 it may be determined whether the nth risk score satisfies a threshold, such as an nth threshold. If the nth risk score is determined to be acceptable at step 306, the method proceeds to step 312 and the nth risk score is returned. If the nth risk score is not acceptable at step 306 (exceeding threshold correlation) , the method proceeds to step 308 and it is determined if n is the maximum number of stages. For example, for the first iteration through the method where n=1, it will be determined that n does not equal or exceed a maximum number of stages (e.g., two or more stages). If there are additional stages to perform, the method proceeds to step 310 and the value of n is incremented. As described herein, there may be two, three, or more stages, each stage with a corresponding risk scoring model (risk score is being calculated in response to the threshold being exceeded/not being able to satisfy initial threshold) . );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Song with regards to one threshold being exceeded to prompt the risk score to be calculated to the method of Marino in view of Golan, Hassanzadeh, and Srivastava in order to further verifying the item that is being authenticated such as an email and reduce computer resources because further it ensures the additional stages that consider additional data associated with additional processing resources (such as calculating a risk score) are only initiated and performed if the first stage (initial threshold) is insufficient (Song ¶0003-0004).
With respect to claim 15, the combination of Marino in view of Golan, Hassanzadeh, Srivastava, and Song teaches method of claim 12 (see rejection of claim 12 above) further comprising: scanning the first inbound email for presence of external content linked to the first inbound email; and in response to detecting a first link to a first external document within the first inbound email, (Marino ¶0138: On the other hand, if the message sender email address does not match any entries in the whitelist, the system checks the recipient of the email message identified does not match any entries in the whitelist, the system checks the recipient of the email message identified in the “To” field of the message header against entries in the parental control profile. If no matching entries in the parental control profile exist, the system proceeds with step 516, whereupon the identity fraud analysis algorithm inspects the header of the email message for possible phishing scam (omitting the first inbound email address) . Upon passing of the phishing scam inspection, the message header pattern is analyzed at step 517 for SPAM content. If SPAM is not detected in the header, at step 518, the system checks whether the message header indicates presence of encrypted email message. The encrypted content is indicated, for example, by presence of "Content-Type: application/x-pkcs7-mime" record in the header of the email (scanning presence of external content linked to the first inbound email) . If the content is not encrypted, the system inspects the body of the message for SPAM content at step 519. If the content is not encrypted, the system inspects the body of the message for SPAM content at 519 (in response to detecting a first link to a first external document within inbound email). );
scanning the first external document for presence of malicious content; and (Srivastava ¶0062: Figure 2, is an exemplary flow schematic illustrating a process for performing routine collection of information associated with suspect activity, as further depicted in Figures 3 and 4. In step 210, a collection process accesses an initial webpage, such as through a standard HTTP request, and downloads its content for analysis.);
wherein calculating the first risk score for the first inbound email comprises calculating the first risk score for the first inbound email based on: the first correlation; and presence of malicious content in the first external document. (Srivastava ¶0088-0091: If the email's non-semantic score does not meet the threshold score, semantic analysis (¶0076: Semantic information also comprise of various keywords typically associated with social engineering attacks & ¶0106: Word expressions often perform the “heavy lifting” of the scoring process. Word expressions are usually mathematical equations, where the variables in the equations might represent, for example, a number of occurrences of keywords, patterns, or otherwise identifiably potentially malicious trends in the digital media document text.) (correlating keywords) may then be performed on the email (step 550). For example, at least four semantic cues may be found in content 610 to indicate that email 600 may be fraudulent. Such semantic patterns may also be quantified and combined to produce a numerical or other type of score (calculating risk score) );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Srivastava with regards to implementing risk score to the method of Marino in view of Golan, Hassanzadeh, and Song in order to better evaluate the likelihood if the communication is directed to a various forms of social engineering attacks (Srivastava: ¶0084)
Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Golan et al. (US PGPub No. 20090307320-A1), Hassanzadeh et al. (US PGPub No. 20210352093-A1), Srivastava et al. (US PGPub No.20160012223-A1), Song et al. (US PGPub No. 20210342848-A1), and Chechik et al. (US Pat No. 10911489-B1).
With respect to claim 13, the combination of Marino in view of Golan, Hassanzadeh, Srivastava, and Song teaches method of claim 12 (see rejection of claim 12 above) wherein scanning the body of the first inbound email for language signals in the set of language signals associated with fraudulent email attempts comprises: (Marino ¶0055-0058: To extract the relevant features of the model 540, at least a portion of the e-mail may be processed by input processing logic 510 of the model processor 500. The input processing logic 510 may be configured to condition at least the portion of the e-mail for analysis by feature extraction logic 520. In aspect, the input processing logic 510 may perform natural language processing (NLP) on text data included in the e-mail 400, such as the body portion 420. Based on the NLP processing, the body portion 420 of the e-mail 400 may be transformed into a list of words in a standardized format that may be analyzed by the feature extraction logic 520 (scanning a body of the email for language signals). The candidate features derived from the body portion 420 may be provided to the feature processing logic 530 where the candidate features may be analyzed and used to update values within the model 540. For example, the feature processing logic 530 may analyze the candidate features derived from the body portion 420 to determine whether any keywords associated with malicious e-mails are present (set of language signals associated with fraudulent email). );
Marino in view of Golan, Hassanzadeh, Srivastava, and Song does not disclose:
scanning the body of the first inbound email for financial language signals in the set of language signals associated with fraudulent email attempts to access financial information associated with the organization; and
wherein detecting the first correlation between the first sequence of words, in the body of the first inbound email, with the first language signal in the set of language signals comprises:
detecting the first correlation between the first sequence of words, in the body of the first inbound email, with the first language signal in the set of language signals, the first language signal comprising a first financial language signal.
However, Chechik teaches scanning the body of the first inbound email for financial language signals in the set of language signals associated with fraudulent email attempts to access financial information associated with the organization; and (¶0064: Secondary attributes are generally attributes that are determined from primary attributes and/or other data (e.g., as determined from the threat detection datastore 408). The secondary attributes may be determined by one or more secondary extractors. Secondary extractors can be global (e.g., shared across multiple enterprises) or specific to an enterprise. Examples of secondary attributes include whether the body of an outgoing/incoming email includes high-risk words, phrases, or sentiments (e.g., whether the body includes financial vocabulary (financial language signals in set of language signal associated with fraudulent email attempts to access financial information) , credential theft vocabulary , engagement vocabulary, non-ASCII content, attachments, links, etc.));
wherein detecting the first correlation between the first sequence of words, in the body of the first inbound email, with the first language signal in the set of language signals comprises: detecting the first correlation between the first sequence of words, in the body of the first inbound email, with the first language signal in the set of language signals, the first language signal comprising a first financial language signal. (¶0068: Figure 4 depicts an example of a platform 400 able to detect threats to an enterprise network 414 (also referred to as a “customer network” or “corporate network”) posed by compromised email accounts belonging to employee. The analysis module 410 operates to analyze each digital activity performed with an email account to determine the likelihood that the email account has been compromised. For example, the analysis module 410 may examine each email received and/or transmitted by the email account to determine whether those emails deviate from past email activity. In such embodiments, the analysis module 410 may determine whether a given email deviates from the past email activity (and thus may be indicative of compromise) based on its primary and/or secondary attributes (detecting and correlating first financial language signal (secondary attribute)).);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Chechik with regards to scanning for financial language signals to the method of Marino in view of Golan, Hassanzadeh, Srivastava, and Song in order to better detect business email compromise scams and to prevent harm to an enterprise by examining further suspected compromises (Chechik ¶0019-0023).
Claim 14 is rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Golan et al. (US PGPub No. 20090307320-A1), Hassanzadeh et al. (US PGPub No. 20210352093-A1), Srivastava et al. (US PGPub No.20160012223-A1), Song et al. (US PGPub No. 20210342848-A1), Chechik et al. (US Pat No. 10911489-B1), and Elworthy et al. (US PGPub No. 20180359280-A1).
With respect to claim 14, the combination of Marino in view of Golan, Hassanzadeh, Srivastava, and Song teaches method of claim 12 (see rejection of claim 12 above) but does not disclose wherein scanning the body of the first inbound email for language signals in the set of language signals associated with fraudulent email attempts comprises: scanning the body of the first inbound email for urgency language signals and action language signals in the set of language signals associated with fraudulent email attempts and indicating urgency of actions requested in the body of the first inbound email; wherein detecting the first correlation between the first sequence of words, in the body of the first inbound email, with the first language signal in the set of language signals comprises: detecting the first correlation between the first sequence of words, in the body of the first inbound email, with the first language signal in the set of language signals, the first language signal comprising a first urgency language signal; further comprising detecting a second correlation between a second sequence of words, in the body of the first inbound email, with a second language signal in the set of language signals, the second language signal comprising a first action language signal; and wherein calculating the first risk score for the first inbound email comprises: calculating the first risk score for the first inbound email based on the first correlation and the second correlation.
However, Chechik teaches wherein scanning the body of the first inbound email for language signals in the set of language signals associated with fraudulent email attempts comprises: scanning the body of the first inbound email for urgency language signals and action language signals in the set of language signals associated with fraudulent email attempts and indicating urgency of actions requested in the body of the first inbound email; (¶0064: Secondary attributes are generally attributes that are determined from primary attributes and/or other data (e.g., as determined from the threat detection datastore 408). The secondary attributes may be determined by one or more secondary extractors. Secondary extractors can be global (e.g., shared across multiple enterprises) or specific to an enterprise. Examples of secondary attributes include whether the body of an outgoing/incoming email includes high-risk words , phrases, or sentiments (e.g., whether the body includes financial vocabulary, credential theft vocabulary (urgent and action language signals) , engagement vocabulary, non-ASCII content, attachments, links, etc.));
wherein detecting the first correlation between the first sequence of words, in the body of the first inbound email, with the first language signal in the set of language signals comprises: detecting the first correlation between the first sequence of words, in the body of the first inbound email, with the first language signal in the set of language signals, the first language signal comprising a first urgency language signal; further comprising detecting a second correlation between a second sequence of words, in the body of the first inbound email, with a second language signal in the set of language signals, the second language signal comprising a first action language signal; and (¶0068: Figure 4 depicts an example of a platform 400 able to detect threats to an enterprise network 414 (also referred to as a “customer network” or “corporate network”) posed by compromised email accounts belonging to employee. The analysis module 410 operates to analyze each digital activity performed with an email account to determine the likelihood that the email account has been compromised. For example, the analysis module 410 may examine each email received and/or transmitted by the email account to determine whether those emails deviate from past email activity. In such embodiments, the analysis module 410 may determine whether a given email deviates from the past email activity (and thus may be indicative of compromise) based on its primary and/or secondary attributes (detecting and correlating urgent and action language signals (secondary attributes)).);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Chechik with regards to scanning for urgency and action language signals to the method of Marino in view of Golan, Hassanzadeh, Srivastava, and Song in order to better detect business email compromise scams and to prevent harm to an enterprise by examining further suspected compromises (Chechik ¶0019-0023).
Marino in view of Golan, Hassanzadeh, Srivastava, Song, and Chechik does not disclose:
wherein calculating the first risk score for the first inbound email comprises: calculating the first risk score for the first inbound email based on the first correlation and the second correlation.
However, Elworthy teaches wherein calculating the first risk score for the first inbound email comprises: calculating the first risk score for the first inbound email based on the first correlation and the second correlation. (¶0036: The detection of keywords and urgent terms (first and second correlation) in the subject and body is performed as part of the data enrichment process prior to presenting to Trust Score Generation Analytics Module 600. Additionally, there may be correlators and other information associated with the input data. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Elworthy with regards to implementing risk score deriving from urgency keywords to the method of Marino in view of Golan, Hassanzadeh, Srivastava, Song, and Chechik in order to provide visibility and insight into risk factors, and enables for an informed decision on validity of each email message even when a message is totally safe (Elworthy ¶0006).
Claims 16, 18, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Srivastava et al. (US PGPub No.20160012223-A1) and Dinkin et al. (US PGPub No. 20050050150-A1).
With respect to claim 16, Marino teaches a method comprising: intercepting a first inbound email received from a first sender at a first inbound email address and addressed to a first recipient; (¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
Marino does not disclose:
scanning a body of the first inbound email for language signals in a set of language signals; detecting a first correlation between a first sequence of words, in the body of the first inbound email, with a first language signal in the set of language signals;
However, Srivastava scanning a body of the first inbound email for language signals in a set of language signals; detecting a first correlation between a first sequence of words, in the body of the first inbound email, with a first language signal in the set of language signals; (¶0081: As seen in Figure 6, thus, using email 600 as an example, in step 520, device 630 extracts non-semantic data, e.g., data 611 (“relay.g16z.org”) and 612 (“accounts_manager@www.TDBank.com”) from the SMTP headers of content 610. Security device 630 may also elect to receive the body of email 600 in order to further glean any non-semantic data therefrom as well, such as the URLs in line 615 (detecting a first correlation between the first sequence of words) .);
detecting a second correlation between a second sequence of words, in the body of the first inbound email, with a second language signal in the set of language signals; (¶0083: Database 640 may additionally (detecting second correlation between a second sequence of words) or alternatively be populated using data from government, proprietary, or other available feeds detailing cyber threat and/or other security information, such as various whitelists, blacklists, or reputational data. For example, database 640 may include data that may be used to positively identify an email as benign (rather than to identify it as malicious) using whitelist information, such as reputational classifications for known domain names or IP addresses.);
calculating a risk score based on the first correlation and the second correlation; and in response to the risk score exceeding a threshold risk score: (¶0088: If the email's non-semantic score meets or exceeds a threshold score, the email may be flagged as potentially suspect, quarantined, and forwarded for analysis (step 580).);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Srivastava with regards to implementing risk scores to the method of Marino in order to better evaluate the likelihood if the communication is directed to a various forms of social engineering attacks (Srivastava: ¶0084).
Marino in view of Srivastava does not disclose:
accessing a whitelist associated with the organization and comprising a set of verified email addresses associated with authentic email attempts within the organization;
and in response to the set of verified email addresses omitting the first inbound email address, withholding transmission of the first inbound email to the first recipient.
However, Dinkin teaches accessing a whitelist associated with the organization and comprising a set of verified email addresses associated with authentic email attempts within the organization; (¶00111: Figure 4B illustrates a filter 400 for filtering electronic mail messages. The additional database 440 may include a "whitelist" of senders from which an e-mail is automatically passed through to the intended receiver.);
and in response to the set of verified email addresses omitting the first inbound email address, withholding transmission of the first inbound email to the first recipient. (¶0031: Conventional methods used to block junk mail include blacklisting (centralized and local) in which a filter rejects all sender addresses that are included in a blacklist, blocking mail from nonexistent domains, and whitelisting in which a filter rejects all sender addresses that are not included in a local whitelist (omitting email address and withholding transmission).);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Dinkin with regards to withholding in accords to a whitelist to the method of Marino in view of Srivastava in order to keep malicious content out of an organization’s internal network (Dinkin: ¶00007-0010).
With respect to claim 18, the combination of Marino in view of Srivastava and Dinkin teaches the method of claim 16 (see rejection of claim 16 above), further comprising: scanning the first inbound email for presence of external content linked to the first inbound email; and in response to detecting a first link to a first external document within the first inbound email, (Marino ¶0138: On the other hand, if the message sender email address does not match any entries in the whitelist, the system checks the recipient of the email message identified does not match any entries in the whitelist, the system checks the recipient of the email message identified in the “To” field of the message header against entries in the parental control profile. If no matching entries in the parental control profile exist, the system proceeds with step 516, whereupon the identity fraud analysis algorithm inspects the header of the email message for possible phishing scam (omitting the first inbound email address) . Upon passing of the phishing scam inspection, the message header pattern is analyzed at step 517 for SPAM content. If SPAM is not detected in the header, at step 518, the system checks whether the message header indicates presence of encrypted email message. The encrypted content is indicated, for example, by presence of "Content-Type: application/x-pkcs7-mime" record in the header of the email (scanning presence of external content linked to the first inbound email) . If the content is not encrypted, the system inspects the body of the message for SPAM content at step 519. If the content is not encrypted, the system inspects the body of the message for SPAM content at 519 (in response to detecting a first link to a first external document within inbound email). );
scanning the first external document for presence of malicious content; and (Srivastava ¶0062: Figure 2, is an exemplary flow schematic illustrating a process for performing routine collection of information associated with suspect activity, as further depicted in Figures 3 and 4. In step 210, a collection process accesses an initial webpage, such as through a standard HTTP request, and downloads its content for analysis .);
wherein calculating the risk score for the first inbound email comprises calculating the risk score for the first inbound email based on: the first correlation; the second correlation; and presence of malicious content in the first external document. (Srivastava ¶0088-0091: If the email's non-semantic score does not meet the threshold score, semantic analysis (¶0076: Semantic information also comprise of various keywords typically associated with social engineering attacks & ¶0106: Word expressions often perform the “heavy lifting” of the scoring process. Word expressions are usually mathematical equations, where the variables in the equations might represent, for example, a number of occurrences of keywords, patterns, or otherwise identifiably potentially malicious trends in the digital media document text.) (correlating first and second correlation based on external device)) may then be performed on the email (step 550). For example, at least four semantic cues may be found in content 610 to indicate that email 600 may be fraudulent. Such semantic patterns may also be quantified and combined to produce a numerical or other type of score (calculating risk score) );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Srivastava with regards to implementing risk scores to the method of Marino in view of Dinkin in order to better evaluate the likelihood if the communication is directed to a various forms of social engineering attacks (Srivastava: ¶0084)
With respect to claim 19, the combination of Marino in view of Srivastava and Dinkin teaches the method of claim 16 (see rejection of claim 16 above), further comprising: intercepting a second inbound email received from a second sender at a second inbound email address and addressed to a second recipient; (Marino ¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
scanning a second body of the second inbound email for language signals in the set of language signals; detecting a third correlation between a third sequence of words, in the second body of the second inbound email, with a third language signal in the set of language signals; (Srivastava ¶0081: As seen in Figure 6, thus, using email 600 as an example, in step 520, device 630 extracts non-semantic data, e.g., data 611 (“relay.g16z.org”) and 612 (“accounts_manager@www.TDBank.com”) from the SMTP headers of content 610. Security device 630 may also elect to receive the body of email 600 in order to further glean any non-semantic data therefrom as well, such as the URLs in line 615 (detecting a first correlation between the first sequence of words) .);
calculating a second risk score based on the third correlation and the fourth correlation; (¶0083: Database 640 may additionally (detecting fourth correlation between a second sequence of words) or alternatively be populated using data from government, proprietary, or other available feeds detailing cyber threat and/or other security information, such as various whitelists, blacklists, or reputational data. For example, database 640 may include data that may be used to positively identify an email as benign (rather than to identify it as malicious) using whitelist information, such as reputational classifications for known domain names or IP addresses.) and in response to the second risk score exceeding the threshold risk score: (Srivastava ¶0088: If the email's non-semantic score meets or exceeds a threshold score, the email may be flagged as potentially suspect, quarantined, and forwarded for analysis (step 580).);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Srivastava with regards to implementing risk scores to the method of Marino in view of Dinkin in order to better evaluate the likelihood if the communication is directed to a various forms of social engineering attacks (Srivastava: ¶0084).
accessing the whitelist associated with the organization; and in response to identifying the second inbound email address in the set of verified email addresses on the whitelist, releasing the second inbound email to the second recipient. (Dinkin ¶0111: Likewise, the additional database 440 may include a "whitelist" of senders from which an e-mail is automatically passed through to the intended receiver. The inventive filter 400 may also work in cooperation with and/or supplement the filtering provided by conventional filtering devices. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Dinkin with regards to passing an email in accords to a whitelist to the method of Marino in view of Srivastava in order to keep malicious content out of an organization’s internal network (Dinkin: ¶00007-0010).
Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Srivastava et al. (US PGPub No.20160012223-A1), Dinkin et al. (US PGPub No. 20050050150-A1), and LaRosa et al. (US PGPub No. 20170251006-A1).
With respect to claim 17, the combination of Marino in view of Srivastava and Dinkin teaches the method of claim 16 (see rejection of claim 16 above) further comprising: intercepting a second inbound email received from a second sender at a second inbound email address and addressed to a second recipient; (Marino ¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
scanning a second body of the second inbound email for language signals in the set of language signals; (Srivastava ¶0081: As seen in Figure 6, thus, using email 600 as an example, in step 520, device 630 extracts non-semantic data, e.g., data 611 (“relay.g16z.org”) and 612 (“accounts_manager@www.TDBank.com”) from the SMTP headers of content 610. Security device 630 may also elect to receive the body of email 600 in order to further glean any non-semantic data therefrom as well, such as the URLs in line 615 (detecting a first correlation between the first sequence of words) .);
detecting a third correlation between a third sequence of words, in the second body of the second inbound email, with a third language signal in the set of language signals: (Srivastava ¶0083: Database 640 may additionally (detecting second correlation between a second sequence of words) or alternatively be populated using data from government, proprietary, or other available feeds detailing cyber threat and/or other security information, such as various whitelists, blacklists, or reputational data. For example, database 640 may include data that may be used to positively identify an email as benign (rather than to identify it as malicious) using whitelist information, such as reputational classifications for known domain names or IP addresses.);
detecting a fourth correlation between a fourth sequence of words, in the body of the first inbound email, with a fourth language signal in the set of language signals; (Srivastava ¶0083: Database 640 may additionally (detecting second correlation between a second sequence of words) or alternatively be populated using data from government, proprietary, or other available feeds detailing cyber threat and/or other security information, such as various whitelists, blacklists, or reputational data. For example, database 640 may include data that may be used to positively identify an email as benign (rather than to identify it as malicious) using whitelist information, such as reputational classifications for known domain names or IP addresses.);
calculating a second risk score based on the third correlation and the fourth correlation; and (Srivastava ¶0088: If the email's non-semantic score meets or exceeds a threshold score, the email may be flagged as potentially suspect, quarantined, and forwarded for analysis (step 580).);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Srivastava with regards to implementing risk scores to the method of Marino in view of Dinkin in order to better evaluate the likelihood if the communication is directed to a various forms of social engineering attacks (Srivastava: ¶0084).
Marino in view of Dinkin does not disclose:
in response to the second risk score falling below the threshold risk score, releasing the second inbound email to the second recipient.
However, LaRosa teaches in response to the second risk score falling below the threshold risk score, releasing the second inbound email to the second recipient. (¶0108- 0112: As seen in Figure 2 is a content linguistic graph of words associated with communications between email addresses (word correlation aiding in the score). Based on forgoing the passing or blocking of email will occur based on one or more of the following steps: 1. Evaluating an email's cumulative score to determine message processing. 2. Determining initial risk points review criteria based on 90 day learned behavioral profiling and organizational tolerance for scoring. 4. Passing on to the designated recipient those messages that are under the threshold.);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of LaRosa with regards to passing on email based on the risk score of the correlation of words to the method of Marino in view of Srivastava and Dinkin in order to better evaluate the likelihood if the communication is directed to a various forms of social engineering attacks (LaRosa: ¶0084).
Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Marino et al. (US PGPub No. 20130013907-A1) in view of Srivastava et al. (US PGPub No.20160012223-A1), Dinkin et al. (US PGPub No. 20050050150-A1), Leddy et al. (US PGPub No.20200067861-A1), and Hsu et al. (US Pat No. 10666676-B1).
With respect to claim 20, the combination of Marino in view of Srivastava and Dinkin teaches the method of claim 16 (see rejection of claim 16 above), teaches further comprising: intercepting a second inbound email received from a second sender at a second inbound email address and addressed to a second recipient; (Marino ¶0134: The process illustrated in Figure 5A is automatically initiated when, at step 502, the appliance 101 accepts a connection from user’s computer 201 on the outbound port 110, corresponding to TCP/IP protocol, well known to persons of skill in the art. Through established connection, at step 503, the appliance 101 intercepts a request generated by user’s email client software to retrieve messages corresponding to user’s email account from the internet service provider (ISP). );
Marino in view of Srivastava and Dinkin but does not disclose:
scanning a second body of the second inbound email for language signals in the set of language signals; and in response to detecting absence of correlations between sequences of words, in the second body of the second inbound email, with language signals in the set of language signals:
However, Leddy teaches scanning a second body of the second inbound email for language signals in the set of language signals; and in response to detecting absence of correlations between sequences of words, in the second body of the second inbound email, with language signals in the set of language signals: (¶0132: By detecting that the email comes from an untrusted sender (i.e., not from a friend); that the sender address is deceptive (e.g., it is a close match with a party who is trusted by the recipient); and that the subject line, email body, or an attachment contain high-risk keywords or a storyline known to correspond to scam—by detecting such a combination of properties, it is determined that this email is high-risk, and should not be delivered, or should be marked up, quarantined, or otherwise processed in a way that limits the risk associated with the email (implying that if there are no high-risk words transmission would be allowed). In ¶0086-0087 shows the parts of filtering an email wherein b. If no to (2), then does the email have high-risk content (an attachment, presence of high-risk key-words, etc.)? If yes to (2b), then perform in-depth filtering to it as described below, and perform a conditional action. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Leddy with regards to was an absence of high risk words to the method of Marino in view of Srivastava and Dinkin in order to better detect business email compromise attack (Leddy: ¶0132).
Marino In view of Srivastava, Dinkin, and Leddy does not disclose:
scanning the second inbound email for presence of external content linked to the second inbound email; and
in response to detecting absence of external content linked to the second inbound email, passing the second inbound email to the second recipient.
However, Hsu teaches scanning the second inbound email for presence of external content linked to the second inbound email; and (¶0024: The URL filter 156 may comprise a conventional URL filter. The URL filter may configure to evaluate one or more URLS that are included in an email (e.g., in the message body and/or Simple Mail Transfer Protocol (SMTP) header) (scanning for email for external content linked) , block URLs that are in the blacklist of URLs .);
in response to detecting absence of external content linked to the second inbound email, passing the second inbound email to the second recipient. (¶0024. For example, the URL filter 156 may consult a local or remote reputation database containing reputations of known URLs to determine if a URL extracted from an email has a good (i.e., non-malicious), bad (i.e., malicious), or unknown reputation. The URL filter 156 may be configured to block emails that contain one or more URLs with a bad reputation (if the absence of malicious external content linked to email passing to email to recipient as seen in the process of Figure 2 where the email gets passed along in the endpoint system 152).);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Hsu with regards to a detection of external linked content linked to email to the method of Marino in view of Srivastava, Dinkin, and Leddy in order to better identify abnormal activity that indicative of malicious attack against the user in a targeted email (Hsu: ¶0002-0003).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAYLOR P VU whose telephone number is (703)756-1218. The examiner can normally be reached MON - FRI (7:30 - 5:00).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/T.P.V./Examiner, Art Unit 2437
/MENG LI/Primary Examiner, Art Unit 2437