Automated intelligence gathering
    2.
    发明授权

    公开(公告)号:US11102244B1

    公开(公告)日:2021-08-24

    申请号:US15992752

    申请日:2018-05-30

    申请人: Agari Data, Inc.

    IPC分类号: H04L29/06 H04L12/58

    摘要: In one example, intelligence is gathered about an attacker that is attempting an attack via a malicious exploit message by exploiting the attacker's belief that the attack is succeeding. A received message (e.g., malicious message) sent from a first message account (e.g., attacker) to a second message account (e.g., intended victim) is received. A security risk associated with the received message is determined. It is determined that the security risk associated with the received message meets one or more criteria. Based on the determination that the security risk associated with the received message meets the one or more criteria, a responsive message is sent in response to the received message from a third message account (e.g., security service) to the first message account. The responsive message includes a content reference identified as referring to a content for a user of the first message account. In response to receiving a request made by the user of the first message account using the content reference, access to a message repository associated with the first message account is requested. Once access is granted, the message repository can be analyzed and intelligence about the first message account can be gathered and reported.

    Mitigating communication risk by detecting similarity to a trusted message contact

    公开(公告)号:US10992645B2

    公开(公告)日:2021-04-27

    申请号:US16399801

    申请日:2019-04-30

    申请人: Agari Data, Inc.

    IPC分类号: H04L29/06

    摘要: At least one of a measure of trust or a measure of spoofing risk associated with a sender of a message is determined. A measure of similarity between an identifier of the sender of the message and an identifier of at least one trusted contact of a recipient of the message is determined. The measure of similarity is combined with at least one of the measure of trust or the measure of spoofing risk to at least in part determine a combined measure of risk associated with the message. The sender of the message is not included in the at least one trusted contact of the recipient of the message. Based at least in part on the combined measure of risk associated with the message, the message is modified to alter content of a data field that includes an identification of the sender of the message.

    Mitigating communication risk by detecting similarity to a trusted message contact

    公开(公告)号:US10326735B2

    公开(公告)日:2019-06-18

    申请号:US15723524

    申请日:2017-10-03

    申请人: Agari Data, Inc.

    IPC分类号: H04L29/06

    摘要: A measure of similarity between an identifier of a sender of the message and each identifier of one or more identifiers of each trusted contact of a plurality of trusted contacts of a recipient of the message is determined. In the event the sender of the message is not any of the trusted contacts but at least one of the measure of similarity between the identifier of the sender of the message and a selected identifier of a selected trusted contact of the plurality of trusted contacts meets a threshold, the message is modified, if applicable, to alter content of a data field that includes an identification of the sender of the message. The data field is one of a plurality of data fields included in a header of the message.

    Mitigating communication risk by verifying a sender of a message

    公开(公告)号:US12074850B2

    公开(公告)日:2024-08-27

    申请号:US16941326

    申请日:2020-07-28

    申请人: Agari Data, Inc.

    IPC分类号: H04L9/40

    摘要: A first risk analysis of a message is performed. In the event the first risk analysis results in a determination that the message meets a first criteria, at least a portion of the message is modified prior to sending a modified version of the message to a specified recipient of the message, and a second risk analysis of the message is performed. The first risk analysis is performed before sending the modified version of the message and the modified version of the message is sent to the specified recipient of the message prior to a conclusion of the second risk analysis. In the event the second risk analysis results in a determination that the message meets a second criteria, content of the message that was previously prevented from being accessed by the specified recipient is provided to the specified recipient of the message.

    Mitigating communication risk by detecting similarity to a trusted message contact

    公开(公告)号:US11595354B2

    公开(公告)日:2023-02-28

    申请号:US17207139

    申请日:2021-03-19

    申请人: Agari Data, Inc.

    IPC分类号: H04L9/40

    摘要: At least one of a measure of trust or a measure of spoofing risk associated with a sender of a message is determined. A measure of similarity between an identifier of the sender of the message and an identifier of at least one trusted contact of a recipient of the message is determined. The measure of similarity is combined with at least one of the measure of trust or the measure of spoofing risk to at least in part determine a combined measure of risk associated with the message. Based at least in part on the combined measure of risk associated with the message, a verification action is performed including by automatically providing an inquiry message that requests a response to be provided.