IP Library Granted Patent US 9,215,241
Granted Patent B2
US 9,215,241 · App. 14/472,234 · Granted Dec 15, 2015

Reputation-based threat protection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,215,241
App. No.
14/472,234
Granted
Dec 15, 2015
Kind
B2
Abstract

Information concerning a plurality of identified threats provided by a plurality of preselected sources is stored in memory. An e-mail message may be received over a communication network. The received e-mail message is separated into a plurality of components. The stored information is searched to identify a reputation score associated with each of the plurality of components. It is then determined whether the e-mail is a threat based on the identified reputation score of each of the plurality of components. The determination is sent to a designated recipient.

Claims (40)

1. A method for reputation-based threat protection, the method comprising:

maintaining one or more dictionaries for identifying sensitive data in memory, wherein the sensitive data is defined by policies of an identified organization;

maintaining information in one or more databases concerning a plurality of identified threats;

intercepting an e-mail message from a sender in the organization and addressed to a destination outside of the organization, wherein the e-mail message is intercepted prior to leaving a communication network of the organization;

executing instructions stored in memory, wherein execution of the instructions by a processor:

determines that the intercepted e-mail message includes sensitive data by searching for predefined patterns, wherein searching comprises reference to the one or more dictionaries stored in memory for identifying the sensitive data,

identifies the e-mail message is a threat based on one or more reputation scores associated with the e-mail message and the determination that the e-mail message includes sensitive data, wherein the e-mail message is associated with the one or more reputation scores using the maintained information, and

applies one or more enforcement actions based on the determination that the e-mail message includes sensitive data; and

notifying the sender that the e-mail message was identified to be a threat.

2. The method of claim 1 , wherein determining that the intercepted e-mail message includes sensitive data comprises looking at content within an attachment.

3. The method of claim 1 , wherein the predefined patterns pertain to at least one of social security numbers, bank routing numbers, and credit card numbers.

4. The method of claim 1 , further comprising providing a plurality of approval boxes that allow for viewing and approval of the e-mail message before sending out of the identified organization.

5. The method of claim 1 , further comprising matching the e-mail message to a policy based on the sensitive data.

6. The method of claim 5 , further comprising routing the matching e-mail message to an e-mail archive.

7. The method of claim 5 , further comprising directing the e-mail message to an encryption/decryption server.

8. The method of claim 1 , wherein the dictionaries are associated with regulatory policies, industry standards, corporate compliance policies, or intellectual property policies.

9. A system for reputation-based threat protection, the system comprising:

database memory that maintains one or more dictionaries for identifying sensitive data in memory, wherein the sensitive data is defined by policies of an identified organization;

one or more databases that maintain information concerning a plurality of identified threats; and

a server that:

intercepts an e-mail message from a sender in the organization and addressed to a destination outside of the organization, wherein the e-mail message is intercepted prior to leaving a communication network of the organization,

determines that the intercepted e-mail message includes sensitive data by searching for predefined patterns, wherein searching comprises reference to the one or more dictionaries stored in memory for identifying the sensitive data,

identifies the e-mail message is a threat based on one or more reputation scores associated with the e-mail message and the determination that the e-mail message includes sensitive data, wherein the e-mail message is associated with the one or more reputation scores using the maintained information,

applies one or more enforcement actions based on the determination that the e-mail message includes sensitive data, and

notifies the sender that the e-mail message was identified to be a threat.

10. The system of claim 9 , wherein the server determines that the intercepted e-mail message includes sensitive data by looking at content within an attachment.

11. The system of claim 9 , wherein the predefined patterns pertain to at least one of social security numbers, bank routing numbers, and credit card numbers.

12. The system of claim 9 , wherein the server further provides a plurality of approval boxes that allow for viewing and approval of the e-mail message before sending out of the identified organization.

13. The system of claim 9 , wherein the server further matches the e-mail message to a policy based on the sensitive data.

14. The system of claim 13 , wherein the server further routes the matching e-mail message to an e-mail archive.

15. The system of claim 13 , wherein the server further directs the e-mail message to an encryption/decryption server.

16. The system of claim 9 , wherein the dictionaries are associated with regulatory policies, industry standards, corporate compliance policies, or intellectual property policies.

17. A non-transitory computer-readable storage medium, having embodied thereon a program executable by a processor to perform a method for reputation-based threat protection, the method comprising:

maintaining one or more dictionaries for identifying sensitive data in memory, wherein the sensitive data is defined by policies of an identified organization;

maintaining information concerning a plurality of identified threats;

intercepting an e-mail message from a sender in the organization and addressed to a destination outside of the organization, wherein the e-mail message is intercepted prior to leaving a communication network of the organization;

determining that the intercepted e-mail message includes sensitive data by searching for predefined patterns, wherein searching comprises reference to the one or more dictionaries stored in memory for identifying the sensitive data;

identifying the e-mail message is a threat based on one or more reputation scores associated with the e-mail message and the determination that the e-mail message includes sensitive data, wherein the e-mail message is associated with the one or more reputation scores using the maintained information;

applying one or more enforcement actions based on the determination that the e-mail message includes sensitive data; and

notifying the sender that the e-mail message was identified to be a threat.

Assignments (24)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Jan 9, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045029/0497 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF REEL 037848 FRAME 0210 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040031/0725 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 037848 FRAME 0001 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0152 →
RELEASE OF REEL 037847 FRAME 0843 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0366 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037848/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037847/0843 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 037848/0210 →
CONVERSION AND NAME CHANGE Recorded Jul 10, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 036092/0012 →
MERGER Recorded Jul 10, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 036062/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2014
From: YANOVSKY, BORIS; EIKENBERRY, SCOTT
To: SONICWALL, INC.
Reel/Frame 033639/0313 →