IP Library Granted Patent US 8,407,792
Granted Patent B2
US 8,407,792 · App. 10/849,633 · Granted Mar 26, 2013

Systems and methods for computer security

Inventor: Paul Gassoway (Norwood, MA)
Assignee: CA, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,407,792
App. No.
10/849,633
Granted
Mar 26, 2013
Kind
B2
Abstract

A method for maintaining computer security comprises receiving an incoming email destined for an email server, determining whether the received incoming email is infected with malicious code and blocking the incoming email determined to be infected with malicious code from reaching the email server.

Claims (69)

1. A method for maintaining computer security comprising:

receiving, at a proxy server, an email directed from an email server to an email client associated with the email server;

scanning an email message included in the received email using intrusion detection signatures to determine if the email message would exploit a vulnerability associated with the email server;

determining whether an attachment included in the received email is infected with malicious code; by

parsing the received email;

converting the received email into an internal format; and

determining, at the proxy server, whether the converted received email includes malicious code using a virus signature file; and

based on a determination that the attachment is infected:

removing the attachment from the received email;

modifying the received email, the modification indicating that the attachment was removed; and

sending the modified email to the email client.

2. The method of claim 1 , further comprising reassembling the converted email back into its original format if it is determined that the received email does not include malicious code.

3. The method of claim 2 , wherein sending the modified email comprises sending the reassembled email to the email client.

4. The method of claim 1 , wherein the virus signature file contains information about known email viruses.

5. The method of claim 1 , wherein the virus signature file contains information about known viruses for email attachments.

6. The method of claim 1 , further comprising continuously updating the virus signature file.

7. The method of claim 1 , further comprising periodically downloading an updated virus signature file in order to make its copy current.

8. The method of claim 1 , wherein the received email is parsed based on a protocol of the email, wherein the proxy server supports the protocol.

9. The method of claim 2 , wherein the converted email is reassembled based on a protocol of the email, wherein the proxy server supports the protocol.

10. The method of claim 1 , further comprising sending a notification to the sender of the received email and the receiver of the received email, the notification indicating that the attachment is infected with malicious code.

11. A computer system for maintaining computer security comprising:

one or more computers configured to store computer code executable by the one or more computers, the computer code configured to:

receive, at a proxy server, an email directed from an email server to an email client associated with the email server;

scan an email message included in the received email using intrusion detection signatures to determine if the email message would exploit a vulnerability associated with the email server;

determine whether an attachment included in the received email is infected with malicious code; and

based on a determination that the attachment is infected:

remove the attachment from the received email;

modify the received email, the modification indicating that the attachment was removed; and

send the modified email to the email client;

wherein the computer code is further configured to determine whether an attachment included in the received email is infected with malicious code by:

parsing the received email;

converting the received email into an internal format; and

determining, at the proxy server, whether the converted received email includes malicious code using a virus signature file.

12. The computer system of claim 11 , wherein the computer code is further configured to reassemble the converted email back into its original format if it is determined that the received email does not include malicious code.

13. The computer system of claim 12 , wherein the computer code is configured to send the modified email to the client by sending the reassembled email to the client.

14. The computer system of claim 11 , wherein the virus signature file contains information about known email viruses.

15. The computer system of claim 11 , wherein the virus signature file contains information about known viruses for email attachments.

16. The computer system of claim 11 , wherein the computer code is further configured to continuously update the virus signature file.

17. The computer system of claim 11 , wherein the computer code is further configured to periodically download an updated virus signature file in order to make its copy current.

18. A computer system for maintaining computer security comprising:

one or more computers configured to store computer code executable by the one or more computers, the computer code configured to:

receive, at a proxy server, an email directed from an email server to an email client associated with the email server;

scan an email message included in the received email using intrusion detection signatures to determine if the email message would exploit a vulnerability associated with the email server;

determine whether an attachment included in the received email is infected with malicious code by:

parsing the received email;

converting the received email into an internal format; and

determining, at the proxy server, whether the converted received email includes malicious code using a virus signature file; and

based on a determination where the attachment is infected:

remove the attachment from the received email;

modify the received email, the modification indicating that the attachment was removed; and

send the modified email to the email client.

19. The computer system of claim 18 , wherein the computer code is further configured to reassemble the converted email.

20. A non-transitory computer storage medium including computer executable code for maintaining computer security, wherein the code is configured to:

receive, at a proxy server, an email directed from an email server to an email client associated with the email server;

scan an email message included in the received email using intrusion detection signatures to determine if the email message would exploit a vulnerability associated with the email server;

determine whether an attachment included in the received email is infected with malicious code by:

parsing the received email;

converting the received email into an internal format; and

determining, at the proxy server, whether the converted received email includes malicious code using a virus signature file; and

based on a determination that the attachment is infected:

remove the attachment from the received email;

modify the received email, the modification indicating that the attachment was removed; and

send the modified email to the email client.

21. The computer storage medium of claim 20 , wherein the code is further configured to reassemble the converted email back into its original format if it is determined that the received email does not include malicious code.

22. The computer storage medium of claim 21 , wherein the code is configured to send the modified email to the client by sending the reassembled email to the email client.

23. The computer storage medium of claim 20 , wherein the virus signature file contains information about known email viruses.

24. The computer storage medium of claim 20 , wherein the virus signature file contains information about known viruses for email attachments.

25. The computer storage medium of claim 20 , wherein the code is configured to continuously update the virus signature file.

26. The computer storage medium of claim 20 , wherein the code is configured to periodically download an updated virus signature file in order to make its copy current.

Assignments (2)
MERGER Recorded Jan 28, 2013
From: COMPUTER ASSOCIATES THINK, INC.
To: CA, INC.
Reel/Frame 029702/0160 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2005
From: GASSOWAY, PAUL
To: COMPUTER ASSOCIATES THINK, INC.
Reel/Frame 016304/0805 →
Continuity (1)
Related Publication 20050262566A1 · Nov 24, 2005