US2023403296A1PendingUtilityA1

Analyses and aggregation of domain behavior for email threat detection by a cyber security system

Assignee: DARKTRACE HOLDINGS LTDPriority: Jun 9, 2022Filed: Jun 7, 2023Published: Dec 14, 2023
Est. expiryJun 9, 2042(~15.9 yrs left)· nominal 20-yr term from priority
H04L 63/1425H04L 63/1416H04L 63/1483H04L 63/1441H04L 63/1458H04L 63/0263H04L 63/145
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A cyber security appliance to protect a domain associated with an organization or user and global domain intelligence data store for centralized storage of analytic results is described. The cyber security appliance features a communication module including one or more input/output (I/O) ports, an email module, and an autonomous response module. The email module comprises email report analytic logic to analyze content within an email authentication report, received via the one or more I/O ports, to detect an email suspected of being malicious when the email is directed to a computing device operating outside of the domain and a source address of the email falsely identifying the domain as part of the source email address. The autonomous response module is configured to cause a first set of autonomous actions to mitigate similar email dissemination over a network.

Claims

exact text as granted — not AI-modified
1 . A cyber security appliance to protect a domain associated with an organization or user, comprising:
 a communication module including one or more input/output (I/O) ports;   an email module communicatively coupled to the communication module, the email module comprises email report analysis logic to analyze content within an email authentication report received via the one or more I/O ports to detect an email suspected of being malicious when the email is directed to a computing device operating outside of the domain and a source email address of the email falsely identifying the domain as part of the source email address; and   an autonomous response module communicatively coupled to the email module, the autonomous response module is configured to cause a first set of autonomous actions to mitigate similar email dissemination over a network.   
     
     
         2 . The cyber security appliance of  claim 1 , wherein the email module further comprises email authentication set-up logic configured to notify and assist domain administrators in response to the email report analysis logic identifying potential Domain Name System (DNS) sever misconfiguration based on the content of the email authentication report. 
     
     
         3 . The cyber security appliance of  claim 2 , wherein the email authentication report corresponds to a Domain-based Message Authentication, Reporting and Conformance (DMARC) aggregate report includes content associated with emails that utilize the domain as part of its source address. 
     
     
         4 . The cyber security appliance of  claim 3 , wherein the DMARC aggregate report includes content that identifies an email failing at least one of a plurality of authentications to categorize the email as malicious, the plurality of authentications include a Sender Policy Framework (SPF) authentication that confirms that the email is being sent from a mail server authorized to send emails on behalf of the domain and a DomainKeys Identified Mail (DKIM) authentication that confirms that the content of the email has not been modified during transit. 
     
     
         5 . The cyber security appliance of  claim 4 , wherein the plurality of authentications include DMARC authentication that detects whether a misalignment between an actual email address of an email sender and the source email address included within a From header field of the email identifying the domain as part of the source email address. 
     
     
         6 . The cyber security appliance of  claim 4 , wherein the autonomous response module configured to provide data to be rendered on a display to assist a domain administrator in configuring a DMARC record that adjusts the DMARC authentication or a SPF record that adjusts the SPF authentication. 
     
     
         7 . The cyber security appliance of  claim 1  further comprising:
 an inoculation module communicatively coupled to the email module, the inoculation module is configured to cause a second set of autonomous actions, wherein the second set of autonomous actions include one or more defensive actions including issuance of an alert or one or more offensive actions including issuance of a Denial of Service (DoS) attack on a malicious server from which the email originated. 
 
     
     
         8 . The cyber security appliance of  claim 1  communicatively coupled to a global domain intelligence data store to provide results of the analysis of the content within the email authentication report along with the content of the email authentication report to assist in reconfiguration of a plurality of email authentications conducted during transmission of the email and global tracking of behavior of a source of the suspected malicious email. 
     
     
         9 . Implemented within a cyber security appliance, a non-transitory storage medium configured to store instructions in a format that, when executed, identifies malicious spoofing and phishing emails to protect a domain associated with an organization or user, the non-transitory storage medium comprising:
 an email module including email report analysis logic to analyze content within an email authentication report received from an Internet Service Provider (ISP) to detect an email suspected of being malicious upon failure of an authentication process that detects when the email is directed to a computing device operating outside of the domain and a source address of the email falsely identifies the domain as part of the source email address; and   an autonomous response module communicatively coupled to the email module, the autonomous response module is configured to cause a first set of autonomous actions to mitigate similar email dissemination over a network.   
     
     
         10 . The non-transitory storage medium of  claim 9 , wherein the email module further comprises email authentication set-up logic configured to notify and assist domain administrators in response to the email report analysis logic identifying potential Domain Name System (DNS) sever misconfiguration based on the content of the email authentication report. 
     
     
         11 . The non-transitory storage medium of  claim 10 , wherein the email authentication report corresponds to a Domain-based Message Authentication, Reporting and Conformance (DMARC) aggregate report includes content associated with emails that utilize the domain as part of its source address. 
     
     
         12 . The non-transitory storage medium of  claim 11 , wherein the DMARC aggregate report includes content that identifies an email failing at least one of a plurality of authentications to categorize the email as malicious, the plurality of authentications include a Sender Policy Framework (SPF) authentication that confirms that the email is being sent from a mail server authorized to send emails on behalf of the domain and a DomainKeys Identified Mail (DKIM) authentication that confirms that the content of the email has not been modified during transit. 
     
     
         13 . The non-transitory storage medium of  claim 12 , wherein the plurality of authentications include DMARC authentication that detects whether a misalignment between an actual email address of an email sender and the source email address included within a From header field of the email identifying the domain as part of the source email address. 
     
     
         14 . The non-transitory storage medium of  claim 12 , wherein the autonomous response module configured to provide data to be rendered on a display to assist a domain administrator in configuring a DMARC record that adjusts the DMARC authentication or a SPF record that adjusts the SPF authentication. 
     
     
         15 . The non-transitory storage medium of  claim 9  further comprising:
 an inoculation module communicatively coupled to the email module, the inoculation module is configured to cause a second set of autonomous actions, wherein the second set of autonomous actions include one or more defensive actions including issuance of an alert or one or more offensive actions including issuance of a Denial of Service (DoS) attack on a malicious server from which the email originated. 
 
     
     
         16 . A method for a cyber security appliance to protect a domain associated with an organization or user, comprising:
 analyzing content within an email authentication report received from a resource external to the domain to determine whether an email, observed as using the domain as part of its source email address, has failed at least one of a plurality of email authentication processes, wherein the plurality of email authentication processes include (i) a first authentication process configured to confirm that the email is being sent from a mail server authorized to send emails on behalf of the domain, (ii) a second authentication process configured to confirm that the content of the email has not been modified during transit, and (iii) a third authentication process configured to detect misalignment between an actual email address of an email sender and the source email address included within a From header field of the email identifying the domain as part of the source email address;   determining whether the email corresponds to a suspected malicious email upon the email failing at least one of the plurality of email authentication processes; and   performing a first set of autonomous actions to mitigate continued dissemination of emails over a network by a malicious actor originating the suspected malicious email.   
     
     
         17 . The method of  claim 16 , wherein the first set of autonomous actions include (i) one or more defensive actions including issuance of an alert across to multiple cyber security appliances across multiple domains including the domain or (ii) one or more offensive actions including issuance of a Denial of Service (DoS) attack on a malicious server from which the suspected malicious email originated. 
     
     
         18 . The method of  claim 16 , wherein the first email authentication process corresponds to a Sender Policy Framework (SPF) authentication that confirms that the email is being sent from a mail server authorized to send emails on behalf of the domain, the second email authentication process corresponds to a DomainKeys Identified Mail (DKIM) authentication that confirms that the content of the email have not been modified during transit, and the third email authentication process corresponds to a DMARC authentication that detects whether a misalignment between an actual email address of an email sender and the source email address included within a From header field of the email identifying the domain as part of the source email address. 
     
     
         19 . The method of  claim 16  further comprising:
 provide results of an analysis of the content within the email authentication report along with the content of the email authentication report to a global domain intelligence data store to (i) provide real-time access of the results and the content to an administrator to assist in reconfiguration of one or more of the plurality of email authentication processes and (ii) enable global tracking of behavior of the email sender of the suspected malicious email.

Join the waitlist — get patent alerts

Track US2023403296A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.