IP Library Granted Patent US 8,015,250
Granted Patent B2
US 8,015,250 · App. 11/579,171 · Granted Sep 6, 2011

Method and system for filtering electronic messages

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,015,250
App. No.
11/579,171
Granted
Sep 6, 2011
Kind
B2
Abstract

Embodiments of the invention provide a system and methods for filtering electronic messages having data therein identifying a link to a remote processing system. One embodiment provides a method which includes interrupting the transmission of the electronic message, identifying a link within the electronic message, and analyzing the electronic message on the basis of at least one of an attribute of the link and of at least an attribute intrinsic to the received electronic message so as to classify the message as either a suspect message or acceptable message. The method further includes modifying the electronic message so as to replace the link with an alternative network location corresponding to a remote processing system different from that corresponding to the link if the message is classified as a suspect message. The method further includes transmitting the electronic message unmodified if the message is classified as an acceptable message.

Claims (53)

1. A method of modifying an electronic message during transmission through a communications network, said electronic message having a source address and a recipient address, the method comprising:

interrupting transmission of the electronic message;

identifying, by use of a processor, a first link specified within the electronic message, said first link directed to a first network location;

analyzing, by use of a processor, at least the electronic message on the basis of at least one of an attribute of the first link, independent of content of the first network location associated with the first link, and at least an attribute intrinsic to the electronic message so as to classify the electronic message as either a suspect message or an acceptable message;

in response to classification of the electronic message as a suspect message, modifying, by use of a processor, the electronic message, wherein modifying the electronic message comprises:

modifying the first link to comprise link matter that represents the first link; and

wrapping the link matter within a second link directed to an alternative network location, said alternative network location corresponding to a remote processing system different from that corresponding to the first link;

transmitting the modified electronic message; and

in response to classification of the electronic message as an acceptable message, transmitting the unmodified message.

2. A method according to claim 1 , wherein modifying the first link comprises encoding the first link so as to generate said link matter.

3. A method according to claim 1 , wherein modifying the first link comprises assigning an alias to the first link so as to generate said link matter.

4. A method according to claim 1 , wherein wrapping the link matter within the second link comprises containing the link matter within the second link so as to associate said link matter with the second link.

5. A method according to claim 1 , including analyzing the transmitted electronic message on the basis of a criterion unrelated to the first network location.

6. A method according to claim 5 , including analyzing the transmitted electronic message on the basis of a criterion relating to the first network location.

7. A method according to claim 1 , including analyzing the transmitted electronic message on the basis of a criterion relating to at least one other attribute of the electronic message.

8. A method according to claim 7 , in which the criterion includes the sender address and/or the recipient address.

9. A method according to claim 1 , including comparing the first network location with network locations contained within electronic messages that have previously been identified as of the unsolicited type.

10. A method according to claim 1 , including transmitting the modified electronic message to the recipient address.

11. A method according to claim 1 , further comprising:

further classifying the suspect message as an unacceptable message; and

if the electronic message is classified as an unacceptable message, preventing transmission of the received message.

12. A method of identifying an electronic message as an unsolicited electronic message on the basis of a network location specified therein, wherein data indicative of the electronic message are stored in association with the network location, the method comprising:

responsive to a request for access to the network location from a recipient of the electronic message, accessing data indicative of a classification of said electronic message;

retrieving data associated with said network location, independent of data contained at the site associated with the network location, and analyzing, by use of a processor, said retrieved data so as to validate said classification of said electronic message as unsolicited or solicited;

in response to classification of the electronic message as unsolicited, modifying, by use of a processor, the network location specified in the electronic message, wherein modifying the network location comprises:

modifying the network location specified in the electronic message to comprise matter that represents said network location; and

wrapping said matter within a link directed to an alternative network location which corresponds to a remote processing system that is different than the one corresponding to the network location specified in the electronic message;

allowing access to the alternative network location; and

in response to classification of the electronic message as solicited, allowing access to the network location specified in the electronic message.

13. A method according to claim 12 , in which, responsive to said request, the method includes accessing a processing system corresponding to said network location so as to retrieve said data.

14. A method according to claim 12 , in which, responsive to said request, the method includes retrieving data previously accessed from a processing system corresponding to said network location.

15. A method according to claim 12 , in which said matter that represents said network location comprises encoded data corresponding to the network location.

16. A method according to claim 12 , in which said matter that represents said network location comprises an alias corresponding to the network location, and the method further comprises identifying the network location from the alias.

17. A method according to claim 12 , including notifying the recipient of the classification of the electronic message.

18. A method according to claim 12 , including transmitting data retrieved from the network location to the recipient in the event that the electronic message is classified as being of the solicited type.

19. A method of modifying an electronic message transmitted through a communications network, the method comprising:

receiving an electronic message;

identifying, by use of a processor, first data indicative of a first network location, the first data being independent of data contained at the site associated with the first network location, said first network location being specified within the electronic message;

analyzing, by use of a processor, the electronic message on the basis of at least an attribute intrinsic to the message and unrelated to the first network location so as to classify the message as either a suspect message or an acceptable message;

in response to classification of the electronic message as a suspect message, associating, by use of a processor, the first data with second data indicative of a second network location, said second network location corresponding to a remote processing system different to that corresponding to the first network location, wherein associating the first data with second data comprises:

generating matter that represents the first data; and

wrapping said matter with the second data;

modifying the electronic message so as to include the second data;

transmitting the modified electronic message; and

in response to classification of the electronic message as an acceptable message, transmitting the unmodified electronic message.

20. A system for modifying an electronic message during transmission through a communications network, said electronic message having a source address and a recipient address, the system comprising:

a network interface for receiving the electronic message before it has been delivered to a device corresponding to the recipient address;

the system comprising a processor arranged to identify a first link specified within the received electronic message, said first link directed to a first network location, and to analyze at least the electronic message on the basis of at least one of an attribute of the first link, independent of content of the site associated with the first link, and at least an attribute intrinsic to the received electronic message so as to classify the received electronic message as either a suspect message or an acceptable message;

wherein, in response to classification of the received message as a suspect message, the system is arranged to modify the received electronic message, wherein modifying the electronic message comprises:

modifying the first link to comprise link matter that represents the first link; and

wrapping the link matter within a second link directed to an alternative network location said alternative network location corresponding to a remote processing system different from that corresponding to the first link;

wherein the system is further arranged to transmit the modified electronic message; and

wherein, in response to classification of the received message as an acceptable message, the system is arranged to transmit the unmodified electronic message.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0220 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 12, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 045312/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT CLOUD LIMITED
To: FORCEPOINT LLC
Reel/Frame 043156/0235 →
CHANGE OF NAME Recorded Jul 6, 2016
From: WEBSENSE HOSTED R&D LIMITED
To: FORCEPOINT CLOUD LIMITED
Reel/Frame 039086/0134 →
CHANGE OF NAME Recorded May 7, 2009
From: SURFCONTROL ON-DEMAND LIMITED
To: WEBSENSE HOSTED R&D LIMITED
Reel/Frame 022660/0259 →
CHANGE OF NAME Recorded Jan 12, 2007
From: BLACKSPIDER TECHNOLOGIES LIMITED
To: SURFCONTROL ON-DEMAND LIMITED
Reel/Frame 018755/0229 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2006
From: KAY, JAMES
To: BLACKSPIDER TECHNOLOGIES
Reel/Frame 018707/0757 →