IP Library Granted Patent US 7,096,498
Granted Patent B2
US 7,096,498 · App. 10/361,091 · Granted Aug 22, 2006

Systems and methods for message threat management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,096,498
App. No.
10/361,091
Granted
Aug 22, 2006
Kind
B2
Abstract

The present invention is directed to systems and methods for detecting unsolicited and threatening communications and communicating threat information related thereto. Threat information is received from one or more sources; such sources can include external security databases and threat information data from one or more application and/or network layer security systems. The received threat information is reduced into a canonical form. Features are extracted from the reduced threat information; these features in conjunction with configuration data such as goals are used to produce rules. In some embodiments, these rules are tested against one or more sets of test data and compared against the same or different goals; if one or more tests fail, the rules are refined until the tests succeed within an acceptable margin of error. The rules are then propagated to one or more application layer security systems.

Claims (41)

1. A method for managing threat information, the method comprising the steps of:

a. receiving threat information from one or more sources selected from the group consisting of application layer security systems, spain databases, a virus information databases, and intrusion information databases;

b. reducing the received threat information into a canonical form;

c. extracting features from the reduced threat information by applying one or more regular expressions;

d. selecting a goal set of one or more threat management goals based at least in part upon a selected application layer security system from the plurality of application layer security systems, wherein the goal set comprises one or more values of a type selected from the group of effectiveness values, accuracy values, efficiency values and false positive values;

e. generating a candidate rule set of one or more threat rules based upon the extracted features and the goal set;

f. testing the candidate rule set against one or more sets of test data;

g. refining the candidate rule set if the evaluation of the rule set fails to satisfy a predetermined confidence level; and

h. transmitting the candidate or refined rule set to at least one application layer security system.

2. A management system for generating and distributing threat detection rules to application layer security systems, the system comprising:

a. communication means for receiving threat information from one or more sources selected from the group consisting of application layer security systems, spain databases, a virus information databases, and intrusion information databases and for transmitting a generated rule set to at least one application layer security system;

b. rule generation means for:

i. reducing threat information received by the communication means into a canonical form;

ii. extracting features from the reduced threat information by applying one or more regular expressions;

iii. selecting a goal set of one or more threat management goals based at least in part upon a selected application layer security system from the plurality of application layer security systems, wherein the goal set comprises one or more values of a type selected from the group of effectiveness values, accuracy values, efficiency values and false positive values; iv. generating a candidate rule set of one or more threat rules based upon the extracted features and the goal set; v. testing the candidate rule set against one or more sets of test data;

vi. refining the candidate rule set if the evaluation of the rule set fails to satisfy a predetermined confidence level; and

vii. providing the candidate or refined rule set to the communication means.

3. An application layer security system, the system comprising:

a. at least one application server system communication interface communicatively coupling the security system to a communication network allowing communication with one or more other application-layer security systems and a threat management system;

b. a system data store capable of storing an electronic conimunication and accumulated data associated with received electronic communications; and

c. a system processor in communication with the system data store and the at least one application server system communication interface, wherein the system processor comprises one or more processing elements and wherein the system processor:

i. receives an electronic communication directed to or from a selected application server system;

ii. applies one or more tests to the received electronic communication, wherein each of the one or more tests evaluates the received electronic communication for a particular security risk;

iii. stores in the system data store a risk profile associated with the received electronic communication based upon the applied one or more tests, the risk profile identifying one or more security risks in the received electronic communication that were identified by the one or more tests; and

iv. outputs information based upon the stored risk profile to a second application layer security system, a threat management center, a threat pushback system or a combination thereof, wherein the outputted information is used by another system processor to detect electronic communications that include the one or more security risks identified in the risk profile.

4. The system of claim 3 , wherein the received electronic communication comprises an e-mail communication, an HTTP communication, an FTP communication, a WAIS communication, a telnet communication or a Gopher communication.

5. The system of claim 4 , wherein the received electronic communication is an e-mail communication.

6. The system of claim 3 , wherein each of the one or more tests applied by the system processor comprises intrusion detection, virus detection, spain detection or policy violation detection.

7. The system of claim 3 , wherein the system processor applies a plurality of tests.

8. The system of claim 7 , wherein the system processor applies each of the plurality of tests in a parallel fashion.

9. The system of claim 7 , wherein the system processor applies each of the plurality of tests in a sequential fashion.

10. The system of claim 3 , wherein the system processor applies each of the one or more tests based upon configuration information stored in the system data store.

11. The system of claim 3 , wherein the system processor outputs the information in the form of an e-mail message, a page, a facsimile, an telephone call, an SMS message, a WAP alert or an SNMP alert.

12. The system of claim 3 , wherein the system processor outputs the information to a threat management center and to a second application layer security system, a threat pushback system or a combination thereof.

13. The system of claim 3 , wherein the one or more tests applied by the system processor comprise anomaly detection.

14. The system of claim 3 , wherein an application layer security system can broadcast a message to at least one other application layer security system.

15. The system of claim 3 , and further comprising a central threat management system, wherein the centralized threat management system coordinates threat information among multiple nodes.

16. The system of claim 3 , wherein each application layer security system is a trusted application layer security system.

17. The system of claim 3 , wherein the system processor outputs information comprising threat statistics.

18. The system of claim 17 , wherein the threat statistics include information about the frequency of certain threat types.

19. The system of claim 3 , wherein the system processor outputs information comprising information corresponding to a specific identified threat, one or more whitelists, traffic pattern data, or combinations thereof.

Assignments (14)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 021523 FRAME: 0713. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF PATENT SECURITY AGREEMENT. Recorded Apr 11, 2022
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 059690/0187 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 023915/0990 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2007
From: CIPHERTRUST, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 018771/0221 →
SECURITY AGREEMENT Recorded Sep 14, 2006
From: SECURE COMPUTING CORPORATION; CIPHERTRUST, INC.
To: CITICORP USA, INC. AS ADMINISTRATIVE AGENT
Reel/Frame 018247/0359 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2003
From: JUDGE, PAUL
To: CIPHERTRUST, INC.
Reel/Frame 013784/0152 →