IP Library Granted Patent US 8,850,566
Granted Patent B2
US 8,850,566 · App. 11/927,438 · Granted Sep 30, 2014

Time zero detection of infectious messages

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,850,566
App. No.
11/927,438
Granted
Sep 30, 2014
Kind
B2
Abstract

Detecting infectious messages comprises performing an individual characteristic analysis of a message to determine whether the message is suspicious, determining whether a similar message has been noted previously in the event that the message is determined to be suspicious, classifying the message according to its individual characteristics and its similarity to the noted message in the event that a similar message has been noted previously.

Claims (36)

1. A method of detecting infectious messages, the method comprising:

performing a first individual characteristic analysis of a message, wherein the first individual characteristic analysis includes comparing the individual characteristics of the message to individual characteristics of a previously received message;

generating a first probability of infection based on the first individual characteristic analysis;

generating a second probability of infection based on a second analysis of the message, the second analysis including a traffic analysis for identifying a spike in a number of previously received messages similar to the message, the previously received messages having been classified as suspicious and stored in memory;

determining an overall probability of infection based on the first probability and the second probability; and

classifying the message as infectious based on the overall probability meeting a threshold, wherein the message is classified as suspicious based on failure of the overall probability to meet the threshold.

2. The method of claim 1 , wherein determining the overall probability is further based on weighting the first and second probability.

3. The method of claim 1 , wherein performing the first individual characteristic analysis comprises comparing the individual characteristics of the message to a statistical model.

4. The method of claim 3 , further comprising updating the statistical model based on the classification of the message.

5. The method of claim 3 , wherein the statistical model is based on a plurality of messages previously sent to a recipient.

6. The method of claim 3 , wherein the statistical model is based on a plurality of messages previously sent to a network.

7. The method of claim 1 , wherein the traffic analysis further comprises identifying a predetermined increase in a number of similar suspicious messages received within a specified period of time previously.

8. The method of claim 7 , further comprising updating the overall probability based on the number of similar suspicious messages received within the specified period of time previously.

9. The method of claim 1 , wherein generating the first probability of infection is based on a degree of similarity with a previously received message.

10. The method of claim 1 , further comprising continuing to perform individual characteristic analyses to generate further probabilities of infection until the overall probability meets the threshold or until it is determined that no more individual characteristic analyses are available.

11. The method of claim 1 , further comprising reclassifying the message as legitimate based on the overall probability meeting a second threshold.

12. A method of detecting infectious messages, the method comprising:

performing a first individual characteristic analysis of a message, wherein performing the first individual characteristic analysis includes comparing a signature based on the individual characteristics of the message to a signature based on individual characteristics of a previously received message;

generating a first probability of infection based on the first individual characteristic analysis;

generating a second probability of infection based on a second analysis of the message, the second analysis including a traffic analysis for identifying a spike in a number of previously received messages similar to the message, the previously received messages having been classified as suspicious and stored in memory;

determining an overall probability of infection based on the first probability and the second probability; and

classifying the message as infectious based on the overall probability meeting a threshold, wherein the message is classified as suspicious based on failure of the overall probability to meet the threshold.

13. An apparatus for detecting infections messages, the apparatus comprising:

a testing module stored in memory and executable by a processor to generate a first and second probability of infection, the first probability of infection based on an individual characteristic analysis of a message, wherein the individual characteristic analysis includes a comparison of a signature based on the individual characteristics of the message to a signature based on individual characteristics of a previously received message, the second analysis including a traffic analysis for identifying a spike in a number of previously received messages similar to the message, the previously received messages having been classified as suspicious and stored in memory;

a processor to execute instructions stored in memory to determine an overall probability of infection based on the first probability of infection and the second probability of infection; and

a message classifier stored in memory and executable to classify the message as infectious based on the overall probability meeting a threshold and to classify the message as suspicious based on failure of the overall probability to meet the threshold.

14. The apparatus of claim 13 , wherein the processor further executes instructions stored in memory to weight the first probability and the second probability for the determination of the overall probability.

15. The apparatus of claim 13 , wherein the traffic analysis further comprises identifying a predetermined increase in a number of previously received similar suspicious messages, the similar suspicious messages received within a specified period of time.

16. The apparatus of claim 15 , wherein the processor further executes instructions stored in memory to update the overall probability based on the number of previously received similar suspicious messages.

17. The apparatus of claim 13 , wherein the testing module is further executable to perform another individual characteristic analysis, the individual characteristic analysis generating further probabilities of infection until the overall probability meets the threshold or it is determined that no more individual characteristic analyses are available to be performed.

18. A non-transitory computer-readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method, the method comprising:

performing a first individual characteristic analysis of a message, wherein the first individual characteristic analysis includes comparing the individual characteristics of the message to individual characteristics of a previously received message;

generating a first probability of infection based on the first individual characteristic analysis;

generating a second probability of infection based on a second analysis of the message, the second analysis including a traffic analysis for identifying a spike in a number of previously received messages similar to the message, the previously received messages having been classified as suspicious and stored in memory;

determining an overall probability of infection based on the first probability and the second probability; and

classifying the message as infectious based on the overall probability meeting a threshold, wherein the message is classified as suspicious based on failure of the overall probability to meet the threshold.

Assignments (25)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Mar 1, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045476/0254 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
MERGER Recorded Nov 5, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 036974/0223 →
CONVERSION AND NAME CHANGE Recorded Nov 5, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037056/0084 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024776/0337 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0115 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024823/0280 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0126 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024823/0280 →
SECURITY AGREEMENT Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024776/0337 →
MERGER Recorded Jul 28, 2010
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 024755/0083 →
CHANGE OF NAME Recorded Jul 28, 2010
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 024755/0091 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2008
From: MAILFRONTIER, INC.
To: SONICWALL, INC.
Reel/Frame 020486/0653 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2008
From: RIHN, JENNIFER; OLIVER, JONATHAN J.
To: MAILFRONTIER, INC.
Reel/Frame 020486/0639 →