IP Library Granted Patent US 10,084,801
Granted Patent B2
US 10,084,801 · App. 15/370,873 · Granted Sep 25, 2018

Time zero classification of messages

Inventors: Jennifer Rihn (Mountain View, CA); Jonathan J. Oliver (San Carlos, CA)
Assignee: SonicWALL Inc.
H04L63/1416G06N7/005H04L63/0245H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,084,801
App. No.
15/370,873
Granted
Sep 25, 2018
Kind
B2
Abstract

Detecting infectious messages comprises performing an individual characteristic analysis of a message to determine whether the message is suspicious, determining whether a similar message has been noted previously in the event that the message is determined to be suspicious, classifying the message according to its individual characteristics and its similarity to the noted message in the event that a similar message has been noted previously.

Claims (60)

1. A method for classifying a message, the method comprising:

receiving a message at a computer network interface;

performing a first test on content associated with the received message;

assigning an infectiousness probability to the received message based on the first test;

comparing the assigned infectiousness probability to a plurality of thresholds;

classifying the received message as suspicious based on the assigned infectiousness probability being above a legitimate threshold and below an infectious threshold;

performing a second test on the content associated with the received message;

updating the infectiousness probability of the received message based on the second test;

comparing the updated infectiousness probability to the thresholds;

re-classifying the message as infectious based on the updated infectiousness probability meeting the infectious threshold; and

performing an action based on the reclassification of the message, wherein the action includes preventing the message from being delivered to a recipient of the message when the reclassification indicates infectiousness.

2. The method of claim 1 , wherein the second test performed on the content associated with the received message includes at least one of a signature matching test, a file mane test a character test, a bit pattern test, an N-gram test, and a probabilistic finite stat automata test.

3. The method of claim 1 , wherein updating the infectiousness probability comprises assigning a value of one when the second test identifies that at least a portion of the content associated with the received message exactly matches a signature associated with a known virus.

4. The method of claim 1 , wherein updating the infectiousness probability comprises assigning a value that corresponds to a degree of similarity in accordance with a statistical model that includes one or more characteristics that are associated with a virus.

5. The method of claim 4 , wherein the one or more characteristics include one or more of a signature, a receipt time, the identity of a recipient, a number of recipients, a sender, an attachment size, a number of attachments, a number of executable attachments, a file name, a file type, and conflicting information in an attachment name.

6. The method of claim 4 , further comprising:

receiving a plurality of additional messages that include at least one of the characteristics;

increasing a count for each of the additional messages that include the at least one characteristic;

identifying that the count has crossed a virus count threshold; and

preventing at least one of the additional messages from being delivered to a recipient based on the identification that the count has crossed the virus count threshold.

7. A non-transitory computer readable storage medium having embodied thereon a program executable by a processor to perform a method for classifying a message, the method comprising:

receiving a message over a computer network interface;

performing a first test on content associated with the received message;

assigning an infectiousness probability to the received message based on the first test;

comparing the assigned infectiousness probability to a plurality of thresholds;

classifying the received message as suspicious based on the assigned infectiousness probability being above a legitimate threshold and below an infectious threshold;

performing a second test on the content associated with the received message;

updating the infectiousness probability of the received message based on the second test;

comparing the updated infectiousness probability to the thresholds;

re-classifying the message as infectious based on the updated infectiousness probability meeting the infectious threshold; and

performing an action based on the reclassification of the message, wherein the action includes preventing the message from being delivered to a recipient of the message when the reclassification indicates infectiousness.

8. The non-transitory computer readable storage medium of claim 7 , wherein the second test performed on the content associated with the received message includes at least one of a signature matching test, a file mane test a character test, a bit pattern test, an N-gram test, and a probabilistic finite stat automata test.

9. The non-transitory computer readable storage medium of claim 7 , wherein updating the infectiousness probability comprises assigning a value of one when the second test identifies that at least a portion of the content associated with the received message exactly matches a signature associated with a known virus.

10. The non-transitory computer readable storage medium of claim 7 , wherein updating the infectiousness probability comprises assigning a value that corresponds to a degree of similarity in accordance with a statistical model that includes one or more characteristics that are associated with a virus.

11. The non-transitory computer readable storage medium of claim 10 , wherein the one or more characteristics include one or more of a signature, a receipt time, the identity of a recipient, a number of recipients, a sender, an attachment size, a number of attachments, a number of executable attachments, a file name, a file type, and conflicting information in an attachment name.

12. The non-transitory computer readable storage medium of claim 10 , wherein the program further comprises instructions executable to:

receive a plurality of additional messages that include at least one of the characteristics;

increase a count for each of the additional messages that include the at least one characteristic;

identify that the count has crossed a virus count threshold; and

prevent at least one of the additional messages from being delivered to a recipient based on the identification that the count has crossed the virus count threshold.

13. An apparatus for classifying a message, the apparatus comprising:

a network interface that receives a message over a computer network interface; and

a processor that executes instructions out of memory to:

perform a first test on content associated with the received message;

assign an infectiousness probability to the received message based on the first test,

compare the assigned infectiousness probability to a plurality of thresholds,

classify the received message based on the assigned infectiousness probability being above a legitimate threshold and below an infectious threshold,

perform a second test on the content associated with the received message,

update the infectiousness probability of the received message based on the second test,

compare the updated infectiousness probability to the thresholds,

re-classify the message as infectious based on the updated infectiousness probability meeting the infectious threshold, and

perform an action based on the reclassification of the message, wherein the action includes preventing the message from being delivered to a recipient of the message when the reclassification indicates infectiousness.

14. The apparatus of claim 13 , wherein the second test performed on the content associated with the received message includes at least one of a signature matching test, a file mane test a character test, a bit pattern test, an N-gram test, and a probabilistic finite stat automata test.

15. The apparatus of claim 13 , wherein the processor updates the infectiousness probability by assigning a value of one when the second test identifies that at least a portion of the content associated with the received message exactly matches a signature associated with a known virus.

16. The apparatus of claim 13 , wherein the processor updates the infectiousness probability by assigning a value that corresponds to a degree of similarity in accordance with a statistical model that includes one or more characteristics that are associated with a virus.

17. The apparatus of claim 13 , wherein the processor executes further instructions to:

receive a plurality of additional messages that include at least one of the characteristics;

increase a count for each of the additional messages that include the at least one characteristic;

identify that the count has crossed a virus count threshold; and

prevent at least one of the additional messages from being delivered to a recipient based on the identification that the count has crossed the virus count threshold.

Assignments (12)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
MERGER Recorded Nov 27, 2017
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 044228/0562 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 044754/0711 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2017
From: RIHN, JENNIFER; OLIVER, JONATHAN J
To: MAILFRONTIER, INC.
Reel/Frame 044228/0407 →
CHANGE OF NAME Recorded Nov 27, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044837/0514 →
CHANGE OF NAME Recorded Nov 27, 2017
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 044808/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2017
From: MAILFRONTIER, INC.
To: SONICWALL, INC.
Reel/Frame 044228/0425 →
MERGER Recorded Nov 27, 2017
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 044228/0465 →
CHANGE OF NAME Recorded Nov 27, 2017
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 044228/0525 →
Continuity (6)
Continuation 15133824 · Apr 20, 2016
Continuation 14472026 · Aug 28, 2014
Continuation 11927438 · Oct 29, 2007
Continuation 11156372 · Jun 16, 2005
Provisional Application 60587839 · Jul 13, 2004
Related Publication 20170155670A1 · Jun 1, 2017