IP Library Patent Application 15404788
Patent Application
App. No. 15/404,788

CLASSIFYING AN EMAIL AS MALICIOUS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/404,788
Abstract

Provided are systems, methods, and computer-program products for classifying an email as malicious. In some implementations, a malicious detection engine may configure a decoy email address. The decoy email address may include a username that is associated with the malicious email detection engine. Email directed to the decoy email address may be received by the malicious email detection engine. The malicious email detection engine may further make the decoy email address publicly available, and may receive a suspect email addressed to the decoy email address. The suspect email may include a header and content. The malicious email detection engine may analyze the header using a header analysis engine, and the content using a high-interaction network. The malicious email detection engine may determine a status for the suspect email, determination using the header and content analysis, wherein the status indicates whether the suspect email was malicious.

Claims (59)

1 . A method, comprising:

configuring, using a malicious email detection engine, a decoy email address, wherein the decoy email address includes a username that is associated with the malicious email detection engine, and wherein email directed to the decoy email address is received by the malicious email detection engine;

making the decoy email address publicly available;

receiving a suspect email addressed to the decoy email address, wherein the suspect email includes a header and content;

analyzing the header using a header analysis engine;

analyzing the content using a high-interaction network; and

determining a status for the suspect email, wherein the status indicates whether the suspect email was malicious, wherein determining includes using the header and content analysis, and wherein the status is determined using a results engine.

2 . The method of claim 1 , further comprising:

generating the username of the decoy email address using common patterns for email usernames.

3 . The method of claim 1 , further comprising:

generating the username of the decoy email address using a received email.

4 . The method of claim 1 , wherein analyzing the header includes examining one or more fields in the header, wherein examining a field include determining whether a value in the field corresponds with a suspect value.

5 . The method of claim 1 , wherein analyzing the header includes generating and sending a response email to a sender email address.

6 . The method of claim 1 , wherein the contents included in the suspect email include one or more of a file or an Internet link, and wherein analyzing the content includes interacting with the content using the high-interaction network.

7 . The method of claim 1 , further comprising:

generating indicators for the suspect email, wherein the indicators identify the suspect email, and wherein the indicators are generated using the results engine; and

using the indicators to identify malicious email sent to a non-decoy email address.

8 . The method of claim 1 , further comprising:

determining that a computer system has been compromised, wherein determining that the computer system has been compromised includes using the header and content analysis, and wherein the computer system is determined to be compromised using the results engine.

9 . A network device, comprising:

one or more processors; and

a non-transitory computer-readable medium including instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including:

configuring, using a malicious email detection engine, a decoy email address, wherein the decoy email address includes a username that is associated with the malicious email detection engine, and wherein email directed to the decoy email address is received by the malicious email detection engine;

making the decoy email address publicly available;

receiving a suspect email addressed to the decoy email address, wherein the suspect email includes a header and content;

analyzing the header using a header analysis engine;

analyzing the content using a high-interaction network; and

determining a status for the suspect email, wherein the status indicates whether the suspect email was malicious, wherein determining includes using the header and content analysis, and wherein the status is determined using an results engine.

10 . The network device of claim 9 , wherein the non-transitory computer-readable medium further includes instructions that cause the one or more processors to perform operations including:

generating the username of the decoy email address using common patterns for email usernames.

11 . The network device of claim 9 , wherein the non-transitory computer-readable medium further includes instructions that cause the one or more processors to perform operations including:

generating the username of the decoy email address using a received email.

12 . The network device of claim 9 , wherein analyzing the header includes examining one or more fields in the header, wherein examining a field include determining whether a value in the field corresponds with a suspect value.

13 . The network device of claim 9 , wherein the instructions for analyzing the header include instructions for generating and sending a response email to a sender email address.

14 . The network device of claim 9 , wherein the contents included in the suspect email include one or more of a file or an Internet link, and wherein the instructions for analyzing the content include instructions for interacting with the content using the high-interaction network.

15 . The network device of claim 9 , wherein the non-transitory computer-readable medium further includes instructions that cause the one or more processors to perform operations including:

generating indicators for the suspect email, wherein the indicators identify the suspect email, and wherein the indicators are generated using the results engine; and

using the indicators to identify malicious email sent to a non-decoy email address.

16 . The network device of claim 9 , wherein the non-transitory computer-readable medium further includes instructions that cause the one or more processors to perform operations including:

determining that a computer system has been compromised, wherein determining that the computer system has been compromised includes using the header and content analysis, and wherein the computer system is determined to be compromised using the results engine.

17 . A computer-program product tangibly embodied in a non-transitory machine-readable storage medium, including instructions that, when executed by one or more processors, cause the one or more processors to:

configure, using a malicious email detection engine, a decoy email address, wherein the decoy email address includes a username that is associated with the malicious email detection engine, and wherein email directed to the decoy email address is received by the malicious email detection engine;

make the decoy email address publicly available;

receive a suspect email addressed to the decoy email address, wherein the suspect email includes a header and content;

analyze the header using a header analysis engine;

analyze the content using a high-interaction network; and

determine a status for the suspect email, wherein the status indicates whether the suspect email was malicious, wherein determining includes using the header and content analysis, and wherein the status is determined using an results engine.

18 . The computer-program product of claim 17 , further comprising instructions that cause the one or more processors to:

generate the username of the decoy email address using common patterns for usernames.

19 . The computer-program product of claim 17 , further comprising instructions that cause the one or more processors to:

generate the username of the decoy email address using a received email.

20 . The computer-program product of claim 17 , wherein the instructions for analyzing the header include instructions for examining one or more fields in the header, wherein examining a field include determining whether a value in the field corresponds with a suspect value.

21 . The computer-program product of claim 17 , wherein the instructions for analyzing the header include instructions for generating and sending a response email to a sender email address.

22 . The computer-program product of claim 17 , wherein the contents included in the suspect email include one or more of a file or an Internet link, and wherein the instructions for analyzing the content include instructions for interacting with the content using the high-interaction network.

23 . The computer-program product of claim 17 , further comprising instructions that cause the one or more processors to:

generate indicators for the suspect email, wherein the indicators identify the suspect email, and wherein the indicators are generated using the results engine; and

use the indicators to identify malicious email sent to a non-decoy email address.

24 . The computer-program product of claim 17 , further comprising instructions that cause the one or more processors to:

determine that a computer system has been compromised, wherein determining that the computer system has been compromised includes using the header and content analysis, and wherein the computer system is determined to be compromised using the results engine.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2017
From: SINGH, ABHISHEK; GUKAL, SREENIVAS
To: ACALVIO TECHNOLOGIES, INC.
Reel/Frame 041241/0929 →