IP Library Granted Patent US 9,049,235
Granted Patent B2
US 9,049,235 · App. 13/683,976 · Granted Jun 2, 2015

Cloud email message scanning with local policy application in a network environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,049,235
App. No.
13/683,976
Granted
Jun 2, 2015
Kind
B2
Abstract

A method for applying policies to an email message includes receiving, by an inbound policy module in a protected network, message metadata of an email message. The method also includes determining, based on the message metadata, whether receiving the email message in the protected network is prohibited by at least one metadata policy. The method further includes blocking the email message from being forwarded to the protected network if receiving the email message in the protected network is prohibited by the metadata policy. In specific embodiments, the method includes requesting scan results data for the email message if receiving the email message in the protected network is not prohibited by one or more metadata policies. In further embodiments, the method includes receiving the scan results data and requesting the email message if receiving the email message in the protected network is not prohibited by one or more scan policies.

Claims (92)

1. A method for applying policies to an email message, comprising:

receiving, by an inbound policy module in a protected network, message metadata of an email message en route to an intended recipient associated with the protected network, wherein the message metadata is to be received without the email message;

determining, based on the message metadata, whether receiving the email message in the protected network is prohibited by at least one metadata policy of one or more metadata policies;

sending a response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is determined to be prohibited by the at least one metadata policy;

sending a request from the protected network for scan results data for the email message if receiving the email message in the protected network is determined not to be prohibited by the one or more metadata policies;

receiving, by the inbound policy module in the protected network, the scan results data;

determining, based on the scan results data, whether receiving the email message in the protected network is prohibited by at least one scan policy of one or more scan policies;

sending a particular response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is prohibited by the at least one scan policy;

sending a request from the protected network for the email message if receiving the email message in the protected network is not prohibited by the one or more scan policies;

receiving, by the inbound policy module in the protected network, the email message in response to the request for the email message; and

forwarding the email message to a destination network address associated with a recipient email address, wherein the destination network address is in the protected network.

2. The method of claim 1 , wherein the response is sent to an email threat sensor in a cloud network, wherein the email threat sensor received the email message from a sending client in another network.

3. The method of claim 1 , further comprising:

scanning the received email message for content prohibited by one or more local scan policies; and

responsive to finding at least some prohibited content during the scanning, quarantining the email message.

4. The method of claim 1 , further comprising:

scanning the received email message for content prohibited by one or more local scan policies; and

responsive to finding at least some prohibited content during the scanning, blocking the email message from being delivered to the intended recipient of the email message.

5. The method of claim 1 , further comprising:

scanning the received email message for content prohibited by one or more local scan policies; and

responsive to not finding any prohibited content during the scanning, forwarding the email message to a mail server in the protected network, wherein the mail server delivers the email message to the intended recipient of the email message.

6. At least one non-transitory machine readable storage medium having instructions stored thereon for applying policies to an email message, the instructions when executed by a processor cause the processor to:

receive, by an inbound policy module in a protected network, message metadata of an email message en route to an intended recipient associated with the protected network, wherein the message metadata is to be received without the email message;

determine, based on the message metadata, whether receiving the email message in the protected network is prohibited by at least one metadata policy of one or more metadata policies;

send a response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is determined to be prohibited by the at least one metadata policy;

send a request from the protected network for scan results data for the email message if receiving the email message in the protected network is determined not to be prohibited by the one or more metadata policies;

receive, by the inbound policy module in the protected network, the scan results data;

determine, based on the scan results data, whether receiving the email message in the protected network is prohibited by at least one scan policy of one or more scan policies;

send a particular response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is prohibited by the at least one scan policy;

send a request from the protected network for the email message if receiving the email message in the protected network is not prohibited by the one or more scan policies;

receive, by the inbound policy module in the protected network, the email message in response to the request for the email message; and

forward the email message to a mail server in the protected network, wherein the mail server delivers the email message to the intended recipient of the email message.

7. The at least one non-transitory machine readable storage medium of claim 6 , wherein the response is to be sent to an email threat sensor in a cloud network, wherein the email threat sensor is to receive the email message from a sending client in another network.

8. At least one non-transitory machine readable storage medium having instructions stored thereon for applying policies to an email message, the instructions when executed by a processor cause the processor to:

receive, by an inbound policy module in a protected network, message metadata of an email message en route to an intended recipient associated with the protected network, wherein the message metadata is to be received without the email message;

determine, based on the message metadata, whether receiving the email message in the protected network is prohibited by at least one metadata policy of one or more metadata policies;

send a response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is determined to be prohibited by the at least one metadata policy;

send a request from the protected network for scan results data for the email message if receiving the email message in the protected network is determined not to be prohibited by the one or more metadata policies;

receive, by the inbound policy module in the protected network, the scan results data;

determine, based on the scan results data, whether receiving the email message in the protected network is prohibited by at least one scan policy of one or more scan policies;

send a particular response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is prohibited by the at least one scan policy;

send a request from the protected network for the email message if receiving the email message in the protected network is not prohibited by the one or more scan policies;

receive, by the inbound policy module in the protected network, the email message in response to the request for the email message;

scan the received email message for content prohibited by one or more local scan policies; and

responsive to finding at least some prohibited content during the scanning, quarantine the email message.

9. At least one non-transitory machine readable storage medium having instructions stored thereon for applying policies to an email message, the instructions when executed by a processor cause the processor to:

receive, by an inbound policy module in a protected network, message metadata of an email message en route to an intended recipient associated with the protected network, wherein the message metadata is to be received without the email message;

determine, based on the message metadata, whether receiving the email message in the protected network is prohibited by at least one metadata policy of one or more metadata policies;

send a response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is determined to be prohibited by the at least one metadata policy;

send a request from the protected network for scan results data for the email message if receiving the email message in the protected network is determined not to be prohibited by the one or more metadata policies;

receive, by the inbound policy module in the protected network, the scan results data;

determine, based on the scan results data, whether receiving the email message in the protected network is prohibited by at least one scan policy of one or more scan policies;

send a particular response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is prohibited by the at least one scan policy;

send a request from the protected network for the email message if receiving the email message in the protected network is not prohibited by the one or more scan policies;

receive, by the inbound policy module in the protected network, the email message in response to the request for the email message;

scan the received email message for content prohibited by one or more local scan policies; and

responsive to finding at least some prohibited content during the scanning, block the email message from being delivered to the intended recipient of the email message.

10. At least one non-transitory machine readable storage medium having instructions stored thereon for applying policies to an email message, the instructions when executed by a processor cause the processor to:

receive, by an inbound policy module in a protected network, message metadata of an email message en route to an intended recipient associated with the protected network, wherein the message metadata is to be received without the email message;

determine, based on the message metadata, whether receiving the email message in the protected network is prohibited by at least one metadata policy of one or more metadata policies;

send a response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is determined to be prohibited by the at least one metadata policy;

send a request from the protected network for scan results data for the email message if receiving the email message in the protected network is determined not to be prohibited by the one or more metadata policies;

receive, by the inbound policy module in the protected network, the scan results data;

determine, based on the scan results data, whether receiving the email message in the protected network is prohibited by at least one scan policy of one or more scan policies;

send a particular response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is prohibited by the at least one scan policy;

send a request from the protected network for the email message if receiving the email message in the protected network is not prohibited by the one or more scan policies;

receive the email message in response to the request for the email message;

scan the received email message for content prohibited by a local scan policy; and

responsive to not finding any prohibited content during the scanning, forward the email message to a mail server in the protected network, wherein the mail server is configured to deliver the email message to the intended recipient of the email message.

11. An apparatus for applying policies to an email message, comprising:

a processor in a protected network; and

an inbound policy module executing on the processor, the inbound policy module configured to:

receive message metadata of an email message en route to an intended recipient associated with the protected network, wherein the message metadata is to be received without the email message;

determine, based on the message metadata, whether receiving the email message in the protected network is prohibited by at least one metadata policy of one or more metadata policies;

send a response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is determined to be prohibited by the at least one metadata policy;

send a request from the protected network for scan results data for the email message if receiving the email message in the protected network is determined not to be prohibited by the one or more metadata policies;

receive the scan results data;

determine, based on the scan results data, whether receiving the email message in the protected network is prohibited by at least one scan policy of one or more scan policies;

send a particular response from the protected network to block the email message from being forwarded to the protected network if receiving the email message in the protected network is prohibited by the at least one scan policy;

send a request from the protected network for the email message if receiving the email message in the protected network is not prohibited by the one or more scan policies;

receive the email message in response to the request for the email message; and

forward the email message to a mail server in the protected network, wherein the mail server delivers the email message to the intended recipient of the email message.

12. The apparatus of claim 11 , wherein the response is to be sent to an email threat sensor in a cloud network, wherein the email threat sensor is to receive the email message from a sending client in another network.

13. The apparatus of claim 11 , wherein the inbound policy module is further configured to:

scan the received email message for content prohibited by a local scan policy; and

responsive to finding at least some prohibited content when the email message is scanned, quarantine the email message.

14. The apparatus of claim 11 , wherein the inbound policy module is further configured to:

scan the received email message for content prohibited by a local scan policy; and

responsive to finding at least some prohibited content during the scanning, block the email message from being delivered to the intended recipient of the email message.

15. The apparatus of claim 11 , wherein the inbound policy module is further configured to:

scan the received email message for content prohibited by a local scan policy; and

responsive to not finding any prohibited content during the scan, forward the email message to the mail server in the protected network.

Assignments (19)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2022
From: MUSARUBRA US LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 061032/0678 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2013
From: LIEBMANN, NICHOLAS; NEAL, PETER; BISHOP, MICHAEL G.; CRAGIN, JUSTIN; DRISCOLL, MICHAEL
To: MCAFEE, INC.
Reel/Frame 030321/0082 →