IP Library Granted Patent US 8,042,181
Granted Patent B2
US 8,042,181 · App. 11/456,954 · Granted Oct 18, 2011

Systems and methods for message threat management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,042,181
App. No.
11/456,954
Granted
Oct 18, 2011
Kind
B2
Abstract

The present invention is directed to systems and methods for detecting unsolicited and threatening communications and communicating threat information related thereto. Threat information is received from one or more sources; such sources can include external security databases and threat information data from one or more application and/or network layer security systems. The received threat information is reduced into a canonical form. Features are extracted from the reduced threat information; these features in conjunction with configuration data such as goals are used to produce rules. In some embodiments, these rules are tested against one or more sets of test data and compared against the same or different goals; if one or more tests fail, the rules are refined until the tests succeed within an acceptable margin of error. The rules are then propagated to one or more application layer security systems.

Claims (45)

1. A method to classify communications from messaging entities, the method comprising:

initiating a plurality of interrogation engines, each interrogation engine implementing a message classification technique;

initiating a corresponding plurality of index queues, each index queue associated with one interrogation engine;

storing, in each index queue, indexes that index communications in a order in which its corresponding interrogation engine is to process the communications;

receiving a communication from a messaging entity, wherein the communication is a legitimate e-mail message or spam or a virus or a communication that violates corporate policy;

assigning an index to the communication;

performing a load evaluation in response to receiving the communication;

determining an additional interrogation engine should be initiated based on the load evaluation, and in response to the determination, creating a new index queue and initiating a new interrogation engine, wherein the new index queue is associated with the new interrogation engine;

placing the index assigned to the communication into one or more index queues of the plurality of index queues and the new index queue;

for each of the one or more index queues into which the index is assigned, using the corresponding interrogation engine and message classification technique to classify the communication;

combining, using one or more data processors, results of the message classification techniques to generate a message profile score for the communication; and

wherein the message profile score is used in deciding what action is to be taken with respect to the communication associated with the messaging entity, and the communication is interrogated by a plurality of interrogation engines of different types.

2. The method of claim 1 , wherein the communication is an e-mail message or VoIP communication or Instant Messaging communication or SMS message or MMS message.

3. The method of claim 1 , wherein the message classification techniques include at least two techniques selected from the group: Real-time Black-hole Lists (RBLs) classification technique, reputation server classification technique, signature-based classification technique, fingerprinting-based classification technique, message header analysis classification technique, sender authentication set of classification techniques, statistical classification techniques, and content filtering classification technique.

4. The method of claim 1 , wherein each message classification technique is associated with a confidence value of a classification of the communication by the message classification technique, which is used in generating a message classification result from the message classification technique.

5. The method of claim 4 , wherein a classification value from each of the message classification techniques is multiplied by its associated confidence value in order to generate the message classification result.

6. The method of claim 5 , further comprising: iterating through the message classification techniques and allowing each technique to attempt to classify the message; wherein the result of each classification is a numeric value, textual value, or categorical value.

7. The method of claim 1 , wherein combining results of the message classification techniques to generate a message profile score comprises summing together probabilities of each classification technique that the message is unwanted.

8. The method of claim 7 , wherein combining results of the message classification techniques to generate a message profile score comprises summing together probabilities of each classification technique that the message is legitimate.

9. The method of claim 1 , wherein at least one of the message classification techniques includes a reputation scoring technique; and

wherein the reputation scoring technique assigns a reputation probability to a messaging entity;

wherein the reputation probability indicates reputability of a messaging entity based upon an extent to which the communication's characteristics exhibit or conform to one or more reputation-related criteria.

10. The method of claim 1 , wherein the communication was sent over a network.

11. The method of claim 1 , wherein the message profile score is an aggregation of the results of each of the message classification techniques.

12. One or more computer readable media storing instructions that are executable by one or more data processors, and upon such execution cause the one or more data processors to perform operations comprising:

initiating a plurality of interrogation engines, each interrogation engine implementing a message classification technique;

initiating a corresponding plurality of index queues, each index queue associated with one interrogation engine;

storing, in each index queue, indexes that index communications in a order in which its corresponding interrogation engine is to process the communications;

receiving a communication that was sent over a network from a messaging entity, wherein the communication is a legitimate e-mail message or spam or a virus or a communication that violates corporate policy;

assigning an index to the communication;

performing a load evaluation in response to receiving the communication;

determining an additional interrogation engine should be initiated based on the load evaluation, and in response to the determination, creating a new index queue and initiating a new interrogation engine, wherein the new index queue is associated with the new interrogation engine;

placing the index assigned to the communication into one or more index queues of the plurality of index queues and the new index queue; for each of the one or more index queues into which the index is assigned, using the corresponding interrogation engine and message classification technique to classify the communication;

wherein each message classification technique is associated with a confidence value which is used in generating a message classification output from the message classification technique;

combining results of the message classification techniques to generate a message profile score for the communication; and

wherein the message profile score is used in deciding what action is to be taken with respect to the communication associated with the messaging entity, and the communication is interrogated by a plurality of interrogation engines of different types.

13. The computer readable media of claim 12 , wherein the communication is an e-mail message or VoIP communication or Instant Messaging communication.

14. The computer readable media of claim 12 , wherein the profile score is used in determining the communication is a legitimate message or unwanted communication or a communication violative of a pre-selected policy.

15. The computer readable media of claim 14 , wherein an unwanted communication includes a spam or virus communication;

wherein the pre-selected policy includes a corporate communication policy, a messaging policy, a legislation or regulatory policy, or an international communication policy.

16. The computer readable media of claim 12 , wherein the message classification techniques include at least two techniques selected from the group: real-time black-hole lists (RBLs) classification technique, reputation server classification technique, signature-based classification technique, fingerprinting-based classification technique, message header analysis classification technique, sender authentication set of classification techniques, statistical classification techniques, and content filtering classification technique.

17. The computer readable media of claim 12 , wherein the message classification output of is a numeric value, textual value, or categorical value.

18. The computer readable media of claim 12 , wherein at least one of the message classification techniques includes a reputation scoring technique; and

wherein the reputation scoring technique assigns a reputation probability to a messaging entity;

wherein the reputation probability indicates reputability of a messaging entity based upon an extent to which the communication's characteristics exhibit or conform to one or more reputation-related criteria.

Assignments (14)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 021523 FRAME: 0713. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF PATENT SECURITY AGREEMENT. Recorded Apr 11, 2022
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 059690/0187 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 023915/0990 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2007
From: CIPHERTRUST, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 018771/0221 →
SECURITY AGREEMENT Recorded Sep 14, 2006
From: SECURE COMPUTING CORPORATION; CIPHERTRUST, INC.
To: CITICORP USA, INC. AS ADMINISTRATIVE AGENT
Reel/Frame 018247/0359 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2006
From: JUDGE, PAUL
To: CIPHERTRUST, INC.
Reel/Frame 018089/0242 →