IP Library Granted Patent US 7,225,466
Granted Patent B2
US 7,225,466 · App. 11/388,575 · Granted May 29, 2007

Systems and methods for message threat management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,225,466
App. No.
11/388,575
Granted
May 29, 2007
Kind
B2
Abstract

The present invention is directed to systems and methods for detecting unsolicited and threatening communications and communicating threat information related thereto. Threat information is received from one or more sources; such sources can include external security databases and threat information data from one or more application and/or network layer security systems. The received threat information is reduced into a canonical form. Features are extracted from the reduced threat information; these features in conjunction with configuration data such as goals are used to produce rules. In some embodiments, these rules are tested against one or more sets of test data and compared against the same or different goals; if one or more tests fail, the rules are refined until the tests succeed within an acceptable margin of error. The rules are then propagated to one or more application layer security systems.

Claims (38)

1. A management system for generating and distributing threat detection rules to application layer security systems, the system comprising:

a. a communication interface adapted to allow communication between the management system and at least one application layer security system;

b. a system data store comprising one or more data storage elements, wherein the system data store is capable of storing:

i. one or more sets of threat management goals; and

ii. threat information; and

c. a system processor in communication with the communication interface and the system data store, wherein the system processor comprises one or more processing elements and the one or more processing elements are programmed or adapted to:

i. receive threat information from one or more sources;

ii. reduce the received threat information into a canonical form;

iii. extract features from the reduced threat information;

iv. generate a rule set of one or more threat rules based upon the extracted features and a goal set of one or more threat management goals in the system data store; and

v. transmit the generated rule set to at least one of the plurality of application layer security systems.

2. The system of claim 1 , wherein the system data store is further capable of storing one or more sets of test data, wherein the system processor is further programmed or adapted to evaluate the generated rule set against one or more sets of test data in the system data store and to refine the rule set if the evaluation of the rule set fails to satisfy a predetermined confidence level.

3. The system of claim 2 , wherein the system processor evaluates the generated rule set against one or more sets of test data based upon the goal set used to generate the rule set.

4. The system of claim 3 , wherein the second goal set comprises one or more values of a type selected from the group of effectiveness values, accuracy values, efficiency values and false positive values.

5. The system of claim 2 , wherein the system processor evaluates the generated rule set against one or more sets of test data based upon a second goal set of one or more goals from the system data store that differs from the goal set used to generate the rule set.

6. The system of claim 5 , wherein the second goal set comprises one or more values of a type selected from the group of effectiveness values, accuracy values, efficiency values and false positive values.

7. The system of claim 1 , wherein the goal set comprises one or more attributes selected from the group consisting of effectiveness values, accuracy values, efficiency values and false positive values.

8. The system of claim 1 , wherein the goal set comprises one or more undesirable message types, wherein each undesirable message type is selected from the group consisting of business email, personal email, chain letters, adult language, porn, web product offerings, newsletters, mailing lists, Trojans, worms and viruses.

9. The system of claim 8 , wherein associated with each undesirable message type is a value corresponding to a level of undesirability for the message type.

10. The system of claim 1 , wherein the system processor is further programmed or adapted to select the goal set from the system data store.

11. The system of claim 10 , wherein the system processor's programming or adaptation to select the goal set includes programming or adaptation to select the goal set based at least in part upon a selected application layer security system from the plurality of application layer security systems.

12. The system of claim 11 , wherein the system processor transmits the generated rule set to at least the selected application layer security system.

13. The system of claim 1 , wherein the system processor receives threat information from a selected application layer security system via the communication interface.

14. The system of claim 1 , wherein the system processor receives threat information from a spam database, a virus information database, an intrusion information database or combinations thereof.

15. The system of claim 14 , wherein the system processor receives further threat information from a selected application layer security system via the communication interface.

16. The system of claim 1 , wherein the system processor extracts features that each correspond to an interrogation type available on at least one of the plurality of application layer security systems.

17. The system of claim 1 , wherein the system processor extracts features by applying one or more regular expression filters.

18. The system of claim 1 , wherein the system processor is further programmed or adapted to receive at least one rules and policy application programming interface.

19. The system of claim 18 , wherein the system processor generates the rule set based upon the at least one rules and policy application programming interface.

20. A method for generating and distributing threat detection rules to application layer security systems, the method comprising:

receiving threat information from one or more sources comprising application layer security systems, spam databases, a virus information databases, intrusion information databases, or combinations thereof;

reducing the received threat information into a canonical form;

extracting features from the reduced threat information by applying one or more regular expressions;

selecting a goal set of one or more threat management goals based at least in part upon a selected application layer security system from the plurality of application layer security systems, wherein the goal set comprises one or more values of a type comprising effectiveness values, accuracy values, efficiency values, false positive values, or combinations thereof;

generating a candidate rule set of one or more threat rules based upon the extracted features and the goal set;

testing the candidate rule set against one or more sets of test data;

refining the candidate rule set if the evaluation of the rule set fails to satisfy a predetermined confidence level; and

transmitting the candidate or refined rule set to at least one application layer security system.

Assignments (14)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 021523 FRAME: 0713. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF PATENT SECURITY AGREEMENT. Recorded Apr 11, 2022
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 059690/0187 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 023915/0990 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2007
From: CIPHERTRUST, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 018771/0221 →
SECURITY AGREEMENT Recorded Sep 14, 2006
From: SECURE COMPUTING CORPORATION; CIPHERTRUST, INC.
To: CITICORP USA, INC. AS ADMINISTRATIVE AGENT
Reel/Frame 018247/0359 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2006
From: JUDGE, PAUL
To: CIPHERTRUST, INC.
Reel/Frame 018089/0210 →