Enhanced message content security
Systems and methods for redacting malicious URLs and other activatable content from messages are disclosed. A content analysis system may receive a text message or a multimedia message and determine whether a URL is contained in such a message. If so, the content analysis system may determine the maliciousness of the URL using various techniques, redacting the URL from the message before providing it to the user device if the URL is determined to be malicious. The original message may be stored for user access if desired.
1 . A method performed by a content analysis system, the method comprising:
receiving, at a processor configured at the content analysis system, a first message comprising textual content;
determining, by the processor, a uniform resource locator (URL) within the textual content;
generating, by the processor, a cryptographic hash digest based at least in part on the textual content;
determining, by the processor and based at least in part on a content data store and the cryptographic hash digest, a maliciousness of the URL, wherein determining the maliciousness of the URL comprises determining that the URL is malicious when a message detection counter associated with an entry corresponding to the cryptographic hash digest in the content data store meets or exceeds a message detection counter threshold value, the message detection counter indicating a number of received messages that are detected as having a matching digest to the cryptographic hash digest;
generating, by the processor and based at least in part on the maliciousness of the URL, a second message by redacting the URL from the first message; and
transmitting, from the processor to a message controller, the second message for transmission to a user equipment (UE).
2 . The method of claim 1 , wherein determining the maliciousness of the URL comprises determining that the URL is malicious when a malicious URL flag is set for an entry associated with the cryptographic hash digest in the content data store.
3 . The method of claim 2 , further comprising:
transmitting a query comprising the URL to a malicious URL database; and
setting the malicious URL flag for the entry associated with the cryptographic hash digest in the content data store based at least in part on a response received for the malicious URL database.
4 . The method of claim 1 , wherein:
the first message further comprises at least one of image content or video content, and
the textual content comprises metadata associated with at least one of the image content or the video content.
5 . The method of claim 1 , further comprising:
receiving, at the processor, a third message comprising second textual content;
determining, by the processor, that the second textual content excludes any URL; and
transmitting, from the processor to the message controller and based at least in part on determining that the second textual content excludes any URL, the third message for transmission to a second UE.
6 . A content analysis system comprising:
one or more processors;
one or more transceivers; and
non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:
receiving a first message comprising textual content;
determining a uniform resource locator (URL) within the textual content;
generating a cryptographic hash digest based at least in part on the textual content;
modifying an entry in a content data store based at least in part on the cryptographic hash digest;
determining a maliciousness of the URL, wherein determining the maliciousness of the URL comprises determining that the URL is malicious when the message detection counter meets or exceeds a message detection counter threshold value, the message detection counter indicating a number of received messages that are detected as having a matching digest to the cryptographic hash digest;
generating, based at least in part on the maliciousness of the URL, a second message by redacting the URL from the first message; and
transmitting the second message to a message controller for transmission to a user equipment (UE).
7 . The content analysis system of claim 6 , wherein modifying the entry in the content data store comprises generating the entry in the content data store based at least in part on determining that the cryptographic hash digest is not represented in the content data store.
8 . The content analysis system of claim 6 , wherein modifying the entry in the content data store comprises incrementing a message detection counter associated with the entry in the content data store based at least in part on determining that the cryptographic hash digest is represented in the entry in the content data store.
9 . The content analysis system of claim 6 , wherein determining the maliciousness of the URL comprises querying a remote malicious URL database for maliciousness data associated with the URL.
10 . The content analysis system of claim 9 , wherein determining the maliciousness of the URL further comprises setting a malicious URL flag associated with the entry in the content data store based at least in part on the maliciousness data associated with the URL.
11 . The content analysis system of claim 6 , wherein:
the first message further comprises at least one of image content or video content, and
the textual content comprises metadata associated with at least one of the image content or the video content.
12 . The content analysis system of claim 6 , wherein the second message is further generated by replacing the URL with URL redaction information.
13 . A non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:
receiving a first message comprising textual content;
determining a uniform resource locator (URL) within the textual content;
generating a cryptographic hash digest based at least in part on the textual content;
modifying an entry in a content data store based at least in part on the cryptographic hash digest, wherein modifying the entry in the content data store comprises incrementing a message detection counter associated with the entry in the content data store based at least in part on determining that the cryptographic hash digest is represented in the entry in the content data store, the message detection counter indicating a number of received messages that are detected as having a matching digest to the cryptographic hash digest;
determining a maliciousness of the URL when the message detection counter meets or exceeds a message detection counter threshold value;
generating, based at least in part on the maliciousness of the URL, a second message by redacting the URL from the first message; and
transmitting the second message to a message controller for transmission to a user equipment (UE).
14 . The non-transitory computer-readable media of claim 13 , wherein the operations further comprise:
receiving a third message comprising second textual content;
determining that the second textual content excludes any URL; and
transmitting, the third message to the message controller for transmission to a second UE based at least in part on determining that the second textual content excludes any URL.
15 . The non-transitory computer-readable media of claim 13 , wherein the second message is further generated by replacing the URL with URL redaction information.
16 . The non-transitory computer-readable media of claim 13 , wherein the operations further comprise:
receiving a request for the first message from the UE; and
in response to the request, transmitting the first message comprising the textual content to the UE.
17 . The non-transitory computer-readable media of claim 13 , wherein:
the first message further comprises at least one of image content or video content, and
the textual content comprises metadata associated with at least one of the image content or the video content.