LINKED RESOURCE REFERENCE REPLACEMENT IN A MESSAGE
A message is received and one or more linked resource references included in the message are identified. For a specific linked resource reference included in the one or more linked resource references, a threat score is determined based at least in part on one or more attributes of the specific linked resource reference. A determination is made that the threat score satisfies a replacement criterion. The specific linked resource reference is replaced for the message with a replacement linked resource reference to an interstitial resource. One or more user interactions with the replacement linked resource reference are tracked. A security action is performed based on the tracked one or more user interactions.
1 . A method, comprising:
receiving a message;
identifying one or more linked resource references included in the message;
for a specific linked resource reference included in the one or more linked resource references, determining a threat score based at least in part on one or more attributes of the specific linked resource reference;
determining that the threat score satisfies a replacement criterion;
replacing for the message the specific linked resource reference with a replacement linked resource reference to an interstitial resource;
tracking one or more user interactions with the replacement linked resource reference; and
performing a security action based on the tracked one or more user interactions.
2 . The method of claim 1 , wherein the one or more attributes of the specific linked resource reference are based on one or more of the following associated with the specific linked resource reference: a domain name, a keyword, a use of a reference shortener, a use of authentication, an authentication type, or a past knowledge of the specific linked resource reference.
3 . The method of claim 1 , wherein the one or more attributes of the specific linked resource reference are based on one or more of the following associated with the message: a message subject, a message header, an Internet Protocol (IP) address, message text, or an attachment.
4 . The method of claim 1 , wherein the threat score includes at least a risk score component and an abnormality score component.
5 . The method of claim 1 , wherein determining that the threat score satisfies the replacement criterion includes comparing the one or more attributes of the specific linked resource reference against one or more reference criteria.
6 . The method of claim 1 , wherein comparing the one or more attributes of the specific linked resource reference against the one or more reference criteria includes applying one or more logical operations to a set of the one or more attributes.
7 . The method of claim 1 , wherein tracking the one or more user interactions with the replacement linked resource reference includes tracking one or more of the following: an identity of a visiting user, a time of a visit to the interstitial resource by the visiting user, an access by the visiting user to the specific linked resource reference from the interstitial resource, or a time of an access to the specific linked resource reference from the interstitial resource by the visiting user.
8 . The method of claim 1 , further comprising:
receiving a request to the interstitial resource; and
in response to the request to the interstitial resource, providing information on the linked resource reference.
9 . The method of claim 8 , wherein the provided information includes a description of a security threat associated with the linked resource reference.
10 . The method of claim 8 , wherein the provided information includes a description of one or more security threat characteristics associated with the linked resource reference.
11 . The method of claim 8 , wherein the provided information includes a reference to the specific linked resource reference accessible from the interstitial resource.
12 . A system, comprising:
one or more processors; and
a memory coupled to the one or more processors, wherein the memory is configured to provide the one or more processors with instructions which when executed cause the one or more processors to:
receive a message;
identify one or more linked resource references included in the message;
for a specific linked resource reference included in the one or more linked resource references, determine a threat score based at least in part on one or more attributes of the specific linked resource reference;
determine that the threat score satisfies a replacement criterion;
replace for the message the specific linked resource reference with a replacement linked resource reference to an interstitial resource;
track one or more user interactions with the replacement linked resource reference; and
perform a security action based on the tracked one or more user interactions.
13 . The system of claim 12 , wherein the one or more attributes of the specific linked resource reference are based on one or more of the following associated with the specific linked resource reference: a domain name, a keyword, a use of a reference shortener, a use of authentication, an authentication type, or a past knowledge of the specific linked resource reference.
14 . The system of claim 12 , wherein the one or more attributes of the specific linked resource reference are based on one or more of the following associated with the message: a message subject, a message header, an Internet Protocol (IP) address, message text, or an attachment.
15 . The system of claim 12 , wherein the threat score includes at least a risk score component and an abnormality score component.
16 . The system of claim 12 , wherein determining that the threat score satisfies the replacement criterion includes comparing the one or more attributes of the specific linked resource reference against one or more reference criteria.
17 . The system of claim 12 , wherein comparing the one or more attributes of the specific linked resource reference against the one or more reference criteria includes applying one or more logical operations to a set of the one or more attributes.
18 . The system of claim 12 , wherein to track the one or more user interactions with the replacement linked resource reference includes one or more of the following: to track an identity of a visiting user, a time of a visit to the interstitial resource by the visiting user, an access by the visiting user to the specific linked resource reference from the interstitial resource, or a time of an access to the specific linked resource reference from the interstitial resource by the visiting user.
19 . The system of claim 12 , wherein the memory is further configured to provide the one or more processors with instructions which when executed cause the one or more processors to:
receive a request to the interstitial resource; and
in response to the request to the interstitial resource, provide information on the linked resource reference including a reference to the specific linked resource reference accessible from the interstitial resource.
20 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:
receiving a message;
identifying one or more linked resource references included in the message;
for a specific linked resource reference included in the one or more linked resource references, determining a threat score based at least in part on one or more attributes of the specific linked resource reference;
determining that the threat score satisfies a replacement criterion;
replacing for the message the specific linked resource reference with a replacement linked resource reference to an interstitial resource;
tracking one or more user interactions with the replacement linked resource reference; and
performing a security action based on the tracked one or more user interactions.