IP Library Granted Patent US 7,941,490
Granted Patent B1
US 7,941,490 · App. 11/127,814 · Granted May 10, 2011

Method and apparatus for detecting spam in email messages and email attachments

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,941,490
App. No.
11/127,814
Granted
May 10, 2011
Kind
B1
Abstract

A method and system for a character-based document comparison are described. In one embodiment, the method includes receiving an email message and determining a level of noise present in the message. The level of noise present in the email message is then utilized to determine whether the message is indicative of spam.

Claims (67)

1. A method comprising:

a computer system receiving an email message;

the computer system performing a plurality of demangling operations on the received email message, wherein each demangling operation identifies a different type of obfuscation technique, and wherein said performing includes modifying content of the received email message;

the computer system counting a number of the performed plurality of demangling operations that indicate a presence of noise in the received email message; and

the computer system utilizing the counted number of demangling operations to determine whether the email message is indicative of spam.

2. The method of claim 1 wherein performing a first of the plurality of demangling operations on the received email message includes:

identifying, in the received email message, a first set of data indicative of a first type of obfuscation technique; and

responsive to the identifying, modifying the email message.

3. The method of claim 1 wherein performing one of the plurality of demangling operations includes: identifying, in the email message, one or more numeric character references or character entity references indicative of a first type of obfuscation technique; and

responsive to the identifying, modifying at least one of the identified references.

4. The method of claim 3 wherein performing one of the plurality of demangling operations includes:

identifying, in the email message, URL password syntax data indicative of a second type of obfuscation technique; and

responsive to the identifying, modifying the identified URL password syntax data.

5. The method of claim 1 wherein performing one of the plurality of demangling operations includes:

identifying HTML formatting data in the email message; and

responsive to the identifying, removing the identified HTML formatting data from the email message.

6. The method of claim 1 further comprising the computer system blocking the email message if the email message is determined to be spam.

7. The method of claim 1 wherein performing one of the plurality of demangling operations includes:

identifying noise in a header of an attachment of the email message; and

responsive to the identifying, removing the identified noise from the header.

8. The method of claim 7 wherein the identifying includes utilizing a mathematical signature associated with a type of the attachment.

9. The method of claim 7 wherein the identified noise is identified in a file extension associated with the attachment.

10. A computer system comprising:

a processor;

a memory storing program instructions executable by the processor to:

receive an email message;

perform a plurality of demangling operations on the received email message, including modifying content of the received email message, wherein each demangling operation identifies a different type of obfuscation technique;

count a number of the performed plurality of demangling operations that indicate a presence of noise in the received email message; and

utilize the counted number of demangling operations to determine whether the email message is indicative of spam.

11. A non-transitory computer readable storage medium storing program instructions that are executable to:

receive an email message;

perform a plurality of demangling operations on the received email message,

wherein each demangling operation identifies a different type of obfuscation technique, and wherein one or more of the demangling operations modifies the received email message;

count a number of the performed plurality of demangling operations that indicate a presence of noise in the received email message; and

utilize the counted number of demangling operations to determine whether the email message is indicative of spam.

12. The non-transitory computer readable storage medium of claim 11 wherein the program instructions executable to perform one of the plurality of demangling operations are executable to:

identify one or more numeric character references or character entity references in the email message; and

responsive to identifying the one or more numeric character references or character entity references, modify at least one of the identified references.

13. The non-transitory computer readable storage medium of claim 11 wherein the program instructions executable to perform one of the plurality of demangling operations are executable to:

identify URL password syntax data in the email message; and

responsive to identifying the URL password syntax data, modify the identified URL password syntax data.

14. The non-transitory computer readable storage medium of claim 11 wherein the program instructions executable to perform one of the plurality of demangling operations are executable to:

identify HTML formatting data in the email message; and

responsive to identifying the HTML formatting data, remove the identified HTML formatting data from the email message.

15. The non-transitory computer readable storage medium of claim 11 wherein the program instructions executable to perform one of the plurality of demangling operations are executable to:

identify noise in a header of an attachment of the email message; and

responsive to identifying the noise in the header, remove the identified noise from the header.

16. The non-transitory computer readable storage medium of claim 15 wherein the identified noise is identified in a file extension associated with the attachment.

17. The computer system of claim 10 wherein the program instructions executable to perform one of the plurality of demangling operations are executable to:

identify one or more numeric character references or character entity references in the email message; and

responsive to identifying the one or more numeric character references or character entity references, modify at least one of the identified references.

18. The computer system of claim 10 wherein the program instructions executable to perform one of the plurality of demangling operations are executable to:

identify URL password syntax data in the email message; and

responsive to identifying the URL password syntax data, modify the identified URL password syntax data.

19. The computer system of claim 10 wherein the program instructions executable to perform one of the plurality of demangling operations are executable to:

identify noise in a header of an attachment of the email message; and

responsive to identifying the noise in the header, remove the identified noise from the header.

20. A non-transitory computer readable storage medium storing program instructions that are executable to:

count a number of different obfuscation techniques present in a received email message;

assign a first spam weight value in response to the counted number being within a first range; and

determine whether the received email message is a spam email message, including by utilizing the first spam weight value.

21. The non-transitory computer readable storage medium of claim 20 , wherein the program instructions are further executable to:

modify the received email message to remove noise associated with one or more of the number of different obfuscation techniques counted as being present in the received email message; and

compute a second spam weight value indicative of whether the modified email message resembles a known spam message;

wherein the program instructions executable to determine whether the received email message is a spam email message utilize the first and second spam weight values.

22. The non-transitory computer readable storage medium of claim 21 , wherein the program instructions executable to count a number of different obfuscation techniques are executable to determine whether a numeric character reference or character entity reference is present in the email message.

23. The non-transitory computer readable storage medium of claim 21 , wherein the program instructions are further executable to assign a second spam weight value in response to the counted number being within a second range, and wherein determining whether the received email message is a spam email message includes utilizing the second spam weight value.

Assignments (4)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2005
From: COWINGS, DAVID O.
To: SYMANTEC CORPORATION
Reel/Frame 016564/0437 →