IP Library Granted Patent US 11,552,896
Granted Patent B2
US 11,552,896 · App. 16/842,288 · Granted Jan 10, 2023

Filtering network traffic from automated scanners

Inventor: Zachary Stewart (Atlanta, GA)
Assignee: Salesforce, Inc.
H04L47/2441H04L47/28
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,552,896
App. No.
16/842,288
Granted
Jan 10, 2023
Kind
B2
Abstract

Methods, systems, and devices for filtering network traffic from automated scanner are described. A device (e.g., an application server) may receive an activity message associated with an interaction with an electronic communication message and identify, from the activity message, at least a source identifier of the activity message and one or more attributes associated with the electronic communication message. The device may then add the activity message to a mapping of source identifiers and attributes associated with previously received activity messages and classify the activity message as being associated with an automated scanner based on a comparison of the received activity message to the mapping over a previous time window. Upon classifying the activity message, the device may transmit a classification result to an external server.

Claims (53)

1. A method for filtering network traffic at an application server, comprising:

receiving an activity message associated with an interaction between a source network address and an electronic communication message;

identifying, from the activity message, at least a source identifier for the source network address and one or more attributes associated with the electronic communication message;

adding the activity message to a mapping of source identifiers and attributes associated with previously received activity messages received during a previous time window;

comparing the activity message to a plurality of interactions in accordance with the mapping, wherein the plurality of interactions is between the source network address and a plurality of electronic communication messages within the previous time window;

classifying the source network address as an automated scanner based at least in part on identifying, in accordance with the comparing, a pattern of interactions of the source network address with the plurality of electronic communication messages within the previous time window; and

transmitting, to an external server, a classification result based at least in part on classifying the source network address.

2. The method of claim 1 , further comprising:

identifying, from the activity message, a timestamp associated with the electronic communication message; and

determining that the timestamp corresponds to the previous time window, wherein adding the activity message comprises adding the activity message to the mapping associated with the previous time window.

3. The method of claim 2 , further comprising:

determining the previous time window based at least in part on the timestamp associated with the electronic communication message.

4. The method of claim 1 , further comprising:

determining one or more signals associated with the source identifier of the activity message based at least in part on the mapping of source identifiers and the attributes associated with the previously received activity messages, wherein classifying the source network address is based at least in part on the one or more signals.

5. The method of claim 4 , further comprising:

identifying a plurality of activity messages associated with the source identifier within the previous time window, wherein the plurality of activity messages include the plurality of interactions of the source identifier with the plurality of electronic communication messages; and

determining the one or more signals based at least in part on the plurality of activity messages associated with the source identifier within the previous time window.

6. The method of claim 5 , wherein the plurality of interactions of the source identifier comprise opening of the plurality of electronic communication messages within the previous time window.

7. The method of claim 5 , wherein the plurality of interactions of the source identifier comprise the plurality of interactions with a plurality of customers associated with the plurality of electronic communication messages.

8. The method of claim 5 , wherein the plurality of interactions of the source identifier comprise the plurality of interactions with a link included in one or more of the plurality of electronic communication messages.

9. The method of claim 5 , wherein the plurality of interactions of the source identifier comprise the plurality of interactions with a link included in one or more of the plurality of electronic communication messages, the one or more of the plurality of electronic communication messages being associated with one or more customers.

10. The method of claim 1 , further comprising:

receiving a classification request from the external server, wherein classifying the source network address is based at last in part on the classification request.

11. The method of claim 1 , wherein the source identifier of the activity message comprises an Internet Protocol (IP) address associated with the activity message.

12. The method of claim 1 , wherein the one or more attributes associated with the electronic communication message comprises at least one of an account identifier associated with the electronic communication message, an electronic communication message identifier, a timestamp associated with the electronic communication message, an identifier associated with a type of activity, or a combination thereof.

13. The method of claim 1 , wherein the automated scanner comprises an email security scanner.

14. An apparatus for filtering network traffic at an application server, comprising: a processor, memory coupled with the processor; and instructions stored in the memory and executable by the processor to cause the apparatus to:

receive an activity message associated with an interaction between a source network address and an electronic communication message;

identify, from the activity message, at least a source identifier for the source network address and one or more attributes associated with the electronic communication message;

add the activity message to a mapping of source identifiers and attributes associated with previously received activity messages received during a previous time window;

compare the activity message to a plurality of interactions in accordance with the mapping, wherein the plurality of interactions is between the source network address and a plurality of electronic communication messages within the previous time window;

classify the source network address as an automated scanner based at least in part on identifying, in accordance with the comparing, a pattern of interactions of the source network address with the plurality of electronic communication messages within the previous time window; and

transmit, to an external server, a classification result based at least in part on classifying the source network address.

15. The apparatus of claim 14 , wherein the instructions are further executable by the processor to cause the apparatus to:

identify, from the activity message, a timestamp associated with the electronic communication message; and

the instructions to determine that the timestamp corresponds to the previous time window, wherein adding the activity message are executable by the processor to cause the apparatus to add the activity message to the mapping associated with the previous time window.

16. The apparatus of claim 15 , wherein the instructions are further executable by the processor to cause the apparatus to:

determine the previous time window based at least in part on the timestamp associated with the electronic communication message.

17. The apparatus of claim 14 , wherein the instructions are further executable by the processor to cause the apparatus to:

determine one or more signals associated with the source identifier of the activity message based at least in part on the mapping of source identifiers and the attributes associated with the previously received activity messages, wherein classifying the source network address is based at least in part on the one or more signals.

18. The apparatus of claim 17 , wherein the instructions are further executable by the processor to cause the apparatus to:

identify a plurality of activity messages associated with the source identifier within the previous time window, wherein the plurality of activity messages include the plurality of interactions of the source identifier with the plurality of electronic communication messages; and

determine the one or more signals based at least in part on the plurality of activity messages associated with the source identifier within the previous time window.

19. A non-transitory computer-readable medium storing code for filtering network traffic at an application server, the code comprising instructions executable by a processor to:

receive an activity message associated with an interaction between a source network address and with an electronic communication message;

identify, from the activity message, at least a source identifier for the source network address and one or more attributes associated with the electronic communication message;

add the activity message to a mapping of source identifiers and attributes associated with previously received activity messages received during a previous time window;

compare the activity message to a plurality of interactions in accordance with the mapping, wherein the plurality of interactions is between the source network address and a plurality of electronic communication messages within the previous time window;

classify the source network address as an automated scanner based at least in part on identifying, in accordance with the comparing, a pattern of interactions of the source network address with the plurality of electronic communication messages within the previous time window; and

transmit, to an external server, a classification result based at least in part on classifying the source network address.

20. The non-transitory computer-readable medium of claim 19 , wherein the instructions are further executable to:

identify, from the activity message, a timestamp associated with the electronic communication message; and

determine that the timestamp corresponds to the previous time window.

Assignments (2)
CHANGE OF NAME Recorded Dec 18, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069717/0480 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2020
From: STEWART, ZACHARY
To: SALESFORCE.COM, INC.
Reel/Frame 052334/0189 →
Continuity (1)
Related Publication 20210314269A1 · Oct 7, 2021