US2021176272A1PendingUtilityA1

Phishing Mitigation Service

Assignee: MCAFEE LLCPriority: Dec 5, 2019Filed: Dec 5, 2019Published: Jun 10, 2021
Est. expiryDec 5, 2039(~13.4 yrs left)· nominal 20-yr term from priority
H04L 67/55H04L 51/212H04L 51/58G06F 21/552H04L 63/1483H04L 12/1859H04W 4/12H04L 67/02H04L 63/168H04L 51/18H04W 12/128H04L 67/26
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

There is disclosed in one example a computing apparatus, including: a hardware platform including a processor and a memory; a network interface; and a phishing mitigation engine including instructions encoded within the memory to: receive via the network request a validation request from a mobile computing device, the validation request including an e-mail payload; query a cloud phishing reputation service for a reputation, the query including information from the e-mail payload; receive from the cloud phishing reputation service reputation data for the e-mail payload; and provide a push notification to the mobile computing device, the push notification including a reputation notice for the e-mail payload.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computing apparatus, comprising:
 a hardware platform comprising a processor and a memory;   a network interface; and   a phishing mitigation engine comprising instructions encoded within the memory to:
 receive via the network request a validation request from a mobile computing device, the validation request comprising an e-mail payload; 
 query a cloud phishing reputation service for a reputation, the query comprising information from the e-mail payload; 
 receive from the cloud phishing reputation service reputation data for the e-mail payload; and 
 provide a push notification to the mobile computing device, the push notification comprising a reputation notice for the e-mail payload. 
   
     
     
         2 . The computing apparatus of  claim 1 , wherein the reputation notice comprises a high-confidence reputation that the e-mail payload includes phishing content, and wherein the push notification includes an instruction not to open the e-mail payload. 
     
     
         3 . The computing apparatus of  claim 1 , wherein the reputation notice comprises a high-confidence reputation that the e-mail payload is non-malicious, and wherein the push notification includes an instruction that the e-mail payload can be safely opened. 
     
     
         4 . The computing apparatus of  claim 1 , wherein the reputation notice comprises a low-confidence reputation, and wherein the push notification comprises a warning that a reliable reputation for the e-mail payload could not be computed. 
     
     
         5 . The computing apparatus of  claim 1 , wherein the instructions are further to extract link information from the e-mail payload, and wherein querying the cloud phishing reputation service comprises querying a uniform resource locator (URL) reputation service for link reputations. 
     
     
         6 . The computing apparatus of  claim 5 , wherein the reputation notice for the e-mail payload comprises a not-safe reputation if at least one link has a high-confidence reputation for being a phishing link. 
     
     
         7 . The computing apparatus of  claim 1 , wherein the instructions are further to provide information from an attachment of the e-mail payload to the cloud reputation service, and wherein the reputation data comprise reputation data for the attachment. 
     
     
         8 . The computing apparatus of  claim 1 , wherein the instructions are further to provide a screenshot image of the e-mail payload, and wherein the reputation data comprise reputation data based on a visual analysis of the e-mail payload. 
     
     
         9 . The computing apparatus of  claim 1 , wherein the validation request comprises a forwarded e-mail. 
     
     
         10 . The computing apparatus of  claim 1 , wherein the validation request comprises a one-click reputation request from the mobile computing device. 
     
     
         11 . A phishing mitigation ecosystem, comprising:
 a user endpoint device, comprising:
 an e-mail client including a user interface to provide a low-overhead user interaction to provide a phishing analysis request for an e-mail; 
   a phishing analysis server, comprising:
 a receiver module to receive the phishing analysis request from the user endpoint device; 
 an extraction module to extract analysis data from the phishing analysis request; 
 a request module to request a reputation, and to receive a reputation response comprising a reputation associated with the request for a reputation; and 
 a response module to provide a response to the user endpoint device comprising a safety indicator for the phishing analysis request; and 
   a cloud reputation service, comprising:
 a reputation store; 
 a receiver module to receive the request for a reputation; 
 an analysis module to analyze the request for a reputation and to assign a reputation from the reputation store; and 
 a response module to provide the reputation response to the phishing analysis server. 
   
     
     
         12 . The phishing mitigation ecosystem of  claim 11 , wherein the user endpoint device is a smart phone or tablet. 
     
     
         13 . The phishing mitigation ecosystem of  claim 11 , wherein response to the user endpoint device comprises a push notification. 
     
     
         14 . The phishing mitigation ecosystem of  claim 11 , wherein the phishing analysis server further comprises a module to remotely instruct the user endpoint device to delete or quarantine an e-mail after determining with high confidence that the e-mail is a malicious phishing e-mail. 
     
     
         15 . The phishing mitigation ecosystem of  claim 11 , wherein the response to the user endpoint device comprises an e-mail flag indicating that an e-mail is green (safe), red (unsafe), or yellow (reputation not determined with confidence above a threshold). 
     
     
         16 . The phishing mitigation ecosystem of  claim 11 , wherein the low-overhead user interaction comprises providing authentication credentials to the phishing analysis server for a user's web e-mail. 
     
     
         17 . The phishing analysis mitigation ecosystem of  claim 16 , wherein receiving the request for a reputation comprises retrieving the user's incoming mail via post office protocol (POP) or internet message access protocol (IMAP) without deleting the incoming mail or marking the incoming mail as read. 
     
     
         18 . A method of detecting phishing or malicious e-mail content, comprising:
 conditioning an end user operating an endpoint device to identify an e-mail as suspicious with a low threshold for suspiciousness, wherein the threshold for suspiciousness includes any e-mail that may potentially collect personal, enterprise, or financial information;   receiving from the end user a request to verify a suspicious e-mail;   extracting content from the suspicious e-mail;   forwarding the extracted content to a public cloud reputation service;   receiving from the public cloud reputation service a reputation for the extracted content; and   providing to the endpoint device a reputation for the suspicious e-mail.   
     
     
         19 . The method of  claim 18 , wherein providing the reputation for the suspicious e-mail comprises providing a push notification to the endpoint device. 
     
     
         20 . The method of  claim 18 , wherein providing the reputation for the suspicious e-mail comprises providing electronic information regarding the reputation for the suspicious e-mail.

Join the waitlist — get patent alerts

Track US2021176272A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.