IP Library Granted Patent US 8,363,793
Granted Patent B2
US 8,363,793 · App. 13/091,011 · Granted Jan 29, 2013

Stopping and remediating outbound messaging abuse

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,363,793
App. No.
13/091,011
Granted
Jan 29, 2013
Kind
B2
Abstract

Systems and methods are provided for allowing subscriber message sending profiles to be maintained and used in conjunction with behavior-based anomaly detection techniques and traditional content-based spam signature filtering to enable application of appropriate message disposition policies to outbound subscriber message traffic. According to one embodiment, subscriber profiles are constructed for multiple subscriber accounts associated with a service provider based on outbound message flow originated from the subscriber accounts. Then, possible subscriber account misuse may be discovered by performing behavior-based anomaly detection, including a comparison of a subscriber profile associated with the subscriber account with recent subscriber account usage information, to identify one or more behavioral anomalies in outbound message flow originated from a subscriber account, the behavior-based anomaly detection.

Claims (45)

1. A method comprising:

extracting behavior data from outbound messages originated from a subscriber account, wherein the behavior data includes attributes that are indicative of misuse of the subscriber account;

building a profile for the subscriber account based on the behavior data, the profile Including long-term outbound message flow data associated with the subscriber account;

tracking said behavior data; and

detecting a behavior-based anomaly for the outbound messages by comparing recent outbound messages originated from the subscriber account to the long-term outbound message flow data of the profile of the subscriber account to detect changes in the recent outbound messages in comparison to the profile of the subscriber account.

2. The method of claim 1 , further comprising determining reputation data for the subscriber account based on the detected behavior-based anomaly, wherein the reputation data is added to the profile to determine a reputation score, and wherein if the reputation score falls below a threshold, then any subsequent outbound messages from the subscriber account are redirected.

3. The method of claim 1 , further comprising determining reputation data for the subscriber account based on the detected behavior-based anomaly, wherein the reputation data is added to the profile to determine a reputation score, and wherein if the reputation score falls below a threshold, then any subsequent outbound messages from the subscriber account are redirected for a specific time interval.

4. The method of claim 1 wherein said behavior data comprises at least one of a group consisting of: metrics relating to a size of the outbound messages, metrics relating to a number of recipients specified in the outbound messages, metrics relating to presence of attachments to the outbound messages, metrics relating to timing of the outbound messages, a total number of the outbound messages, a total number of the outbound messages suspected of being spam, a total number of the outbound messages suspected of containing a virus, an average number of the outbound messages, an average size of the outbound messages, a largest size of the outbound messages, a maximum size permitted for the outbound messages, an average number of recipients for the outbound messages, a largest number of recipients for the outbound messages, a maximum number of recipients permitted for the outbound messages, a frequency of repetition of recipients for the outbound messages, an address format employed for the outbound messages, an average number of message header lines for the outbound messages, an average Bayesian spam filter score for the outbound messages, a number of the outbound messages originated with attachments, a number of the outbound messages originated with particular attachment types, a number of the outbound messages originated by a particular mailer, a number of the outbound messages containing a particular character set, and standard deviations of various measurements of the outbound messages.

5. The method of claim 1 further comprising alerting a network operations analyst of potential account misuse based on the detected behavior-based anomaly.

6. The method of claim 2 comprising applying a predetermined set of message disposition policies to messages originated from the subscriber account based upon the reputation score.

7. The method of claim 2 further comprising:

combining said reputation data with content-based spam signature filtering to construct combined reputation data for the subscriber account;

taking an immediate action on one of the outbound messages in response to the combined reputation data; and

taking a long term action on the subscriber account in response to said combined reputation data.

8. The method of claim 2 wherein the building of the profile is performed until there is sufficient behavior data to identify an anomaly prior to the detecting of the behavior-based anomalies.

9. A sender reputation gateway system, comprising:

a service and response system that services and responds to requests from at least one subscriber account;

a behavior data extraction system that extracts behavior data of said at least one subscriber account from outbound messages originated from the subscriber account, the behavior data including attributes of the subscriber account that are indicative of misuse of the subscriber account;

a profile builder system that builds a profile for the subscriber account based on the behavior data extracted from the outbound messages, the subscriber profile including long-term outbound messages flow data associated with subscriber account;

a tracking system that tracks the behavior data; and

an anomaly detection system that detects behavior-based anomalies for the outbound messages by comparing recent outbound messages originated from the subscriber account to the long-term outbound message flow data of the profile of the subscriber account to detect changes in the recent outbound messages in comparison to the profile of the subscriber account.

10. The sender reputation gateway system of claim 9 , further comprising:

a reputation data determination system that determines reputation data for the subscriber account based on the detected behavior-based anomalies, wherein the reputation data is added to the profile to determine a reputation score, and wherein if the reputation score falls below a threshold, then any subsequent outbound messages from the subscriber account are redirected.

11. The sender reputation gateway system of claim 9 , further comprising:

a reputation data determination system that determines reputation data for the subscriber account based on the detected behavior-based anomalies, wherein the reputation data is added to the profile to determine a reputation score, and wherein if the reputation score falls below a threshold, then any subsequent outbound messages from the subscriber account are redirected for a specific time interval.

12. The sender reputation gateway system of claim 9 wherein said behavior data comprises at least one of a group consisting of: metrics relating to a size of the outbound messages, metrics relating to a number of recipients specified in the outbound messages, metrics relating to presence of attachments to the outbound messages, metrics relating to timing of the outbound messages, a total number of the outbound messages, a total number of the outbound messages suspected of being spam, a total number of the outbound messages suspected of containing a virus, an average number of the outbound messages, an average size of the outbound messages, a largest size of the outbound messages, a maximum size permitted for the outbound messages, an average number of recipients for the outbound messages, a largest number of recipients for the outbound messages, a maximum number of recipients permitted for the outbound messages, a frequency of repetition of recipients for the outbound messages, an address format employed for the outbound messages, an average number of message header lines for the outbound messages, an average Bayesian spam filter score for the outbound messages, a number of the outbound messages originated with attachments, a number of the outbound messages originated with particular attachment types, a number of the outbound messages originated by a particular mailer, a number of the outbound messages containing a particular character set, and standard deviations of various measurements of the outbound messages.

13. The sender reputation gateway system of claim 9 further comprising an alert system that alerts a network operations analyst of potential subscriber account misuse based on the behavior-based anomalies.

14. The sender reputation gateway system of claim 10 further comprising a disposition policy system that applies a predetermined set of message disposition policies to the messages originated by the subscriber account based upon the reputation data for the subscriber account.

15. The sender reputation gateway system of claim 10 wherein the reputation data determination system further combines the reputation data with content-based spam signature filtering to construct combined reputation data for the subscriber account; takes an immediate action on a particular message originated by the subscriber account in response to the combined reputation data; and takes a long term action on the subscriber account in response to the combined reputation data.

16. The sender reputation gateway system of claim 10 wherein the profile builder system operates until there is sufficient behavior data to identify anomalies prior to operating the anomaly detection system.

17. Logic encoded in one or more tangible media that includes code for execution and when executed by one or more processors is operable to perform operations comprising:

extracting behavior data from outbound messages originated from a subscriber account, wherein the behavior data includes attributes that are indicative of misuse of the subscriber account;

building a profile for the subscriber account based on the behavior data, the subscriber profile including long-term outbound message flow data associated with the subscriber account;

tracking said behavior data; and

detecting a behavior-based anomaly for the outbound messages by comparing recent outbound messages originated from the subscriber account to the long-term outbound message flow data of the profile of the subscriber account to detect changes in the recent outbound messages in comparison to the profile of the subscriber account.

18. The encoded logic of claim 17 , further comprising determining reputation data for the subscriber account based on the detected behavior-based anomaly, wherein the reputation data is added to the profile to determine a reputation score, and wherein if the reputation score falls below a threshold, then any subsequent outbound messages from the subscriber account are redirected.

19. The encoded logic of claim 17 , further comprising determining reputation data for the subscriber account based on the detected behavior-based anomaly, wherein the reputation data is added to the profile to determine a reputation score, and wherein if the reputation score falls below a threshold, then any subsequent outbound messages from the subscriber account are redirected for a specific time interval.

20. The encoded logic of claim 18 wherein said behavior data comprises at least one of a group consisting of: metrics relating to a size of the outbound messages, metricscrelating to a number of recipients specified in the outbound messages, metrics relating to presence of attachments to the outbound messages, metrics relating to timing of the outbound messages, a total number of the outbound messages, a total number of the outbound messages suspected of being spam, a total number of the outbound messages suspected of containing a virus, an average number of the outbound messages, an average size of the outbound messages, a largest size of the outbound messages, a maximum size permitted for the outbound messages, an average number of recipients for the outbound messages, a largest number of recipients for the outbound messages, a maximum number of recipients permitted for the outbound messages, a frequency of repetition of recipients for the outbound messages, an address format employed for the outbound messages, an average number of message header lines for the outbound messages, an average Bayesian spam filter score for the outbound messages, a number of the outbound messages originated with attachments, a number of the outbound messages originated with particular attachment types, a number of the outbound messages originated by a particular mailer, a number of the outbound messages containing a particular character set, and standard deviations of various measurements of the outbound messages.

21. The encoded logic of claim 17 further comprising alerting a network operations analyst of potential account misuse based on the detected behavior-based anomaly.

22. The encoded logic of claim 18 comprising applying a predetermined set of message disposition policies to messages originated from the subscriber account based upon the reputation score.

23. The encoded logic of claim 18 further comprising:

combining said reputation data with content-based spam signature filtering to construct combined reputation data for the subscriber account;

taking an immediate action on one of the outbound messages in response to the combined reputation data; and

taking a long term action on the subscriber account in response to said combined reputation data.

24. The encoded logic of claim 18 wherein the building of the profile is performed until there is sufficient behavior data to identify an anomaly prior to the detecting of the behavior-based anomalies.

Assignments (20)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →