IP Library Granted Patent US 7,953,814
Granted Patent B1
US 7,953,814 · App. 11/365,130 · Granted May 31, 2011

Stopping and remediating outbound messaging abuse

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,953,814
App. No.
11/365,130
Granted
May 31, 2011
Kind
B1
Abstract

Systems and methods are provided for allowing subscriber message sending profiles to be maintained and used in conjunction with behavior-based anomaly detection techniques and traditional content-based spam signature filtering to enable application of appropriate message disposition policies to outbound subscriber message traffic. According to one embodiment, subscriber profiles are constructed for multiple subscriber accounts associated with a service provider based on outbound message flow originated from the subscriber accounts. Then, possible subscriber account misuse may be discovered by performing behavior-based anomaly detection, including a comparison of a subscriber profile associated with the subscriber account with recent subscriber account usage information, to identify one or more behavioral anomalies in outbound message flow originated from a subscriber account, the behavior-based anomaly detection.

Claims (40)

1. A method comprising:

extracting behavior data of at least one subscriber account from outbound messages originated by said at least one subscriber account using a Sender Reputation Gateway (SRG) running on a computer system, said behavior data of said at least one subscriber account being attributes of said at least one subscriber account that are indicative of spam, virus, or worm related activity of said at least one subscriber account;

building a profile for said at least one subscriber account based on said behavior data extracted from said outbound messages originated by said at least one subscriber on said SRG running on said computer system;

tracking said behavior data extracted from said outbound messages originated by said at least one subscriber account using said SRG running on said computer system;

detecting behavior-based anomalies for said outbound messages originated by said at least one subscriber account using said SRG running on said computer system by comparing recent outbound messages originated by said at least one subscriber account with said profile of said at least one subscriber account to detect changes in said recent outbound messages originated by said at least one subscriber account in comparison to said profile of said at least one subscriber account;

determining reputation data for said at least one subscriber account based on said detected behavior-based anomalies using said SRG computer system, wherein the reputation data is added to the profile to determine a reputation score, and wherein if the reputation score falls below a threshold, then any subsequent outbound messages from the subscriber account are redirected to a server and prohibited from reaching their intended destination, and wherein the redirection to the server activity is designated for a specific time interval.

2. The method of claim 1 wherein said behavior data comprises at least one of a group consisting of: metrics relating to a size of said messages originated by said at least one subscriber account, metrics relating to a number of recipients specified by said messages originated by said at least one subscriber account, metrics relating to presence of attachments to said messages originated by said at least one subscriber account, metrics relating to timing of said messages originated by said at least one subscriber account, a total number of said messages originated by said at least one subscriber account, a total number of said messages originated by said at least one subscriber account suspected of being spam, a total number of said messages originated by said at least one subscriber account suspected of containing a virus, an average number of said messages originated by said at least one subscriber account, an average size of said messages originated by said at least one subscriber account, a largest size of said messages originated by said at least one subscriber account, a maximum size permitted for said messages originated by said at least one subscriber account, an average number of recipients for said messages originated by said at least one subscriber account, a largest number of recipients for said messages originated by said at least one subscriber account, a maximum number of recipients permitted for said messages originated by said at least one subscriber account, a frequency of repetition of recipients for said messages originated by said at least one subscriber account, an address format employed for said messages originated by said at least one subscriber account, an average number of message header lines for said messages originated by said at least one subscriber account, an average Bayesian spam filter score for said messages originated by said at least one subscriber account, a number of messages originated with attachments for said messages originated by said at least one subscriber account, a number of messages originated with particular attachment types for said messages originated by said at least one subscriber account, a number of messages originated by a particular mailer for said messages originated by said at least one subscriber account, a number of messages containing a particular character set for said messages originated by said at least one subscriber account, and standard deviations of various measurements of said messages originated by said at least one subscriber account behavior.

3. The method of claim 1 further comprising alerting a network operations analyst of said service provider of potential subscriber account misuse based on said detected behavior-based anomalies from said SRG running on said computer system.

4. The method of claim 1 comprising applying a predetermined set of message disposition policies to said messages originated by said at least one subscriber account based upon said determined reputation data for said at least one subscriber account using said SRG running on said computer system.

5. The method of claim 1 further comprising:

combining said reputation data determined based on said detected behavior-based anomalies for said at least one subscriber account with traditional content-based spam filtering reputation data for said at least one subscriber account to construct combined reputation data for said at least one subscriber account using said SRG running on said computer system;

taking an immediate action with regard to a particular message originated by said at least one subscriber account using said SRG running on said computer system in response to said combined reputation data; and

taking a long term action with regard to said at least one subscriber account using said SRG running on said computer system in response to said combined reputation data.

6. The method of claim 1 wherein said outbound communication medium is the Internet.

7. The method of claim 1 wherein said building of said profile for said at least one subscriber account is performed until there is sufficient behavior data to identify anomalies prior to said detecting of said behavior-based anomalies.

8. A sender reputation gateway system, comprising:

a service and response system that services and responds to requests from at least one subscriber account;

a behavior data extraction system that extracts behavior data of said at least one subscriber account from outbound messages originated by said at least one subscriber account, said behavior data of said at least one subscriber account being attributes of said at least one subscriber account that are indicative of spam, virus, or worm related activity;

a profile builder system that builds a profile for said at least one subscriber account based on said behavior data extracted from said outbound messages originated by said at least one subscriber;

a tracking system that tracks said behavior data extracted from said outbound messages originated by said at least one subscriber account;

an anomaly detection system that detects behavior-based anomalies for said outbound messages originated by said at least one subscriber account by comparing recent outbound messages originated by said at least one subscriber account with said profile of said at least one subscriber account to detect changes in said recent outbound messages originated by said at least one subscriber account in comparison to said profile of said at least one subscriber account; and

a reputation data determination system that determines reputation data for said at least one subscriber account based on said detected behavior-based anomalies, wherein the reputation data is added to the profile to determine a reputation score, and wherein if the reputation score falls below a threshold, then any subsequent outbound messages from the subscriber account are redirected to a server and prohibited from reaching their intended destination, and wherein the redirection to the server activity is designated for a specific time interval.

9. The sender reputation gateway system of claim 8 wherein said behavior data comprises at least one of a group consisting of: metrics relating to a size of said messages originated by said at least one subscriber account, metrics relating to a number of recipients specified by said messages originated by said at least one subscriber account, metrics relating to presence of attachments to said messages originated by said at least one subscriber account, metrics relating to timing of said messages originated by said at least one subscriber account, a total number of said messages originated by said at least one subscriber account, a total number of said messages originated by said at least one subscriber account suspected of being spam, a total number of said messages originated by said at least one subscriber account suspected of containing a virus, an average number of said messages originated by said at least one subscriber account, an average size of said messages originated by said at least one subscriber account, a largest size of said messages originated by said at least one subscriber account, a maximum size permitted for said messages originated by said at least one subscriber account, an average number of recipients for said messages originated by said at least one subscriber account, a largest number of recipients for said messages originated by said at least one subscriber account, a maximum number of recipients permitted for said messages originated by said at least one subscriber account, a frequency of repetition of recipients for said messages originated by said at least one subscriber account, an address format employed for said messages originated by said at least one subscriber account, an average number of message header lines for said messages originated by said at least one subscriber account, an average Bayesian spam filter score for said messages originated by said at least one subscriber account, a number of messages originated with attachments for said messages originated by said at least one subscriber account, a number of messages originated with particular attachment types for said messages originated by said at least one subscriber account, a number of messages originated by a particular mailer for said messages originated by said at least one subscriber account, a number of messages containing a particular character set for said messages originated by said at least one subscriber account, and standard deviations of various measurements of said messages originated by said at least one subscriber account behavior.

10. The sender reputation gateway system of claim 8 further comprising an alert system that alerts a network operations analyst of said service provider of potential subscriber account misuse based on said detected behavior-based anomalies.

11. The sender reputation gateway system of claim 8 further comprising a disposition policy system that applies a predetermined set of message disposition policies to said messages originated by said at least one subscriber account based upon said determined reputation data for said at least one subscriber account.

12. The sender reputation gateway system of claim 8 wherein said reputation data determination system further combines said reputation data determined based on said detected behavior-based anomalies for said at least one subscriber account with traditional content-based spam filtering reputation data for said at least one subscriber account to construct combined reputation data for said at least one subscriber account; takes an immediate action with regard to a particular message originated by said at least one subscriber account in response to said combined reputation data; and takes a long term action with regard to said at least one subscriber account in response to said combined reputation data.

13. The sender reputation gateway system of claim 8 wherein said outbound communication medium is the Internet.

14. The sender reputation gateway system of claim 8 wherein said profile builder system operates until there is sufficient behavior data to identify anomalies prior to operating said anomaly detection system.

15. A machine-readable medium that stores instructions for a computer system to perform sender reputation gateway processes, comprising:

extracting behavior data of at least one subscriber account from outbound messages originated by said at least one subscriber account, said behavior data of said at least one subscriber account being attributes of said at least one subscriber account that are indicative of spam, virus, or worm related activity of said at least one subscriber account that results in outbound message abuse of the service provider;

building a profile for said at least one subscriber account based on said behavior data extracted from said outbound messages originated by said at least one subscriber;

tracking said behavior data extracted from said outbound messages originated by said at least one subscriber account;

detecting behavior-based anomalies for said outbound messages originated by said at least one subscriber account by comparing recent outbound messages originated by said at least one subscriber account with said profile of said at least one subscriber account to detect changes in said recent outbound messages originated by said at least one subscriber account in comparison to said profile of said at least one subscriber account;

determining reputation data for said at least one subscriber account based on said detected behavior-based anomalies, wherein the reputation data is added to the profile to determine a reputation score, and wherein if the reputation score falls below a threshold, then any subsequent outbound messages from the subscriber account are redirected to a server and prohibited from reaching their intended destination, and wherein the redirection to the server activity is designated for a specific time interval.

16. The machine-readable medium of claim 15 wherein said behavior data comprises at least one of a group consisting of: metrics relating to a size of said messages originated by said at least one subscriber account, metrics relating to a number of recipients specified by said messages originated by said at least one subscriber account, metrics relating to presence of attachments to said messages originated by said at least one subscriber account, metrics relating to timing of said messages originated by said at least one subscriber account, a total number of said messages originated by said at least one subscriber account, a total number of said messages originated by said at least one subscriber account suspected of being spam, a total number of said messages originated by said at least one subscriber account suspected of containing a virus, an average number of said messages originated by said at least one subscriber account, an average size of said messages originated by said at least one subscriber account, a largest size of said messages originated by said at least one subscriber account, a maximum size permitted for said messages originated by said at least one subscriber account, an average number of recipients for said messages originated by said at least one subscriber account, a largest number of recipients for said messages originated by said at least one subscriber account, a maximum number of recipients permitted for said messages originated by said at least one subscriber account, a frequency of repetition of recipients for said messages originated by said at least one subscriber account, an address format employed for said messages originated by said at least one subscriber account, an average number of message header lines for said messages originated by said at least one subscriber account, an average Bayesian spam filter score for said messages originated by said at least one subscriber account, a number of messages originated with attachments for said messages originated by said at least one subscriber account, a number of messages originated with particular attachment types for said messages originated by said at least one subscriber account, a number of messages originated by a particular mailer for said messages originated by said at least one subscriber account, a number of messages containing a particular character set for said messages originated by said at least one subscriber account, and standard deviations of various measurements of said messages originated by said at least one subscriber account behavior.

17. The machine-readable medium of claim 15 further comprising alerting a network operations analyst of said service provider of potential subscriber account misuse based on said detected behavior-based anomalies.

18. The machine-readable medium of claim 15 further comprising applying a predetermined set of message disposition policies to said messages originated by said at least one subscriber account based upon said determined reputation data for said at least one subscriber account.

19. The machine-readable medium of claim 15 further comprising:

combining said reputation data determined based on said detected behavior-based anomalies for said at least one subscriber account with traditional content-based spam filtering reputation data for said at least one subscriber account to construct combined reputation data for said at least one subscriber account;

taking an immediate action with regard to a particular message originated by said at least one subscriber account in response to said combined reputation data; and taking a long term action with regard to said at least one subscriber account in response to said combined reputation data.

Assignments (25)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
RELEASE OF SECURITY INTEREST Recorded Jun 1, 2022
From: ORIX GROWTH CAPITAL, LLC F/K/A ORIX VENTURE FINANCE, LLC
To: MCAFEE, LLC, SUCCESSOR IN INTEREST TO MX LOGIC, INC.
Reel/Frame 060068/0829 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2010
From: CHASIN, C. SCOTT; LIN, WEI; KINCAID-SMITH, PAUL
To: MX LOGIC, INC.
Reel/Frame 024293/0903 →
MERGER Recorded Apr 18, 2010
From: MX LOGIC, INC.
To: MCAFEE, INC.
Reel/Frame 024244/0644 →
SECURITY AGREEMENT Recorded May 30, 2007
From: MX LOGIC, INC.
To: ORIX VENTURE FINANCE LLC
Reel/Frame 019353/0576 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2006
From: CHASIN, C. SCOTT; LIN, WEI; KINCAID-SMITH, PAUL
To: MX LOGIC, INC.
Reel/Frame 017680/0038 →