IP Library Granted Patent US 7,673,342
Granted Patent B2
US 7,673,342 · App. 09/912,391 · Granted Mar 2, 2010

Detecting e-mail propagated malware

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,673,342
App. No.
09/912,391
Granted
Mar 2, 2010
Kind
B2
Abstract

An e-mail client serves to detect mass mailing malware by detecting if over a threshold number of addressees from within the address book of that e-mail client are being sent an e-mail or over a predetermined number of substantially identical e-mails are being sent by that e-mail client. A quarantine queue may be provided in which e-mail messages are held for a predetermined period prior to being sent out in order that separate e-mail messages being sent to a large proportion of the address book addressees may be identified and linked together.

Claims (58)

1. A computer program product comprising a computer readable storage medium bearing a computer program operable to control an e-mail client computer to detect e-mail propagated malware, said computer program product comprising:

e-mail generating logic operable to generate an e-mail message;

comparison logic operable to compare said e-mail message with at least one of an address book of a sender of said e-mail message and one or more previously generated e-mail messages from said client computer; and

identifying logic operable to identify whether:

(i) said e-mail message is being sent to more than a threshold number of addressees specified within said address book;

(ii) said e-mail message contains message content having at least a threshold level of similarity to non-identical message content of said previously generated e-mail messages being sent to more than a threshold number of addressees specified within said address book; and

(iii) said e-mail message contains message content having at least a threshold level of similarity to non-identical message content of more than a threshold number of said previously generated e-mail messages;

wherein said identifying logic is further operable to identify said email message as potentially containing malware if at least one of items (i), (ii), and (iii) is identified; and

quarantine queue logic operable to hold said previously generated e-mail messages in a quarantine queue for at least a predetermined quarantine period prior to being sent from said client computer;

wherein said quarantine queue logic is further operable such that it is determined whether said email message is a new message by comparing said email message with said previously generated e-mail messages held in said quarantine queue;

wherein said quarantine queue logic is further operable such that said email message is added to said quarantine queue in response to a determination that said email message is said new message;

wherein said quarantine queue logic is further operable such that a score value indicative of one of said previously generated e-mail messages held in said quarantine queue is updated in response to a determination that said email message is not said new message, said score value indicating a proportion of said addressees specified within said address book that have previously been sent said message sharing at least said threshold level of similarity to non-identical message content of said one of said previously generated e-mail messages.

2. A computer program product as claimed in claim 1 , wherein said e-mail message specifies a plurality of addressees, said comparison logic being operable to compare said plurality of addressees with said e-mail address book to determine if said at least a threshold number of addressees has been exceeded.

3. A computer program product as claimed in claim 1 , wherein said at least a threshold number of addressees is specified as a proportion of addressees within said address book.

4. A computer program product as claimed in claim 3 , wherein said proportion of addressees within said address book is user specified.

5. A computer program product as claimed in claim 1 , wherein said quarantine period is user specified.

6. A computer program product as claimed in claim 1 , comprising confirmation input logic operable when said e-mail message is identified as potentially containing malware to generate a user message seeking a confirmation input from a user of said client computer before said e-mail message is sent.

7. A computer program product as claimed in claim 1 , comprising administrator warning logic operable when said e-mail message is identified as potentially containing malware to send an administrator warning message to an administrator of said client computer regarding said e-mail message.

8. A computer program product as claimed in claim 1 , wherein said e-mail message is identified as potentially containing malware only if said e-mail message includes an executable element, to speed processing.

9. A computer program product as claimed in claim 1 , wherein said e-mail message is identified as potentially containing malware when said e-mail message and said previously generated e-mail messages share a common attachment.

10. A computer program product as claimed in claim 1 , wherein a message is sent to a malware computer program provider to provide a warning of new malware outbreaks when said e-mail message is identified as potentially containing malware.

11. A computer program product as claimed in claim 10 , wherein said message to said malware computer program provider includes a copy of said e-mail message.

12. A method of detecting e-mail propagated malware within an e-mail client computer, said method comprising the steps of:

generating an e-mail message;

comparing said e-mail message with at least one of an address book of a sender of said e-mail message and one or more previously generated e-mail messages from said client computer;

identifying whether:

(i) said e-mail message is being sent to more than a threshold number of addressees specified within said address book;

(ii) said e-mail message contains message content having at least a threshold level of similarity to non-identical message content of said previously generated e-mail messages being sent to more than a threshold number of addressees specified within said address book; and

(iii) said e-mail message contains message content having at least a threshold level of similarity to non-identical message content of more than a threshold number of said previously generated e-mail messages;

wherein said email message is identified as potentially containing malware if at least one of items (i), (ii), and (iii) is identified; and

holding said previously generated e-mail messages in a quarantine queue for at least a predetermined quarantine period prior to being sent from said client computer;

wherein it is determined whether said email message is a new message by comparing said email message with said previously generated e-mail messages held in said quarantine queue;

wherein said email message is added to said quarantine queue in response to a determination that said email message is said new message;

wherein a score value indicative of one of said previously generated e-mail messages held in said quarantine queue is updated in response to a determination that said email message is not said new message, said score value indicating a proportion of said addressees specified within said address book that have previously been sent said message sharing at least said threshold level of similarity to non-identical message content of said one of said previously generated e-mail messages.

13. A method as claimed in claim 12 , wherein said e-mail message specifies a plurality of addressees, said plurality of addressees being compared with said e-mail address book to determine if said at least a threshold number of addressees has been exceeded.

14. A method as claimed in claim 12 , wherein said at least a threshold number of addressees is specified as a proportion of addressees within said address book.

15. A method as claimed in claim 14 , wherein said proportion of addressees within said address book is user specified.

16. A method as claimed in claim 12 , wherein said quarantine period is user specified.

17. A method as claimed in claim 12 , wherein when said e-mail message is identified as potentially containing malware, then a user message is generated seeking a confirmation input from a user of said client computer before said e-mail message is sent.

18. A method as claimed in claim 12 , wherein when said e-mail message is identified as potentially containing malware, then an administrator warning message is sent to an administrator of said client computer regarding said e-mail message.

19. Apparatus for detecting e-mail propagated malware within a client computer, said apparatus comprising:

an e-mail generator operable to generate an e-mail message;

a comparator operable to compare said e-mail message with at least one of an address book of a sender of said e-mail message and one or more previously generated e-mail messages from said client computer;

a malware identifier operable to identify whether:

(i) said e-mail message is being sent to more than a threshold number of addressees specified within said address book;

(ii) said e-mail message contains message content having at least a threshold level of similarity to non-identical message content of said previously generated e-mail messages being sent to more than a threshold number of addressees specified within said address book; and

(iii) said e-mail message contains message content having at least a threshold level of similarity to non-identical message content of more than a threshold number of said previously generated e-mail messages;

wherein said malware identifier is further operable to identify said email message as potentially containing malware if at least one of items (i), (ii), and (iii) is identified;

and a quarantine queue operable to hold said previously generated e-mail messages in a quarantine queue for at least a predetermined quarantine period prior to being sent from said client computer;

wherein said quarantine queue is further operable such that it is determined whether said email message is a new message by comparing said email message with said previously generated e-mail messages held in said quarantine queue;

wherein said quarantine queue is further operable such that said email message is added to said quarantine queue in response to a determination that said email message is said new message;

wherein said quarantine queue is further operable such that a score value indicative of one of said previously generated e-mail messages held in said quarantine queue is updated in response to a determination that said email message is not said new message, said score value indicating a proportion of said addressees specified within said address book that have previously been sent said message sharing at least said threshold level of similarity to non-identical message content of said one of said previously generated e-mail messages.

20. Apparatus as claimed in claim 19 , wherein said e-mail message specifies a plurality of addressees, said comparitor being operable to compare said plurality of addressees with said e-mail address book to determine if said at least a threshold number of addressees has been exceeded.

21. Apparatus as claimed in claim 19 , wherein said at least a threshold number of addressees is specified as a proportion of addressees within said address book.

22. Apparatus as claimed in claim 21 , wherein said proportion of addressees within said address book is user specified.

23. Apparatus as claimed in claim 19 , wherein said quarantine period is user specified.

24. Apparatus as claimed in claim 19 , comprising a confirmation input unit operable when said e-mail message is identified as potentially containing malware to generate a user message seeking a confirmation input from a user of said client computer before said e-mail message is sent.

25. Apparatus as claimed in claim 19 , comprising an administrator warning unit operable when said e-mail message is identified as potentially containing malware to send an administrator warning message to an administrator of said client computer regarding said e-mail message.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Aug 1, 2005
From: NETWORKS ASSOCIATES TECHNOLOGY, INC.
To: MCAFEE, INC.
Reel/Frame 016593/0812 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2001
From: HURSEY, NEIL J.; MCEWAN, WILLIAM A.
To: NETWORKS ASSOCIATES TECHNOLOGY, INC.
Reel/Frame 012020/0442 →