IP Library Granted Patent US 8,069,481
Granted Patent B2
US 8,069,481 · App. 11/456,960 · Granted Nov 29, 2011

Systems and methods for message threat management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,069,481
App. No.
11/456,960
Granted
Nov 29, 2011
Kind
B2
Abstract

The present invention is directed to systems and methods for detecting unsolicited and threatening communications and communicating threat information related thereto. Threat information is received from one or more sources; such sources can include external security databases and threat information data from one or more application and/or network layer security systems. The received threat information is reduced into a canonical form. Features are extracted from the reduced threat information; these features in conjuntion with configuration data such as goals are used to produce rules. In some embodiments, these rules are tested against one or more sets of test data and compared against the same or different goals; if one or more tests fail, the rules are refined until the tests succeed within an acceptable margin of error. The rules are then propagated to one or more application layer security systems.

Claims (56)

1. A method for operation upon one or more data processors to assign a reputation to a messaging entity, the method comprising:

receiving a communication from a messaging entity;

deriving a risk profile for the communication comprising:

queuing the communication for interrogation by a plurality of interrogation engines, each interrogation engine of a particular type designed to test the communication for a particular security risk;

performing a load evaluation on an interrogation engine of one of the particular types based upon the plurality of interrogation engines queued to interrogate the communication;

determining that the load evaluation exceeds a threshold, and in response adjusting the plurality of the interrogation engines by generating a new instance of an interrogation engine of the one of the particular types based upon the plurality of interrogation engines queued to interrogate the communication;

aggregating output of the plurality of interrogation engines with data associated with previously received communications to form the risk profile for the communication;

determining, using one or more data processors, a reputation score associated with the communication based upon the risk profile;

wherein the reputation score is indicative of reputation of the messaging entity;

wherein the determined reputation score is used in deciding what action is to be taken with respect to communications associated with the messaging entity.

2. The method of claim 1 , wherein the determined reputation score is distributed to one or more computer systems for use in filtering transmissions.

3. The method of claim 1 , wherein the determined reputation score is locally distributed to a program for use in filtering transmissions.

4. The method of claim 1 , further comprising:

determining reputation indicative probabilities based upon the communication; wherein a reputation indicative probability indicates reputability of a messaging entity based upon an extent to which one or more characteristics of the communication exhibit or conform to one or more reputation-related criteria.

5. The method of claim 4 , wherein a type of messaging entity to which reputations are assigned is a domain name, IP address, phone number, or individual electronic address or username representing an organization, computer, a message, or individual user that transmits electronic messages.

6. The method of claim 1 further comprising: determining reputation indicative probabilities based upon the communication; wherein a reputation indicative probability indicates reputability of a messaging entity based upon extent to which one or more characteristics of the communication exhibit or conform to one or more reputation-related criteria, wherein determining a reputation score includes determining the reputation score based upon aggregation of the reputation indicative probabilities.

7. The method of claim 1 , wherein the communication comprises one of an electronic message communication, a VoIP communication, an HTTP communication, a FTP communication, an SMS communication, or an MMS communication.

8. The method of claim 1 , further comprising adjusting a reputation of the messaging entity based upon the reputation score.

9. The method of claim 1 , further comprising signing the communication and subparts of the communication; determining whether the message has been altered based upon signatures produced by the signing operation.

10. The method of claim 1 , further comprising: comparing a reputation associated with a first messaging entity to a reputation of a second messaging entity, wherein the first and second messaging entities are associated with each other; and, reconciling any differences between the first and second messaging entity.

11. The method of claim 10 , wherein the first messaging entity is a phone number, and the second messaging entity is an internet protocol address associated with the phone number.

12. The method of claim 2 , wherein distributing the reputation score comprises distributing the reputation score to one or more computers that are remote from the one or more data processors.

13. The method of claim 1 , wherein adjusting the plurality of the interrogation engines comprises:

generating a new index queue;

associating the new index queue with the new instance of the interrogation engine; and

assigning an index associated with the communication to the new index queue so that the new instance of the interrogation engine tests the communication for a particular security risk.

14. A computer-implemented method of performing transmission filtering utilizing reputation scores of transmission sender, the method comprising:

storing a transmission from a sender in computer memory;

deriving a risk profile for the transmission comprising:

queuing the transmission for interrogation by a plurality of interrogation engines, each interrogation engine of a particular type designed to test the transmission for a particular security risk;

performing a load evaluation on an interrogation engine of one of the particular types based upon the plurality of interrogation engines queued to interrogate the transmission;

determining that the load evaluation exceeds a threshold, and in response adjusting the plurality of the interrogation engines by generating a new instance of an interrogation engine of the one of the particular types based upon the plurality of interrogation engines queued to interrogate the communication;

aggregating output of the plurality of interrogation engines with data associated with previously received transmission to form the risk profile for the transmission;

determining a reputation score associated for the sender based upon the risk profile;

performing, using one or more data processors, an action on the transmission from the sender corresponding to the score range of the reputation score associated with the sender.

15. The method of claim 14 , wherein the action includes at least one of the following actions:

rejecting all further transmissions from that sender for a period of time or number of transmissions;

silently dropping all further transmissions from that sender for a period of time or number of transmissions;

quarantining all further transmissions from that sender for a period of time or number of transmissions; or

bypassing certain filtering tests for all further transmissions from that sender for a period of time or number of transmissions.

16. The method of claim 14 , wherein adjusting the plurality of the interrogation engines comprises:

generating a new index queue;

associating the new index queue with the new instance of the interrogation engine; and

assigning an index associated with the communication to the new index queue so that the new instance of the interrogation engine tests the transmission for a particular security risk.

17. A system, comprising:

a computer processing device; and

a memory device storing instructions executable by the computer processing device that upon such execution cause the computer processing device to perform operations comprising:

receiving a communication from a messaging entity;

deriving a risk profile for the communication comprising:

queuing the communication for interrogation by a plurality of interrogation engines, each interrogation engine of a particular type designed to test the communication for a particular security risk;

performing a load evaluation on a interrogation engine of one of the particular types based upon the plurality of interrogation engines queued to interrogate the communication;

determining that the load evaluation exceeds a threshold, and in response adjusting the plurality of the interrogation engines by generating a new instance of an interrogation engine of the one of the particular types based upon the plurality of interrogation engines queued to interrogate the communication;

aggregating output of the plurality of interrogation engines with data associated with previously received communications to form the risk profile for the communication;

determining, using one or more data processors, a reputation score associated with the communication based upon the risk profile;

wherein the reputation score is indicative of reputation of the messaging entity;

wherein the determined reputation score is used in deciding what action is to be taken with respect to communications associated with the messaging entity.

Assignments (14)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 021523 FRAME: 0713. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF PATENT SECURITY AGREEMENT. Recorded Apr 11, 2022
From: CITICORP USA, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 059690/0187 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 023915/0990 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2007
From: CIPHERTRUST, INC.
To: SECURE COMPUTING CORPORATION
Reel/Frame 018771/0221 →
SECURITY AGREEMENT Recorded Sep 14, 2006
From: SECURE COMPUTING CORPORATION; CIPHERTRUST, INC.
To: CITICORP USA, INC. AS ADMINISTRATIVE AGENT
Reel/Frame 018247/0359 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2006
From: JUDGE, PAUL
To: CIPHERTRUST, INC.
Reel/Frame 018089/0265 →