IP Library Patent Application 13175812
Patent Application
App. No. 13/175,812

MULTILEVEL INTENT ANALYSIS APPARATUS & METHOD FOR EMAIL FILTRATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/175,812
Abstract

A method for filtering email which contains links to uniform resource identifiers which disguise the content and identity of spam sites by multiple serial redirection.

Claims (54)

1 . An email filtering apparatus comprising a processor configured to receive an electronic document, scan the document for an embedded uniform resource identifier, and transmit a query to a server having a database of categorized websites.

2 . The apparatus of claim one further configured to scan the electronic document for a pattern expression which exhorts manual navigation to a website, and to transmit a query of that website to a server having a database of categorized websites.

3 . The apparatus of claim 1 further configured to apply a score or grade to the email based on the result received from the database of categorized websites.

4 . The apparatus of claim 1 further configured to forward the email to its intended recipient or discard it based on the result received from the database of categorized websites.

5 . A remote computing system communicatively coupled to a plurality of email filtering apparatus, the computing system configured as a database of categorized websites enabled to receive a query from the email filtering apparatus, to operate as a browser on a first uniform resource identifier, to request a second resource based on redirection received in response to the first resource if one or more links in the second resource are found in the database of categorized websites.

6 . The system of claim 5 further configured to observe redirection in the form of http status codes, refresh meta tags, refresh headers, and frame redirects.

7 . The system of claim 5 further configured to observe redirection by analyzing or observing the operation of Javascripts within a browser.

8 . The system of claim 5 further configured to traverse a series of redirections to land on a target website and determine if the target website is found in a database of categorized websites.

9 . A method comprising the steps following:

scanning an electronic document for at least one embedded uniform resource identifier; and

querying a database of categorized uniform resource identifiers to determine if the embedded uniform resource identifier matches.

10 . The method of claim 9 further comprising the process of

traversing at least one embedded uniform resource identifier wherein traversing comprises emulating a browser in

requesting at least one resource through an internet protocol and

receiving at least one response.

11 . The method of claim 9 further comprising the process of

traversing a plurality of embedded uniform resource identifiers wherein traversing comprises

emulating a browser and

requesting a first resource through an internet protocol and

requesting a second resource based on a redirection received in response to the request for the first resource and

repeating the process if necessary whereby a series of redirections is resolved to a target website.

12 . The method of claim 11 further comprising

querying the database to determine if a uniform resource identifier used in redirection has the characteristic of a categorized uniform resource identifier.

13 . The method of claim 11 wherein redirection comprises a process selected from the following group:

receiving a 3xx http status code wherein x is a numeral;

receiving and resolving a refresh meta tag;

receiving and resolving an http refresh header;

receiving and resolving a Javascript redirect; and

receiving and resolving a frame redirect.

14 . The method of claim 11 further comprising

receiving an http error status code in response to traversing a uniform resource identifier wherein an http error status code comprises one of 4xx and 5xx wherein x is a numeral.

15 . The method of claim 11 further comprising

receiving at least one document and

analyzing the document for at least one link found in a database of categorized websites.

16 . The method of claim 15 wherein analyzing comprises

scanning for a pattern expression which suggests navigating to a website and matching the website in a database of known spam uniform resource identifiers.

17 . The method of claim 15 wherein analyzing comprises

scanning for a pattern expression which suggests a Javascript redirection and matching the redirection in a database of known spam uniform resource identifiers.

18 . The method of claim 15 wherein analyzing comprises

scanning for a pattern expression which suggests an obfuscated Javascript.

19 . The method of claim 15 wherein analyzing comprises

scanning for manual instructions to navigate to a website in a database of known spam uri.

20 . The method of claim 15 further comprising

operating on the electronic mail document wherein operating is selected from the following group:

editing the content of the document,

blocking the document,

inserting a tag into the document,

responding to the sender of the document,

setting a score,

forwarding the document,

calling a function with meta data extracted from the document,

lowering the priority of the document,

bouncing the document, and

disconnecting from the source of the document.

Assignments (2)
RELEASE OF SECURITY INTEREST Recorded Jan 8, 2018
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 045027/0870 →
SECURITY INTEREST Recorded Oct 12, 2012
From: BARRACUDA NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 029218/0107 →