Abnormal Security Corporation

États‑Unis d’Amérique

Retour au propriétaire

1-25 de 25 pour Abnormal Security Corporation Trier par
Recheche Texte
Affiner par
Type PI
        Brevet 23
        Marque 2
Juridiction
        États-Unis 17
        International 8
Date
2025 1
2024 2
2023 1
2022 9
2021 11
Voir plus
Classe IPC
H04L 9/40 - Protocoles réseaux de sécurité 13
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole 6
H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif 6
G06N 20/00 - Apprentissage automatique 5
G06Q 10/107 - Gestion informatisée du courrier électronique 5
Voir plus
Statut
En Instance 2
Enregistré / En vigueur 23

1.

A

      
Numéro de série 99080304
Statut En instance
Date de dépôt 2025-03-12
Propriétaire Abnormal Security Corporation (USA)
Classes de Nice  ? 42 - Services scientifiques, technologiques et industriels, recherche et conception

Produits et services

Providing online non-downloadable software using artificial intelligence for machine learning in the field of cybersecurity; Providing online non-downloadable software that utilizes machine learning to determine the normal communication behavior of individuals to identify unusual communication behavior; Computer services for analyzing digital activities to discover security threats; Computer services for analyzing digital communications occurring across email and messaging platforms to discover security threats; Computer security services, namely, online scanning, detecting, quarantining, and eliminating of viruses, worms, trojans, spyware, adware, malware, social engineering based instructions and exploits, and unauthorized data and programs from digital communications including emails and messages; Computer security services, namely, remediating instances of account takeover by restricting unauthorized access to accounts for email and messaging management services; Computer security services, namely, monitoring of computer systems to detect instances of account takeover; Software as a service (SaaS) featuring software for the analysis and protection of digital activities, communications, and accounts; Platform as a service (PaaS) featuring software-implemented platforms for the analysis and protection of digital activities, communications, and accounts; Email and messaging management services for others, namely, threat protection in the nature of monitoring computing systems to detect unauthorized access, data breach, and data exfiltration and storing digital communications recorded in electronic media; Software as a service (SaaS) featuring software for the analysis and protection of the security of network communications, cybersecurity, email management virus protection, email archiving, email continuity, and email security; Computer security consultancy; Computer security services for evaluating emails to identify fraudulent individuals and entities, such as vendors, and then monitoring via computer conduct of those fraudulent individuals and entities on an ongoing basis; Computer services for recording behaviors of individuals and entities deemed to be fraudulent in a blacklist for security purposes, namely, identifying and examining digital communications involving individuals and entities to identify security threats; Computer services for tracking digital activities of individuals and entities determined to be fraudulent based on an analysis of emails sent by those individuals and entities, namely, monitoring digital communications involving individuals and entities determined to be fraudulent to identify security threats; Computer services for generating a federated collection of individuals and entities to prevent security threats, namely, identifying and cataloging individuals' and entities' behaviors through analysis of digital communications

2.

INGESTING, STANDARDIZING, AND ANALYZING DIGITAL ACTIVITY INFORMATION FOR DETECTING THREATS

      
Numéro d'application US2024026105
Numéro de publication 2024/226684
Statut Délivré - en vigueur
Date de dépôt 2024-04-24
Date de publication 2024-10-31
Propriétaire ABNORMAL SECURITY CORPORATION (USA)
Inventeur(s)
  • Jeyakumar, Sanjay
  • Reiser, Evan
  • Bagri, Abhijit
  • Perez, Maritza
  • Edupuganti, Vineet
  • Gao, Yingkai
  • Gultepe, Umut
  • Yeh, Cheng-Lin
  • Philip, Mark
  • Khot, Tejas
  • Dawes, Thomas
  • Mahadik, Sanish
  • Snider, Benjamin
  • Li, Cheng
  • Balachundhar, Nirmal
  • Vellal, Adithya
  • Sonnabend, Lucas

Abrégé

Introduced here is a network-accessible platform (or simply "platform") that is designed to monitor digital activities that are performed across different services to ascertain, in real time, threats to the security of an enterprise. In order to surface insights into the threats posed to an enterprise, the platform can apply machine learning models to data that is representative of digital activities performed on different services with respective accounts. Each model may be trained to understand what constitutes normal behavior for a corresponding employee with respect to a single service or multiple services. Not only can these models be autonomously trained for the employees of the enterprise, but they can also be autonomously applied to detect, characterize, and catalog those digital activities that are indicative of a threat.

Classes IPC  ?

  • G06F 21/00 - Dispositions de sécurité pour protéger les calculateurs, leurs composants, les programmes ou les données contre une activité non autorisée
  • G06F 12/14 - Protection contre l'utilisation non autorisée de mémoire
  • H04L 43/00 - Dispositions pour la surveillance ou le test de réseaux de commutation de données
  • G06N 20/00 - Apprentissage automatique
  • H04L 9/40 - Protocoles réseaux de sécurité

3.

MULTISTAGE ANALYSIS OF EMAILS TO IDENTIFY SECURITY THREATS

      
Numéro d'application 18617282
Statut En instance
Date de dépôt 2024-03-26
Date de la première publication 2024-08-29
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Jeyakumar, Sanjay
  • Bratman, Jeshua Alexis
  • Chechik, Dmitry
  • Bagri, Abhijit
  • Reiser, Evan
  • Liao, Sanny Xiao Lang
  • Lee, Yu Zhou
  • Gasperi, Carlos Daniel
  • Lau, Kevin
  • Jiang, Kai Jing
  • Tan, Su Li Debbie
  • Kao, Jeremy
  • Yeh, Cheng-Lin

Abrégé

Access to emails delivered to an employee of an enterprise is received. An incoming email addressed to the employee is acquired. A primary attribute is extracted from the incoming email by parsing at least one of: (1) content of the incoming email or (2) metadata associated with the incoming email. It is determined whether the incoming email deviates from past email activity, at least in part by determining, as a secondary attribute, a mismatch between a previous value for the primary attribute and a current value for the primary attribute, using a communication profile associated with the employee, and providing a measured deviation to at least one machine learning model.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06F 16/951 - IndexationTechniques d’exploration du Web
  • G06F 16/955 - Recherche dans le Web utilisant des identifiants d’information, p. ex. des localisateurs uniformisés de ressources [uniform resource locators - URL]
  • G06F 16/958 - Organisation ou gestion de contenu de sites Web, p. ex. publication, conservation de pages ou liens automatiques
  • G06N 20/00 - Apprentissage automatique
  • G06Q 10/107 - Gestion informatisée du courrier électronique

4.

Deriving and surfacing insights regarding security threats

      
Numéro d'application 17942931
Numéro de brevet 11704406
Statut Délivré - en vigueur
Date de dépôt 2022-09-12
Date de la première publication 2023-01-19
Date d'octroi 2023-07-18
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Lee, Yu Zhou
  • Jiang, Kai
  • Tan, Su Li Debbie
  • Sng, Geng
  • Yeh, Cheng-Lin
  • Moore, Lawrence Stockton
  • Liao, Sanny Xiao Lang
  • Cerquera, Joey Esteban
  • Bratman, Jeshua Alexis
  • Jeyakumar, Sanjay
  • Karandikar, Nishant Bhalchandra

Abrégé

Deriving and surfacing insights regarding security threats is disclosed. A plurality of features associated with a message is determined. A plurality of facet models is used to analyze the determined features. Based at least in part on the analysis, it is determined that the message poses a security threat. A prioritized set of information is determined to be provided as output that is representative of why the message was determined to pose a security threat. At least a portion of the prioritized set of information is provided as output.

Classes IPC  ?

  • G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures

5.

Investigation of threats using queryable records of behavior

      
Numéro d'application 17888899
Numéro de brevet 12231453
Statut Délivré - en vigueur
Date de dépôt 2022-08-16
Date de la première publication 2022-12-08
Date d'octroi 2025-02-18
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Kao, Jeremy
  • Jiang, Kai Jing
  • Jeyakumar, Sanjay
  • Jung, Yea So
  • Gasperi, Carlos Daniel
  • Young, Justin Anthony

Abrégé

Techniques for producing records of digital activities that are performed with accounts associated with employees of enterprises are disclosed. Such techniques can be used to ensure that records are created for digital activities that are deemed unsafe and for digital activities that are deemed safe by a threat detection platform. At a high level, more comprehensively recording digital activities not only provides insight into the behavior of individual accounts, but also provides insight into the holistic behavior of employees across multiple accounts. These records may be stored in a searchable datastore to enable expedient and efficient review.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 67/125 - Protocoles spécialement adaptés aux environnements propriétaires ou de mise en réseau pour un usage spécial, p. ex. les réseaux médicaux, les réseaux de capteurs, les réseaux dans les véhicules ou les réseaux de mesure à distance en impliquant la commande des applications des terminaux par un réseau

6.

Detection and prevention of external fraud

      
Numéro d'application 17877768
Numéro de brevet 11706247
Statut Délivré - en vigueur
Date de dépôt 2022-07-29
Date de la première publication 2022-11-17
Date d'octroi 2023-07-18
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Lee, Yu Zhou
  • Moore, Lawrence Stockton
  • Bratman, Jeshua Alexis
  • Xu, Lei
  • Jeyakumar, Sanjay

Abrégé

Techniques for detecting instances of external fraud by monitoring digital activities that are performed with accounts associated with an enterprise are disclosed. In one example, a threat detection platform determines the likelihood that an incoming email is indicative of external fraud based on the context and content of the incoming email. To understand the risk posed by an incoming email, the threat detection platform may seek to determine not only whether the sender normally communicates with the recipient, but also whether the topic is one normally discussed by the sender and recipient. In this way, the threat detection platform can establish whether the incoming email deviates from past emails exchanged between the sender and recipient.

Classes IPC  ?

  • H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 51/08 - Informations annexes, p. ex. pièces jointes
  • H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif

7.

Multichannel threat detection for protecting against account compromise

      
Numéro d'application 17861192
Numéro de brevet 11663303
Statut Délivré - en vigueur
Date de dépôt 2022-07-09
Date de la première publication 2022-10-27
Date d'octroi 2023-05-30
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Habal, Rami Faris
  • Bagri, Abhijit
  • Jung, Yea So
  • Deng, Fang Shuo
  • Kao, Jeremy
  • Bratman, Jeshua Alexis
  • Gultepe, Umut
  • Muthakana, Hariank Sagar

Abrégé

Techniques for building, training, or otherwise developing models of the behavior of employees across more than one channel used for communication are disclosed. These models can be stored in profiles that are associated with the employees. Such profiles allow behavior to be monitored across multiple channels so that deviations can be detected and then examined. Remediation can be performed if an account is determined to be compromised based on its recent activity.

Classes IPC  ?

  • G06F 21/31 - Authentification de l’utilisateur
  • G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès
  • G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
  • G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures

8.

Discovering email account compromise through assessments of digital activities

      
Numéro d'application 17751261
Numéro de brevet 12081522
Statut Délivré - en vigueur
Date de dépôt 2022-05-23
Date de la première publication 2022-09-08
Date d'octroi 2024-09-03
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Chechik, Dmitry
  • Gultepe, Umut
  • Kargon, Raphael
  • Bratman, Jeshua Alexis
  • Yeh, Cheng-Lin
  • Liao, Sanny Xiao Lang
  • Ludert, Erin Elisabeth Edkins
  • Jeyakumar, Sanjay
  • Muthakana, Hariank Sagar

Abrégé

Introduced here are threat detection platforms designed to discover possible instances of email account compromise in order to identify threats to an enterprise. In particular, a threat detection platform can examine the digital activities performed with the email accounts associated with employees of the enterprise to determine whether any email accounts are exhibiting abnormal behavior. Examples of digital activities include the reception of an incoming email, transmission of an outgoing email, creation of a mail filter, and occurrence of a sign-in event (also referred to as a “login event”). Thus, the threat detection platform can monitor the digital activities performed with a given email account to determine the likelihood that the given email account has been compromised.

Classes IPC  ?

  • G06F 15/16 - Associations de plusieurs calculateurs numériques comportant chacun au moins une unité arithmétique, une unité programme et un registre, p. ex. pour le traitement simultané de plusieurs programmes
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif
  • H04L 51/222 - Surveillance ou traitement des messages en utilisant des informations de localisation géographique, p. ex. des messages transmis ou reçus à proximité d'un certain lieu ou d'une certaine zone

9.

Multistage analysis of emails to identify security threats

      
Numéro d'application 17677822
Numéro de brevet 11973772
Statut Délivré - en vigueur
Date de dépôt 2022-02-22
Date de la première publication 2022-09-01
Date d'octroi 2024-04-30
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Jeyakumar, Sanjay
  • Bratman, Jeshua Alexis
  • Chechik, Dmitry
  • Bagri, Abhijit
  • Reiser, Evan
  • Liao, Sanny Xiao Lang
  • Lee, Yu Zhou
  • Gasperi, Carlos Daniel
  • Lau, Kevin
  • Jiang, Kai
  • Tan, Su Li Debbie
  • Kao, Jeremy
  • Yeh, Cheng-Lin

Abrégé

Conventional email filtering services are not suitable for recognizing sophisticated malicious emails, and therefore may allow sophisticated malicious emails to reach inboxes by mistake. Introduced here are threat detection platforms designed to take an integrative approach to detecting security threats. For example, after receiving input indicative of an approval from an individual to access past email received by employees of an enterprise, a threat detection platform can download past emails to build a machine learning (ML) model that understands the norms of communication with internal contacts (e.g., other employees) and/or external contacts (e.g., vendors). By applying the ML model to incoming email, the threat detection platform can identify security threats in real time in a targeted manner.

Classes IPC  ?

  • G06N 20/00 - Apprentissage automatique
  • G06F 16/951 - IndexationTechniques d’exploration du Web
  • G06F 16/955 - Recherche dans le Web utilisant des identifiants d’information, p. ex. des localisateurs uniformisés de ressources [uniform resource locators - URL]
  • G06F 16/958 - Organisation ou gestion de contenu de sites Web, p. ex. publication, conservation de pages ou liens automatiques
  • G06Q 10/107 - Gestion informatisée du courrier électronique
  • H04L 9/40 - Protocoles réseaux de sécurité

10.

Discovering graymail through real-time analysis of incoming email

      
Numéro d'application 17743048
Numéro de brevet 11683284
Statut Délivré - en vigueur
Date de dépôt 2022-05-12
Date de la première publication 2022-08-25
Date d'octroi 2023-06-20
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Habal, Rami F.
  • Lau, Kevin
  • Sankar, Sharan Dev
  • Jung, Yea So
  • Purushottam, Dhruv
  • Krishnamoorthi, Venkat
  • Wang, Franklin X.
  • Bratman, Jeshua Alexis
  • Beauchesne, Jocelyn Mikael Raphael
  • Bagri, Abhijit
  • Jeyakumar, Sanjay

Abrégé

Techniques for identifying and processing graymail are disclosed. An electronic message store is accessed. A determination is made that a first message included in the electronic message store represents graymail, including by accessing a profile associated with an addressee of the first message. A remedial action is taken in response to determining that the first message represents graymail.

Classes IPC  ?

  • H04L 51/08 - Informations annexes, p. ex. pièces jointes
  • H04L 51/42 - Aspects liés aux boîtes aux lettres, p. ex. synchronisation des boîtes aux lettres
  • H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif
  • G06Q 10/107 - Gestion informatisée du courrier électronique
  • G06F 9/54 - Communication interprogramme

11.

Abuse mailbox for facilitating discovery, investigation, and analysis of email-based threats

      
Numéro d'application 17550848
Numéro de brevet 11949713
Statut Délivré - en vigueur
Date de dépôt 2021-12-14
Date de la première publication 2022-08-11
Date d'octroi 2024-04-02
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Reiser, Evan
  • Kao, Jeremy
  • Yeh, Cheng-Lin
  • Jung, Yea So
  • Jiang, Kai Jing
  • Bagri, Abhijit
  • Tan, Su Li Debbie
  • Kishnamoorthi, Venkatram
  • Deng, Feng Shuo

Abrégé

Introduced here are computer programs and computer-implemented techniques for discovering malicious emails and then remediating the threat posed by those malicious emails in an automated manner. A threat detection platform may monitor a mailbox to which employees of an enterprise are able to forward emails deemed to be suspicious for analysis. This mailbox may be referred to as an “abuse mailbox” or “phishing mailbox.” The threat detection platform can examine emails contained in the abuse mailbox and then determine whether any of those emails represent threats to the security of the enterprise. For example, the threat detection platform may classify each email contained in the abuse mailbox as being malicious or non-malicious. Thereafter, the threat detection platform may determine what remediation actions, if any, are appropriate for addressing the threat posed by those emails determined to be malicious.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06F 16/9035 - Filtrage basé sur des données supplémentaires, p. ex. sur des profils d'utilisateurs ou de groupes
  • G06Q 10/107 - Gestion informatisée du courrier électronique

12.

Threat detection platforms for detecting, characterizing, and remediating email-based threats in real time

      
Numéro d'application 17498273
Numéro de brevet 11552969
Statut Délivré - en vigueur
Date de dépôt 2021-10-11
Date de la première publication 2022-01-27
Date d'octroi 2023-01-10
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Jeyakumar, Sanjay
  • Bratman, Jeshua Alexis
  • Chechik, Dmitry
  • Bagri, Abhijit
  • Reiser, Evan
  • Liao, Sanny Xiao Lang
  • Lee, Yu Zhou
  • Gasperi, Carlos Daniel
  • Lau, Kevin
  • Jiang, Kai Jing
  • Tan, Su Li Debbie
  • Kao, Jeremy
  • Yeh, Cheng-Lin

Abrégé

Conventional email filtering services are not suitable for recognizing sophisticated malicious emails, and therefore may allow sophisticated malicious emails to reach inboxes by mistake. Introduced here are threat detection platforms designed to take an integrative approach to detecting security threats. For example, after receiving input indicative of an approval from an individual to access past email received by employees of an enterprise, a threat detection platform can download past emails to build a machine learning (ML) model that understands the norms of communication with internal contacts (e.g., other employees) and/or external contacts (e.g., vendors). By applying the ML model to incoming email, the threat detection platform can identify security threats in real time in a targeted manner.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus

13.

Detection and prevention of external fraud

      
Numéro d'application 17491184
Numéro de brevet 11496505
Statut Délivré - en vigueur
Date de dépôt 2021-09-30
Date de la première publication 2022-01-20
Date d'octroi 2022-11-08
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Lee, Yu Zhou
  • Moore, Lawrence Stockton
  • Bratman, Jeshua Alexis
  • Xu, Lei
  • Jeyakumar, Sanjay

Abrégé

Techniques for detecting instances of external fraud by monitoring digital activities that are performed with accounts associated with an enterprise are disclosed. In one example, a threat detection platform determines the likelihood that an incoming email is indicative of external fraud based on the context and content of the incoming email. To understand the risk posed by an incoming email, the threat detection platform may seek to determine not only whether the sender normally communicates with the recipient, but also whether the topic is one normally discussed by the sender and recipient. In this way, the threat detection platform can establish whether the incoming email deviates from past emails exchanged between the sender and recipient.

Classes IPC  ?

  • H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 51/00 - Messagerie d'utilisateur à utilisateur dans des réseaux à commutation de paquets, transmise selon des protocoles de stockage et de retransmission ou en temps réel, p. ex. courriel
  • H04L 51/08 - Informations annexes, p. ex. pièces jointes

14.

Estimating risk posed by interacting with third parties through analysis of emails addressed to employees of multiple enterprises

      
Numéro d'application 17401143
Numéro de brevet 11483344
Statut Délivré - en vigueur
Date de dépôt 2021-08-12
Date de la première publication 2021-12-02
Date d'octroi 2022-10-25
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Bratman, Jeshua Alexis
  • Lee, Yu Zhou
  • Moore, Lawrence Stockton
  • Habal, Rami Faris
  • Xu, Lei

Abrégé

Introduced here are computer programs and computer-implemented techniques for generating and then managing a federated database that can be used to ascertain the risk in interacting with vendors. At a high level, the federated database allows knowledge regarding the reputation of vendors to be shared amongst different enterprises with which those vendors may interact. A threat detection platform may utilize the federated database when determining how to handle incoming emails from vendors.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06Q 10/10 - BureautiqueGestion du temps
  • G06Q 10/06 - Ressources, gestion de tâches, des ressources humaines ou de projetsPlanification d’entreprise ou d’organisationModélisation d’entreprise ou d’organisation
  • H04L 67/30 - Profils
  • G06F 16/335 - Filtrage basé sur des données supplémentaires, p. ex. sur des profils d’utilisateurs ou de groupes
  • H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif
  • H04L 51/214 - Surveillance ou traitement des messages en utilisant le transfert sélectif
  • H04L 67/50 - Services réseau
  • G06F 16/25 - Systèmes d’intégration ou d’interfaçage impliquant les systèmes de gestion de bases de données

15.

Approaches to creating, managing, and applying a federated database to establish risk posed by third parties

      
Numéro d'application 17401161
Numéro de brevet 11477235
Statut Délivré - en vigueur
Date de dépôt 2021-08-12
Date de la première publication 2021-12-02
Date d'octroi 2022-10-18
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Bratman, Jeshua Alexis
  • Lee, Yu Zhou
  • Moore, Lawrence Stockton
  • Habal, Rami Faris
  • Xu, Lei

Abrégé

Introduced here are computer programs and computer-implemented techniques for generating and then managing a federated database that can be used to ascertain the risk in interacting with vendors. At a high level, the federated database allows knowledge regarding the reputation of vendors to be shared amongst different enterprises with which those vendors may interact. A threat detection platform may utilize the federated database when determining how to handle incoming emails from vendors.

Classes IPC  ?

  • H04L 9/40 - Protocoles réseaux de sécurité
  • G06Q 10/10 - BureautiqueGestion du temps
  • G06Q 10/06 - Ressources, gestion de tâches, des ressources humaines ou de projetsPlanification d’entreprise ou d’organisationModélisation d’entreprise ou d’organisation
  • H04L 67/30 - Profils
  • G06F 16/335 - Filtrage basé sur des données supplémentaires, p. ex. sur des profils d’utilisateurs ou de groupes
  • H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif
  • H04L 51/214 - Surveillance ou traitement des messages en utilisant le transfert sélectif
  • H04L 67/50 - Services réseau
  • G06F 16/25 - Systèmes d’intégration ou d’interfaçage impliquant les systèmes de gestion de bases de données

16.

DETECTION AND PREVENTION OF EXTERNAL FRAUD

      
Numéro d'application US2021028917
Numéro de publication 2021/217049
Statut Délivré - en vigueur
Date de dépôt 2021-04-23
Date de publication 2021-10-28
Propriétaire ABNORMAL SECURITY CORPORATION (USA)
Inventeur(s)
  • Lee, Yu Zhou
  • Moore, Lawrence Stockton
  • Bratman, Jeshua Alexis
  • Xu, Lei
  • Jeyakumar, Sanjay

Abrégé

Introduced here are computer programs and computer-implemented techniques for detecting instances of external fraud by monitoring digital activities that are performed with accounts associated with an enterprise. A threat detection platform may determine the likelihood that an incoming email is indicative of external fraud based on the context and content of the incoming email. For example, to understand the risk posed by an incoming email, the threat detection platform may seek to determine not only whether the sender normally communicates with the recipient, but also whether the topic is one normally discussed by the sender and recipient. In this way, the threat detection platform can establish whether the incoming email deviates from past emails exchanged between the sender and recipient.

Classes IPC  ?

  • G06F 11/00 - Détection d'erreursCorrection d'erreursContrôle de fonctionnement

17.

Retrospective learning of communication patterns by machine learning models for discovering abnormal behavior

      
Numéro d'application 17361106
Numéro de brevet 11743294
Statut Délivré - en vigueur
Date de dépôt 2021-06-28
Date de la première publication 2021-10-21
Date d'octroi 2023-08-29
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Jeyakumar, Sanjay
  • Bratman, Jeshua Alexis
  • Chechik, Dmitry
  • Bagri, Abhijit
  • Reiser, Evan James
  • Liao, Sanny Xiao Yang
  • Lee, Yu Zhou
  • Gasperi, Carlos Daniel
  • Lau, Kevin
  • Jiang, Kai Jing
  • Tan, Su Li Debbie
  • Kao, Jeremy
  • Yeh, Cheng-Lin

Abrégé

Conventional email filtering services are not suitable for recognizing sophisticated malicious emails, and therefore may allow sophisticated malicious emails to reach inboxes by mistake. Introduced here are threat detection platforms designed to take an integrative approach to detecting security threats. For example, after receiving input indicative of an approval from an individual to access past email received by employees of an enterprise, a threat detection platform can download past emails to build a machine learning (ML) model that understands the norms of communication with internal contacts (e.g., other employees) and/or external contacts (e.g., vendors). By applying the ML model to incoming email, the threat detection platform can identify security threats in real time in a targeted manner.

Classes IPC  ?

  • H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
  • G06N 20/00 - Apprentissage automatique
  • H04L 9/40 - Protocoles réseaux de sécurité

18.

A

      
Numéro de série 97053007
Statut Enregistrée
Date de dépôt 2021-09-29
Date d'enregistrement 2026-02-10
Propriétaire Abnormal Security Corporation (USA)
Classes de Nice  ? 42 - Services scientifiques, technologiques et industriels, recherche et conception

Produits et services

Providing online non-downloadable software using artificial intelligence for machine learning in the field of cybersecurity; Providing online non-downloadable software that utilizes machine learning to determine the normal communication behavior of individuals to identify unusual communication behavior; Computer services for analyzing digital activities to discover security threats; Computer services for analyzing digital communications occurring across email and messaging platforms to discover security threats; Computer security services, namely, online scanning, detecting, quarantining, and eliminating of viruses, worms, trojans, spyware, adware, malware, social engineering based instructions and exploits, and unauthorized data and programs from digital communications including emails and messages; Computer security services, namely, remediating instances of account takeover by restricting unauthorized access to accounts for email and messaging management services; Computer security services, namely, monitoring of computer systems to detect instances of account takeover; Software as a service (SaaS) featuring software for the analysis and protection of digital activities, communications, and accounts; Platform as a service (PaaS) featuring software-implemented platforms for the analysis and protection of digital activities, communications, and accounts; Email and messaging management services for others, namely, threat protection in the nature of monitoring computing systems to detect unauthorized access, data breach, and data exfiltration and storing digital communications recorded in electronic media; Software as a service (SaaS) featuring software for the analysis and protection of the security of network communications, cybersecurity, email management virus protection, email archiving, email continuity, and email security; Computer security consultancy; Computer services for evaluating emails to identify fraudulent individuals and entities, such as vendors, and then monitoring via computer conduct of those fraudulent individuals and entities on an ongoing basis; Computer services for recording behaviors of individuals and entities deemed to be fraudulent in a blacklist for security purposes, namely, identifying and examining digital communications involving individuals and entities to identify security threats; Computer services for tracking digital activities of individuals and entities determined to be fraudulent based on an analysis of emails sent by those individuals and entities, namely, monitoring digital communications involving individuals and entities determined to be fraudulent to identify security threats; Computer services for generating a federated collection of individuals and entities to prevent security threats, namely, identifying and cataloging individuals' and entities' behaviors through analysis of digital communications

19.

Programmatic discovery, retrieval, and analysis of communications to identify abnormal communication activity

      
Numéro d'application 17341200
Numéro de brevet 12255915
Statut Délivré - en vigueur
Date de dépôt 2021-06-07
Date de la première publication 2021-09-23
Date d'octroi 2025-03-18
Propriétaire Abnormal Security Corporation (USA)
Inventeur(s)
  • Jeyakumar, Sanjay
  • Bratman, Jeshua Alexis
  • Chechik, Dmitry
  • Bagri, Abhijit
  • Reiser, Evan James
  • Liao, Sanny Xiao Yang
  • Lee, Yu Zhou
  • Gasperi, Carlos Daniel
  • Lau, Kevin
  • Jiang, Kai Jing
  • Tan, Su Li Debbie
  • Kao, Jeremy
  • Yeh, Cheng-Lin

Abrégé

Conventional email filtering services are not suitable for recognizing sophisticated malicious emails, and therefore may allow sophisticated malicious emails to reach inboxes by mistake. Introduced here are threat detection platforms designed to take an integrative approach to detecting security threats. For example, after receiving input indicative of an approval from an individual to access past email received by employees of an enterprise, a threat detection platform can download past emails to build a machine learning (ML) model that understands the norms of communication with internal contacts (e.g., other employees) and/or external contacts (e.g., vendors). By applying the ML model to incoming email, the threat detection platform can identify security threats in real time in a targeted manner.

Classes IPC  ?

  • H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
  • G06F 16/901 - IndexationStructures de données à cet effetStructures de stockage
  • G06Q 10/107 - Gestion informatisée du courrier électronique
  • H04L 9/40 - Protocoles réseaux de sécurité
  • H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
  • H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif

20.

IMPROVED INVESTIGATION OF THREATS USING QUERYABLE RECORDS OF BEHAVIOR

      
Numéro d'application US2021022190
Numéro de publication 2021/183939
Statut Délivré - en vigueur
Date de dépôt 2021-03-12
Date de publication 2021-09-16
Propriétaire ABNORMAL SECURITY CORPORATION (USA)
Inventeur(s)
  • Kao, Jeremy
  • Jiang, Kai Jing
  • Jeyakumar, Sanjay
  • Jung, Yea So
  • Gasperi, Carlos Daniel
  • Young, Justin Anthony

Abrégé

Introduced here are computer programs and computer-implemented techniques for producing records of digital activities that are performed with accounts associated with employees of enterprises. Such an approach ensures that records are created for digital activities that are deemed unsafe and for digital activities that are deemed safe by a threat detection platform. At a high level, more comprehensively recording digital activities not only provides insight into the behavior of individual accounts, but also provides insight into the holistic behavior of employees across multiple accounts. These records may be stored in a searchable datastore to enable expedient and efficient review.

Classes IPC  ?

  • G06F 11/00 - Détection d'erreursCorrection d'erreursContrôle de fonctionnement

21.

ABUSE MAILBOX FOR FACILITATING DISCOVERY, INVESTIGATION, AND ANALYSIS OF EMAIL-BASED THREATS

      
Numéro d'application US2021019965
Numéro de publication 2021/178243
Statut Délivré - en vigueur
Date de dépôt 2021-02-26
Date de publication 2021-09-10
Propriétaire ABNORMAL SECURITY CORPORATION (USA)
Inventeur(s)
  • Reiser, Evan James
  • Kao, Jeremy
  • Yeh, Cheng-Lin
  • Jung, Yea So
  • Jiang, Kai Jing
  • Bagri, Abhijit
  • Tan, Su Li Debbie
  • Krishnamoorthi, Venkatram
  • Deng, Fang Shuo

Abrégé

Introduced here are computer programs and computer-implemented techniques for discovering malicious emails and then remediating the threat posed by those malicious emails in an automated manner. A threat detection platform may monitor a mailbox to which employees of an enterprise are able to forward emails deemed to be suspicious for analysis. This mailbox may be referred to as an "abuse mailbox" or "phishing mailbox." The threat detection platform can examine emails contained in the abuse mailbox and then determine whether any of those emails represent threats to the security of the enterprise. For example, the threat detection platform may classify each email contained in the abuse mailbox as being malicious or non-malicious. Thereafter, the threat detection platform may determine what remediation actions, if any, are appropriate for addressing the threat posed by those emails determined to be malicious.

Classes IPC  ?

  • H04L 12/58 - Systèmes de commutation de messages
  • G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
  • G06Q 10/10 - BureautiqueGestion du temps
  • G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus

22.

MULTICHANNEL THREAT DETECTION FOR PROTECTING AGAINST ACCOUNT COMPROMISE

      
Numéro d'application US2021020499
Numéro de publication 2021/178423
Statut Délivré - en vigueur
Date de dépôt 2021-03-02
Date de publication 2021-09-10
Propriétaire ABNORMAL SECURITY CORPORATION (USA)
Inventeur(s)
  • Habal, Rami Faris
  • Bagri, Abhijit
  • Jung, Yea So
  • Deng, Fang Shuo
  • Kao, Jeremy
  • Bratman, Jeshua Alexis
  • Gultepe, Umut
  • Muthakana, Hariank Sagar

Abrégé

Introduced here are computer programs and computer-implemented techniques for building, training, or otherwise developing models of the behavior of employees across more than one channel used for communication. These models can be stored in profiles that are associated with the employees. At a high level, these profiles allow behavior to be monitored across multiple channels so that deviations can be detected and then examined. Moreover, remediation may be performed if an account is determined to be compromised based on its recent activity.

Classes IPC  ?

  • H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
  • G06F 17/30 - Recherche documentaire; Structures de bases de données à cet effet
  • G06Q 10/06 - Ressources, gestion de tâches, des ressources humaines ou de projetsPlanification d’entreprise ou d’organisationModélisation d’entreprise ou d’organisation
  • G06Q 50/00 - Technologies de l’information et de la communication [TIC] spécialement adaptées à la mise en œuvre des procédés d’affaires d’un secteur particulier d’activité économique, p. ex. aux services d’utilité publique ou au tourisme

23.

FEDERATED DATABASE FOR ESTABLISHING AND TRACKING RISK OF INTERACTIONS WITH THIRD PARTIES

      
Numéro d'application US2021019977
Numéro de publication 2021/174050
Statut Délivré - en vigueur
Date de dépôt 2021-02-26
Date de publication 2021-09-02
Propriétaire ABNORMAL SECURITY CORPORATION (USA)
Inventeur(s)
  • Bratman, Jeshua Alexis
  • Lee, Yu Zhou
  • Moore, Lawrence Stockton
  • Habal, Rami Faris
  • Xu, Lei

Abrégé

Introduced here are computer programs and computer-implemented techniques for generating and then managing a federated database that can be used to ascertain the risk in interacting with vendors. At a high level, the federated database allows knowledge regarding the reputation of vendors to be shared amongst different enterprises with which those vendors may interact. A threat detection platform may utilize the federated database when determining how to handle incoming emails from vendors.

Classes IPC  ?

  • G06F 7/00 - Procédés ou dispositions pour le traitement de données en agissant sur l'ordre ou le contenu des données maniées
  • H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole

24.

DISCOVERING EMAIL ACCOUNT COMPROMISE THROUGH ASSESSMENTS OF DIGITAL ACTIVITIES

      
Numéro d'application US2021019030
Numéro de publication 2021/168407
Statut Délivré - en vigueur
Date de dépôt 2021-02-22
Date de publication 2021-08-26
Propriétaire ABNORMAL SECURITY CORPORATION (USA)
Inventeur(s)
  • Chechik, Dmitry
  • Gultepe, Umut
  • Kargon, Raphael
  • Bratman, Jeshua Alexis
  • Yeh, Cheng-Lin
  • Liao, Sanny Xiao Lang
  • Ludert, Erin Elisabeth Edkins
  • Jeyakumar, Sanjay
  • Muthakana, Hariank

Abrégé

Introduced here are threat detection platforms designed to discover possible instances of email account compromise in order to identify threats to an enterprise. In particular, a threat detection platform can examine the digital activities performed with the email accounts associated with employees of the enterprise to determine whether any email accounts are exhibiting abnormal behavior. Examples of digital activities include the reception of an incoming email, transmission of an outgoing email, creation of a mail filter, and occurrence of a sign-in event (also referred to as a "login event"). Thus, the threat detection platform can monitor the digital activities performed with a given email account to determine the likelihood that the given email account has been compromised.

Classes IPC  ?

  • G06F 11/00 - Détection d'erreursCorrection d'erreursContrôle de fonctionnement

25.

THREAT DETECTION PLATFORMS FOR DETECTING, CHARACTERIZING, AND REMEDIATING EMAIL-BASED THREATS IN REAL TIME

      
Numéro d'application US2019067279
Numéro de publication 2020/132137
Statut Délivré - en vigueur
Date de dépôt 2019-12-18
Date de publication 2020-06-25
Propriétaire ABNORMAL SECURITY CORPORATION (USA)
Inventeur(s)
  • Jeyakumar, Sanjay
  • Bratman, Jeshua
  • Chechik, Dmitry
  • Bagri, Abhijit
  • Reiser, Evan
  • Liao, Sanny Xiao Yang
  • Lee, Yu, Zhou
  • Gasperi, Carlos, Daniel
  • Lau, Kevin
  • Jiang, Kai, Jing
  • Tan, Su, Li Debbie
  • Kao, Jeremy
  • Yeh, Cheng-Lin

Abrégé

Conventional email filtering services are not suitable for recognizing sophisticated malicious emails, and therefore may allow sophisticated malicious emails to reach inboxes by mistake. Introduced here are threat detection platforms designed to take an integrative approach to detecting security threats. For example, after receiving input indicative of an approval from an individual to access past email received by employees of an enterprise, a threat detection platform can download past emails to build a machine learning (ML) model that understands the norms of communication with internal contacts (e.g., other employees) and/or external contacts (e.g., vendors). By applying the ML model to incoming email, the threat detection platform can identify security threats in real time in a targeted manner.

Classes IPC  ?

  • G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
  • G06F 21/50 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation
  • G06N 20/00 - Apprentissage automatique
  • H04L 29/02 - Commande de la communication; Traitement de la communication