Detecting and thwarting spear phishing attacks in electronic messages
Abstract
A computer-implemented method may comprise receiving an electronic message from a purported known sender; accessing a database of known senders and determining whether the sender matches one of the known senders. The degree of similarity of the sender to at least one of the known senders may then be quantified. The received message may then be determined to be legitimate when the purported known sender is determined to match one of the known senders. The received electronic message may be flagged as being suspect when the purported known sender does not match one of the plurality of known senders and the quantified degree of similarity of the purported known sender to one of the known senders is greater than a threshold value. A perceptible cue may then be generated when the received message has been flagged as being suspect, to alert the recipient that the flagged message is likely illegitimate.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method, comprising:
receiving an electronic message from a purported known sender over a computer network; accessing a database configured to store a plurality of known senders of electronic messages and determining whether the purported known sender of the electronic message matches one of the plurality of known senders of electronic messages in the database of known senders; quantifying a degree of similarity of the purported known sender of the electronic message to at least one of the plurality of known senders of electronic messages stored in the database; determining the received electronic message to be legitimate when the purported known sender is determined to match one of the plurality of known senders in the database of known senders; flagging the received electronic message as being suspect when:
the purported known sender does not match one of the plurality of known senders in the database of known senders; and
the quantified degree of similarity of the purported known sender of the electronic message to one of the plurality of known senders of electronic messages is greater than a threshold value; and
generating at least a visual cue when the received electronic message has been flagged as being suspect, to alert a recipient thereof that the flagged electronic message is likely illegitimate.
2 . The computer-implemented method of claim 1 , wherein the electronic message comprises an email.
3 . The computer-implemented method of claim 1 , wherein quantifying comprises calculating a string metric of a difference between the purported sender and one of the plurality of known senders in the database of known senders.
4 . The computer-implemented method of claim 1 , wherein quantifying comprises calculating a Levenshtein distance between the purported sender and one of the plurality of known senders in the database of known senders.
5 . The computer-implemented method of claim 1 , further comprising prompting for a decision confirming the flagged electronic message is suspect or a decision denying that the flagged electronic message is suspect.
6 . The computer-implemented method of claim 5 , further comprising dropping the flagged electronic message when the prompted decision is to confirm that the flagged electronic message is suspect and delivering the flagged electronic message when the prompted decision is to deny that the flagged electronic message is suspect.
7 . The computer-implemented method of claim 1 , wherein accessing also accesses a database of blacklisted senders of electronic messages and dropping the received electronic message if a sender of the received electronic matches an entry in the database of blacklisted senders of electronic messages.
8 . A computing device configured to determine whether a received electronic message comprises a spear phishing attack, comprising:
at least one processor; at least one data storage device coupled to the at least one processor; a plurality of processes spawned by said at least one processor, the processes including processing logic for: receiving an electronic message from a purported known sender over a computer network; accessing a database configured to store a plurality of known senders of electronic messages and determining whether the purported known sender of the electronic message matches one of the plurality of known senders of electronic messages in the database of known senders; quantifying a degree of similarity of the purported known sender of the electronic message to at least one of the plurality of known senders of electronic messages stored in the database; determining the received electronic message to be legitimate when the purported known sender is determined to match one of the plurality of known senders in the database of known senders; flagging the received electronic message as being suspect when:
the purported known sender does not match one of the plurality of known senders in the database of known senders; and
the quantified degree of similarity of the purported known sender of the electronic message to one of the plurality of known senders of electronic messages is greater than a threshold value; and
generating at least a visual cue when the received electronic message has been flagged as being suspect, to alert a recipient thereof that the flagged electronic message is likely illegitimate
9 . The computing device of claim 8 , wherein the electronic message comprises an email.
10 . The computing device of claim 8 , wherein quantifying comprises calculating a string metric of a difference between the purported sender and one of the plurality of known senders in the database of known senders.
11 . The computing device of claim 8 , wherein quantifying comprises calculating a Levenshtein distance between the purported sender and one of the plurality of known senders in the database of known senders.
12 . The computing device of claim 8 , wherein the processes further comprise processing logic for prompting for a decision confirming the flagged electronic message is suspect or a decision denying that the flagged electronic message is suspect.
13 . The computing device of claim 12 , wherein the processes further comprise processing logic for dropping the flagged electronic message when the prompted decision is to confirm that the flagged electronic message is suspect and for delivering the flagged electronic message when the prompted decision is to deny that the flagged electronic message is suspect.
14 . The computing device of claim 8 , wherein the processes further comprise processing logic for accessing a database of blacklisted senders of electronic messages and dropping the received electronic message if a sender of the received electronic matches an entry in the database of blacklisted senders of electronic messages.
15 . A tangible, non-transitory machine-readable data storage device having data stored thereon representing sequences of instructions which, when executed by a computing device, cause the computing device to:
receive an electronic message from a purported known sender over a computer network; access a database configured to store a plurality of known senders of electronic messages and determine whether the purported known sender of the electronic message matches one of the plurality of known senders of electronic messages in the database of known senders; quantify a degree of similarity of the purported known sender of the electronic message to at least one of the plurality of known senders of electronic messages stored in the database; determine the received electronic message to be legitimate when the purported known sender is determined to match one of the plurality of known senders in the database of known senders; flag the received electronic message as being suspect when:
the purported known sender does not match one of the plurality of known senders in the database of known senders; and
the quantified degree of similarity of the purported known sender of the electronic message to one of the plurality of known senders of electronic messages is greater than a threshold value; and
generate at least a visual cue when the received electronic message has been flagged as being suspect, to alert a recipient thereof that the flagged electronic message is likely illegitimate.
16 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein the electronic message comprises an email.
17 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein quantifying comprises calculating a string metric of a difference between the purported sender and one of the plurality of known senders in the database of known senders.
18 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein quantifying comprises calculating a Levenshtein distance between the purported sender and one of the plurality of known senders in the database of known senders.
19 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein the stored sequences of instructions further comprise prompting for a decision confirming the flagged electronic message is suspect or a decision denying that the flagged electronic message is suspect.
20 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein the stored sequences of instructions further comprise dropping the flagged electronic message when the prompted decision is to confirm that the flagged electronic message is suspect and delivering the flagged electronic message when the prompted decision is to deny that the flagged electronic message is suspect.
21 . The tangible, non-transitory machine-readable data storage device of claim 15 , wherein the stored sequences of instructions further comprise accessing a database of blacklisted senders of electronic messages and dropping the received electronic message if a sender of the received electronic matches an entry in the database of blacklisted senders of electronic messages.Join the waitlist — get patent alerts
Track US2017085584A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.