IP Library Granted Patent US 9,325,724
Granted Patent B2
US 9,325,724 · App. 14/472,026 · Granted Apr 26, 2016

Time zero classification of messages

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,325,724
App. No.
14/472,026
Granted
Apr 26, 2016
Kind
B2
Abstract

Detecting infectious messages comprises performing an individual characteristic analysis of a message to determine whether the message is suspicious, determining whether a similar message has been noted previously in the event that the message is determined to be suspicious, classifying the message according to its individual characteristics and its similarity to the noted message in the event that a similar message has been noted previously.

Claims (36)

1. A method of classifying messages, the method comprising:

performing an individual characteristic analysis of a message, wherein the individual characteristic analysis includes comparing the individual characteristics of the message to individual characteristics of a previously received message, wherein the individual characteristic analysis yields a first probability of infection;

performing a traffic analysis of the message for identifying a spike in a number of previously received messages similar to the message, the previously received messages having been classified as suspicious, wherein the traffic analysis yields a second probability of infection;

determining an overall probability of infection based on the first probability and the second probability;

classifying the message as legitimate when the overall probability meets a threshold associated with legitimate messages, wherein the message is classified as suspicious or infectious when the overall probability fails to meet the threshold; and

processing the message in accordance with the classification, wherein the message is delivered when classified as legitimate or suspicious, and wherein the message is removed from a message queue when classified as infectious.

2. The method of claim 1 , further comprising updating the overall probability and subsequently classifying the suspicious message as legitimate when the updated overall probability meets the threshold.

3. The method of claim 1 , further comprising updating the overall probability and subsequently classifying the suspicious message as infectious when the updated overall probability meets another threshold associated with infectiousness.

4. The method of claim 1 , wherein the individual characteristic analysis comprises a set of one or more tests.

5. The method of claim 4 , wherein test results from the set of tests are weighted to determine the first probability.

6. The method of claim 4 , wherein the tests are applied in a predetermined order.

7. The method of claim 4 , wherein the set of tests for the received message is different than a set of tests selected for another received message.

8. The method of claim 1 , wherein the traffic analysis pertains to one of a global network, a local network, or a subnet of the local network.

9. The method of claim 1 , wherein the traffic analysis pertains to any combination of a global network, a local network, or a subnet of the local network.

10. A system of classifying messages, the system comprising:

a processor that executes:

a testing module stored in memory, wherein the testing module is executable to:

perform an individual characteristic analysis of a message, wherein the individual characteristic analysis includes comparing the individual characteristics of the message to individual characteristics of a previously received message, wherein the individual characteristic analysis yields a first probability of infection, and

perform a traffic analysis of the message for identifying a spike in a number of previously received messages similar to the message, the previously received messages having been classified as suspicious, wherein the traffic analysis yields a second probability of infection;

instructions stored in memory, wherein the instructions are executable to determine an overall probability of infection based on the first probability and the second probability;

a message classifier stored in memory, wherein the message classifier is executable to classify the message as legitimate when the overall probability meets a threshold associated with legitimate messages, wherein the message is classified as suspicious or infectious when the overall probability fails to meet the threshold; and

a message forwarding device that processes the message in accordance with the classification, wherein the message is delivered when classified as legitimate or suspicious, and wherein the message is removed from a message queue when classified as infectious.

11. The system of claim 10 , wherein the processor executes further instructions to update the overall probability and to subsequently classify the suspicious message as legitimate when the updated overall probability meets the threshold.

12. The system of claim 10 , wherein the processor executes further instructions to update the overall probability and to subsequently classify the suspicious message as infectious when the updated overall probability meets another threshold associated with infectiousness.

13. The system of claim 10 , wherein the individual characteristic analysis comprises a set of one or more tests.

14. The system of claim 13 , wherein test results from the set of tests are weighted to determine the first probability.

15. The system of claim 13 , wherein the tests are applied in a predetermined order.

16. The system of claim 13 , wherein the set of tests for the received message is different than a set of tests selected for another received message.

17. The system of claim 10 , wherein the traffic analysis pertains to one of a global network, a local network, or a subnet of the local network.

18. The system of claim 10 , wherein the traffic analysis pertains to any combination of a global network, a local network, or a subnet of the local network.

19. A non-transitory computer-readable storage medium, having embodied thereon a program executable by a processor to perform a method of classifying messages, the method comprising:

performing an individual characteristic analysis of a message, wherein the individual characteristic analysis includes comparing the individual characteristics of the message to individual characteristics of a previously received message, wherein the individual characteristic analysis yields a first probability of infection;

performing a traffic analysis of the message for identifying a spike in a number of previously received messages similar to the message, the previously received messages having been classified as suspicious, wherein the traffic analysis yields a second probability of infection;

determining an overall probability of infection based on the first probability and the second probability;

classifying the message as legitimate when the overall probability meets a threshold associated with legitimate messages, wherein the message is classified as suspicious when the overall probability fails to meet the threshold; and

processing the message in accordance with the classification, wherein the message is delivered when classified as legitimate or suspicious, and wherein the message is removed from a message queue when classified as infectious.

Assignments (22)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
THIS SUBMISSION IS TO CORRECT AN ERROR TO ASSIGNEE'S NAME IN THE COVER SHEET PREVIOUSLY RECORDED AT REEL/FRAME: 033673/0049. ASSIGNOR CONFIRMS THE MERGER Recorded Jul 6, 2021
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 056772/0965 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CHANGE OF NAME Recorded Nov 27, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044810/0013 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
MERGER Recorded Nov 5, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 036974/0501 →
CONVERSION AND NAME CHANGE Recorded Nov 5, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037056/0155 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2014
From: RIHN, JENNIFER; OLIVER, JONATHAN J.
To: MAILFRONTIER, INC.
Reel/Frame 033673/0041 →
CHANGE OF NAME Recorded Sep 4, 2014
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 033673/0056 →
MERGER Recorded Sep 4, 2014
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC. C/O THOMA BRAVO, LLC
Reel/Frame 033673/0049 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2014
From: MAILFRONTIER, INC.
To: SONICWALL, INC.
Reel/Frame 033673/0046 →