# AI System That Learns Normal Email Use to Spot and Stop Cyber Threats

> This 2023 patent describes an AI system that learns how your company normally uses email and then automatically takes action to stop cyber threats that behave unusually.

- **Patent:** US 11606373
- **Original title:** Cyber threat defense system protecting email networks with machine learning models
- **Owner:** Darktrace Holdings
- **Granted:** 2023
- **Status:** Active
- **Times cited:** 3
- **Field:** cybersecurity, software, ai_ml, telecommunications

## What it does

This patent is about a smart computer system designed to protect email networks from cyberattacks. It uses artificial intelligence, specifically machine learning models, that first learn what 'normal' looks like for both email activity and how people use their email within an organization. Then, a 'cyber-threat module' compares incoming emails and user actions against this learned normal behavior. It calculates a 'threat risk parameter' based on how unusual the activity is and if it looks like a known cyber threat pattern. If the risk gets high enough, an 'autonomous response module' automatically takes action to stop the threat, like isolating the suspicious email, without waiting for a person to step in. This system collects activity data using 'probes' and can even analyze the email's content and metadata for malicious signs.

## What it does NOT cover

- Systems that require a human to manually review every suspicious email before taking action.
- Cyber threat detection that only looks at email content and ignores user activity patterns.
- Systems that cannot automatically take containment actions when a threat is detected.
- Threat detection that doesn't learn and adapt to the specific 'normal' behavior of an organization or user.
- Cyber threat defense systems that are not specifically designed for email networks.

## The clever bit

The key innovation is combining the learning of 'normal' email and user behavior with specific cyber threat detection models. This allows the system to spot subtle deviations that might indicate a threat, even if it's a new type of attack, by comparing it against a continuously updated baseline of what's typical for that specific environment.

## Real-world examples

1. Darktrace Email Security
2. Automated cyber threat response platforms
3. AI-powered email filtering solutions

## Why it matters

As cyberattacks become more sophisticated, relying solely on human analysts to detect and respond to threats is too slow. This patent represents a move towards automated, AI-driven defense systems that can react at machine speed. It's part of the broader trend of using machine learning to enhance cybersecurity, particularly for protecting critical communication channels like email.

## Frequently asked questions

### What does AI System That Learns Normal Email Use to Spot and Stop Cyber Threats cover?

This 2023 patent describes an AI system that learns how your company normally uses email and then automatically takes action to stop cyber threats that behave unusually.

### Who owns patent US 11606373?

Darktrace Holdings owns this patent, granted in 2023.

### When does this patent expire?

This patent is expected to expire on February 19, 2039, when the invention enters the public domain.

### What is patent US 11606373 cited by?

This patent has been cited by 3 later patents that build on its ideas.

### What problem does this patent solve?

As cyberattacks become more sophisticated, relying solely on human analysts to detect and respond to threats is too slow. This patent represents a move towards automated, AI-driven defense systems that can react at machine speed. It's part of the broader trend of using machine learning to enhance cybersecurity, particularly for protecting critical communication channels like email.

### What does this patent NOT cover?

Systems that require a human to manually review every suspicious email before taking action.

**Full plain-English explainer:** https://patentbrief.org/patent/us/11606373/cyber-threat-defense-system-protecting-email-networks-with-machine-learning-mode

**Original patent:** https://patents.google.com/patent/US11606373

---

_Source: PatentBrief — https://patentbrief.org. Patent facts are from public records; the plain-English explanation is PatentBrief's._


## Related patents

Semantically similar inventions in the PatentBrief corpus:

- [How AI Explains Cyberattacks for Security Training](https://patentbrief.org/patent/us/20240406210/cyber-security-training-tool-that-uses-a-large-language-model) — This patent describes a cybersecurity training tool that uses a large language model to explain why machine learning identified a cyber threat, based on both fake and real attacks, for security teams and regular users.
- [How Multiple AI Models Detect Unusual Behavior on Computer Networks](https://patentbrief.org/patent/us/12438891/anomaly-detection-based-on-ensemble-machine-learning-model) — This patent describes a computer system that uses several artificial intelligence models working together to spot unusual and potentially dangerous activity from users or devices on a computer network.
- [How to Clean Files by Rebuilding Them Instead of Scanning Them](https://patentbrief.org/patent/us/9516045/azure-active-directory) — A security method that stops malware by rebuilding files from scratch based on strict format rules, rather than looking for known viruses.
- [How to Monitor Secure Government Computer Networks Automatically](https://patentbrief.org/patent/us/12244567/spacex-philosophy) — A system that automatically collects, organizes, and displays security data from highly secure government networks to help administrators spot potential threats or performance issues.
- [Preventing Sensitive Data Leaks from Company Communications](https://patentbrief.org/patent/us/9349016/windows-hello-biometric-login) — This patent describes a system that watches for unsent drafts of company communications, checks their content for sensitive data based on your current situation, and can block them or warn you if they seem risky.
