IP Library Granted Patent US 8,910,279
Granted Patent B2
US 8,910,279 · App. 13/210,324 · Granted Dec 9, 2014

Reputation-based threat protection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,910,279
App. No.
13/210,324
Granted
Dec 9, 2014
Kind
B2
Abstract

Information concerning a plurality of identified threats provided by a plurality of preselected sources is stored in memory. An e-mail message may be received over a communication network. The received e-mail message is separated into a plurality of components. The stored information is searched to identify a reputation score associated with each of the plurality of components. It is then determined whether the e-mail is a threat based on the identified reputation score of each of the plurality of components. The determination is sent to a designated recipient.

Claims (41)

1. A method for reputation-based threat protection, the method comprising:

maintaining information in memory concerning a plurality of identified threats, the maintained information provided by a plurality of preselected sources;

intercepting an e-mail message from a sender in an organization and addressed to a destination outside of the organization, wherein the e-mail message is intercepted prior to leaving a communication network of the organization;

executing instructions stored in memory, wherein execution of the instructions by a processor:

separates the intercepted e-mail message into a plurality of components,

searches the maintained information to identify a reputation score associated with each of the plurality of components,

determines whether the intercepted e-mail message includes sensitive data as defined by policies of the organization, wherein the determination is based on one or more dictionaries for identifying the sensitive data, and

determines that the e-mail message is a threat based on the identified reputation score of each of the plurality of components and whether the e-mail message includes sensitive data;

sending information to a designated recipient within the organization regarding the determination that the email message is a threat, the information being sent over the communication network;

placing the e-mail message in quarantine for analysis;

permitting the designated recipient to review the quarantined e-mail message and information regarding the determination that the e-mail message is a threat; and

notifying the sender that the e-mail message was determined to be a threat.

2. The method of claim 1 , further comprising generating a thumbprint for each of the plurality of components.

3. The method of claim 2 , wherein each of the preselected sources is allowed one vote per thumbprint per day.

4. The method of claim 3 , wherein the reputation score for each of the plurality of components is based on a collection of votes from the preselected sources.

5. The method of claim 1 , further comprising:

identifying the sender of the e-mail message determined to be a threat; and

sending an alert regarding the identified sender.

6. The method of claim 5 , further comprising locating the sender device, wherein the sender device is placed in safe mode.

7. The method of claim 1 , wherein the analysis includes permitting the sender to review the quarantined message and information regarding the determination that the e-mail message is a threat.

8. The method of claim 1 , wherein content in the quarantined message is blocked from display.

9. A non-transitory computer-readable storage medium, having embodied thereon a program executable by a processor to perform a method for reputation-based threat protection, the method comprising:

maintaining information concerning a plurality of identified threats, the maintained information provided by a plurality of preselected sources;

intercepting an e-mail message from a sender in an organization and addressed to a destination outside of the organization, wherein the e-mail message is intercepted prior to leaving a communication network of the organization;

separating the intercepted e-mail message into a plurality of components;

searching the maintained information to identify a reputation score associated with each of the plurality of components;

determining whether the intercepted e-mail message includes sensitive data as defined by policies of the organization, wherein the determination is based on one or more dictionaries for identifying the sensitive data,

determining that the e-mail message is a threat based on the identified reputation score of each of the plurality of components and whether the e-mail message includes sensitive data;

sending information to a designated recipient within the organization regarding the determination that the e-mail message is a threat;

placing the e-mail message in quarantine for analysis;

permitting the designated recipient to review the quarantined e-mail message and information regarding the determination that the e-mail message is a threat; and

notifying the sender that the e-mail message was determined to be a threat.

10. The non-transitory computer-readable storage medium of claim 9 , wherein content in the quarantined message is blocked from display.

11. The non-transitory computer-readable storage medium of claim 9 , the program further executable to generate a thumbprint for each of the plurality of components.

12. The non-transitory computer-readable storage medium of claim 11 , wherein each of the preselected sources is allowed one vote per thumbprint per day.

13. The non-transitory computer-readable storage medium of claim 12 , wherein the reputation score for each of the plurality of components is based on a collection of votes from the preselected sources.

14. The non-transitory computer-readable storage medium of claim 9 , the program further executable to:

identify the sender of the e-mail message determined to be a threat; and

send an alert regarding the identified sender.

15. The non-transitory computer-readable storage medium of claim 14 , the program further executable to locate the sender device, wherein the sender device is placed in safe mode.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the analysis includes permitting the sender to review the quarantined message and information regarding the determination that the e-mail message is a threat.

Assignments (17)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Jan 9, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045029/0497 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
CONVERSION AND NAME CHANGE Recorded Sep 9, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 036579/0961 →
MERGER Recorded Sep 9, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 036524/0647 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2011
From: YANOVSKY, BORIS; EIKENBERRY, SCOTT
To: SONICWALL, INC.
Reel/Frame 027294/0963 →