IP Library Granted Patent US 9,160,755
Granted Patent B2
US 9,160,755 · App. 11/465,433 · Granted Oct 13, 2015

Trusted communication network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,160,755
App. No.
11/465,433
Granted
Oct 13, 2015
Kind
B2
Abstract

A system includes a processing node configured to send authorized inbound messages to registered enterprise networks. An authorized message is a message that includes trusted source indicia. Trusted source indicia indicates that the message was sent by one or more of the processing node or an authenticated message transfer node associated with one of the registered enterprise networks. The system may further include an administration node configured to maintain registration of a plurality of message transfer nodes associated with the enterprise networks. A method includes receiving outbound messages from an authenticated message transfer node of an enterprise network, screening the messages for threats to determine whether to send the messages to associated recipients, applying a first message identifier to each message, wherein the first message identifier can be used to track the message and, for each message, sending the message to the associated recipient if no threats are detected in the message.

Claims (60)

1. An apparatus for limiting bounce attacks, comprising:

a processing node provided on a computer system having a processor and a computer-readable memory that:

receives an outbound message;

filters said outbound message for threats to determine whether to send said outbound message to at least one message recipient of said outbound message;

in response to determining said outbound message is trusted:

applies a trusted message identifier to said outbound message that identifies said outbound message as a trusted message prescreened for a security threat and having been originated from an authenticated private network member;

inserts a message tracking identifier (ID), a bounce tracking message ID, and a sender authentication tracking message ID into the outbound message, wherein the message tracking ID is generated using a hash of portions of the outbound message;

stores at least the bounce tracking message ID among one or more bounce tracking message IDs at the processing node; and

sends the outbound message to the at least one message recipient of said outbound message;

distinguishes whether a bounce back message is authorized and corresponds to one of the outbound messages sent by the processing node by determining whether bounce tracking message ID in the bounce back message corresponds to one of the bounce tracking message IDs stored at the processing node, wherein the bounce back message is a non-delivery report; and

generates a reputation metric associated with each member network of a plurality of registered member networks, wherein said reputation metric is based at least in part on threats detected in messages sent from said plurality of member networks.

2. The apparatus of claim 1 , wherein said processing node further sends said outbound message to said at least one recipient on other member networks of the plurality of member networks and on non-member networks available on a public network system.

3. The apparatus of claim 1 , further comprising a hosted domain name system (DNS) server configured to provide authentication data when queried by said at least one recipient of said outbound message.

4. The apparatus of claim 3 , wherein said authentication data provided by said hosted DNS server comprises an Internet Protocol (IP) address associated with said processing node.

5. The apparatus of claim 1 , wherein the bounce tracking message ID comprises a hash of one or more parts of the message and replaces a sender envelope ID of the outbound message.

6. The apparatus of claim 1 , wherein said processing node further quarantines outbound messages that have associated threats.

7. The apparatus of claim 6 , wherein said processing node disposes of said outbound messages based on an enterprise disposition policy, wherein said disposition policy is selected from a group consisting of:

quarantine until release,

bounce back to specified enterprise network user,

delete without sending,

deliver after a specified time, and

deliver only after approval.

8. The apparatus of claim 1 , further comprising one or more policies associated with a first member network of the plurality of member networks, wherein one of said one or more policies specifies filtering attributes upon which outbound messages are to be filtered, and wherein said processing node further filters outbound messages according to said one or more policies.

9. The apparatus of claim 8 , wherein said one or more policies comprise one or more of an enterprise-level policy, a group-level policy, a department-level policy, or a user-level policy.

10. The apparatus of claim 8 , wherein said one or more policies specifies a standard stationary to be applied to every outbound message sent from each member network of said plurality of member networks.

11. The apparatus of claim 1 , wherein said processing node further inserts one or more identifiers into each outbound message sent wherein said identifiers are selected from a group consisting of:

an integrity checksum signature; and

a domain name authentication identifier.

12. A non-transitory computer-readable storage medium having machine-executable instructions that when executed on a processor configure the processor to:

receive an outbound message;

filter said outbound message for threats to determine whether to send said outbound message to at least one message recipient of said outbound message;

in response to determining said outbound message is trusted:

apply a trusted message identifier to said outbound message that identifies said outbound message as a trusted message prescreened for a security threat and having been originated from an authenticated private network member;

inserts a message tracking ID, a bounce tracking message ID, and a sender authentication tracking message ID into the outbound message, wherein the message tracking ID is generated using a hash of portions of the outbound message;

store at least the bounce tracking message ID among one or more bounce tracking message IDs at the processing node; and

send the outbound message to the at least one message recipient of said outbound message;

distinguish whether a bounce back message is authorized and corresponds to one of the outbound messages sent by the processing node by determining whether bounce tracking message ID in the bounce back message corresponds to one of the bounce tracking message IDs stored at the processing node, wherein the bounce back message is a non-delivery report; and

generate a reputation metric associated with each member network of a plurality of registered member networks, wherein said reputation metric is based at least in part on threats detected in messages sent from said plurality of member networks.

13. The medium of claim 12 , wherein the machine executable instructions that when executed on the processor configure the processor further to:

send said outbound message to said at least one recipient on other member networks of the plurality of member networks and on non-member networks available on a public network system.

14. The medium of claim 12 , wherein the machine executable instructions that when executed on the processor configure the processor to filter the outbound message according to one or more policies associated with a first member network of the plurality of member networks, wherein one of said one or more policies specifies filtering attributes upon which outbound messages are to be filtered.

15. The medium of claim 14 , wherein said one or more policies comprise one or more of an enterprise-level policy, a group-level policy, a department-level policy, or a user-level policy.

16. The medium of claim 14 , wherein said one or more policies specifies a standard stationary to be applied to every outbound message sent from each member network of said plurality of member networks.

17. The medium of claim 12 , wherein the machine-executable instructions that when executed on the processor configure the processor to further insert one or more identifiers into each outbound message sent wherein said identifiers are selected from a group consisting of:

an integrity checksum signature; and

a domain name authentication identifier.

18. A method for limiting bounce attacks, comprising:

receiving, by a processing node executing on a processor, of a an outbound message;

filtering, by the processing node, said outbound message for threats to determine whether to send said outbound message to at least one message recipient of said outbound message;

in response to determining said outbound message is trusted:

applying, by the processing node, a trusted message identifier to said outbound message that identifies said outbound message as a trusted message prescreened for a security threat and having been originated from an authenticated private network member;

inserting, by the processing node, a message tracking ID, a bounce tracking message ID, and a sender authentication tracking message ID into the outbound message, wherein the message tracking ID is generated using a hash of portions of the outbound message;

storing, by the processing node, at least the bounce tracking message ID among one or more bounce tracking message IDs at the processing node;

sending, by the processing node, the outbound message to the at least one message recipient of said outbound message;

distinguishing, by the processing node, whether a bounce back message is authorized and corresponds to one of the outbound messages sent by the processing node by determining whether bounce tracking message ID in the bounce back message corresponds to one of the bounce tracking message IDs stored at the processing node, wherein the bounce back message is a non-delivery report; and

generating a reputation metric associated with each member network of a plurality of registered member networks, wherein said reputation metric is based at least in part on threats detected in messages sent from said plurality of member networks.

19. The method of claim 18 , further comprising filtering the outbound message according to one or more policies associated with a first member network of the plurality of member networks, wherein one of said one or more policies specifies filtering attributes upon which outbound messages are to be filtered.

20. The method of claim 18 , further comprising inserting one or more identifiers into each outbound message sent wherein said identifiers are selected from a group consisting of:

an integrity checksum signature; and

a domain name authentication identifier.

Assignments (24)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Sep 15, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043969/0057 →
MERGER Recorded Apr 18, 2010
From: MX LOGIC, INC.
To: MCAFEE, INC.
Reel/Frame 024244/0644 →
SECURITY AGREEMENT Recorded May 30, 2007
From: GDX NETWORK, INC.
To: ORIX VENTURE FINANCE LLC
Reel/Frame 019358/0161 →
CHANGE OF NAME Recorded Mar 2, 2007
From: MXTN, INC.
To: GDX NETWORK, INC.
Reel/Frame 018955/0736 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2006
From: CHASIN, C. SCOTT; LIN, WEI
To: MXTN, INC.
Reel/Frame 018410/0689 →