IP Library Granted Patent US 10,243,989
Granted Patent B1
US 10,243,989 · App. 15/661,638 · Granted Mar 26, 2019

Systems and methods for inspecting emails for malicious content

Inventors: Zhichao Ding (Nanjing, CN); Jun Qu (Nanjing, CN); Guangxiang Yang (Nanjing, CN)
Assignee: Trend Micro Incorporated
H04L63/1441H04L51/12H04L51/22H04L51/24H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,243,989
App. No.
15/661,638
Granted
Mar 26, 2019
Kind
B1
Abstract

An email inspection system receives emails that are addressed to recipients of a private computer network. The emails are inspected for malicious content, and security information of emails that pass inspection is recorded. When an email is detected to have malicious content, the recorded security information of emails is checked to identify compromised emails, which are emails that previously passed inspection but include the same malicious content. A notification email is sent to recipients of compromised emails. The notification email includes Simple Mail Transfer Protocol headers that facilitate identification of the recipients, blocking of incoming emails with the same malicious content, and identification of public Mail Transfer Agents that send malicious emails, i.e., emails with malicious content.

Claims (43)

1. A computer-implemented method comprising:

receiving a first email;

inspecting the first email for malicious content;

in response to not detecting malicious content in the first email, recording security information of the first email, the security information comprising an indication that the first email has passed the inspection for malicious content, an address of a recipient of the first email, and an identifier of a content of the first email;

after the first email has passed the inspection for malicious content, forwarding the first email to the recipient of the first email;

receiving a second email after receiving the first email;

inspecting the second email for malicious content;

detecting that the second email has malicious content;

from the recorded security information of the first email, identifying the first email as having previously passed inspection for malicious content but has a same malicious content as the second email; and

after the first email has been forwarded to the recipient and in response to detecting that the first email has the same malicious content as the second email, sending out over a computer network a notification email to the recipient that the first email is a malicious email.

2. The computer-implemented method of claim 1 , wherein the first email has been forwarded through a plurality of public Mail Transfer Agents (MTAs), and wherein sending the notification email to the recipient comprises inserting a first Simple Mail Transfer Protocol (SMTP) header in the notification email, the first SMTP header identifying a first public MTA that first received the first email on the Internet.

3. The computer-implemented method of claim 2 , wherein sending the notification email to the recipient comprises inserting a second SMTP header in the notification email, the second SMTP header identifying a last public MTA that last received the first email on the Internet.

4. The computer-implemented method of claim 1 , wherein sending the notification email to the recipient comprises inserting a third Simple Mail Transfer Protocol (SMTP) header in the notification email, the third SMTP header identifying a malicious content in the first email.

5. The computer-implemented method of claim 4 , wherein the malicious content in the first email comprises a malicious file attachment and the third SMTP header indicates a hash of the malicious file attachment.

6. The computer-implemented method of claim 4 , wherein the malicious content in the first email comprises a malicious Uniform Resource Locator (URL) and the third SMTP header indicates the malicious URL.

7. The computer-implemented method of claim 1 , wherein the first email and the second email are received for inspection for malicious content over the Internet, and the first email is forwarded to the recipient in a private computer network.

8. The computer-implemented method of claim 1 , wherein the first email has been forwarded through a plurality of public Mail Transfer Agents (MTAs), and wherein recording the security information of the first email comprises:

recording in a database an Internet Protocol (IP) IP address of a first public MTA that first received the first email on the Internet; and

recording in the database an IP address of a last public MTA that last received the first email on the Internet.

9. The computer-implemented method of claim 8 , wherein the notification email includes a Simple Mail Transfer Protocol (SMTP) header that indicates the IP address of the first public MTA and another SMTP header that indicates the IP address of the last public MTA.

10. The computer-implemented method of claim 9 , further comprising:

after sending the notification email to the recipient, blocking the IP address of the first public MTA.

11. A system for inspecting emails for malicious content, the system comprising:

a first computer comprising a processor and a memory, the memory of the first computer including instructions that when executed by the processor of the first computer cause the first computer to perform the steps of:

receiving a first email;

inspecting the first email for malicious content;

in response to not detecting malicious content in the first email, recording security information of the first email, the security information comprising an indication that the first email has passed the inspection for malicious content, an address of a recipient of the first email, and an identifier of a content of the first email;

after the first email has passed the inspection for malicious content, forwarding the first email to the recipient of the first email;

receiving a second email after receiving the first email;

inspecting the second email for malicious content;

detecting that the second email has malicious content;

from the recorded security information of the first email, identifying the first email as having previously passed inspection for malicious content but has a same malicious content as the second email; and

after the first email has been forwarded to the recipient and in response to detecting that the first email has the same malicious constant as the second email, sending out over a computer network a notification email to the recipient that the first email is a malicious email.

12. The system of claim 11 , further comprising:

a second computer comprising a processor and a memory, the memory of the second computer including instructions that when executed by the processor of the second computer cause the second computer to perform the steps of:

receiving the notification email in a private computer network; and

forwarding the notification email to a user computer of the recipient in the private computer network.

13. The system of claim 12 , wherein the first email has been forwarded through a plurality of public Mail Transfer Agents (MTAs), and wherein the instructions in the memory of the second computer, when executed by the processor of the second computer, cause the second computer to perform the steps of:

identifying, from a first Simple Mail Transfer Protocol (SMTP) header of the notification email, an Internet Protocol (IP) address of a first public MTA that first received the first email on the Internet; and

blocking emails forwarded from the first public MTA.

14. The system of claim 12 , wherein the first email has been forwarded through a plurality of public Mail Transfer Agents (MTAs), and wherein the instructions in the memory of the second computer, when executed by the processor of the second computer, cause the second computer to perform the steps of:

identifying, from a second Simple Mail Transfer Protocol (SMTP) header of the notification email, an Internet Protocol (IP) address of a last public MTA that last received the first email on the Internet; and

blocking emails forwarded from the last public MTA.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2017
From: DING, ZHICHAO; QU, JUN; YANG, GUANGXIANG
To: TREND MICRO INCORPORATED
Reel/Frame 043219/0313 →
Cited By (9)
US 12,231,453 US 12,255,915 US 12,355,791 US 12,470,599 US 12,500,927 US 12,531,888 US 12,556,550 US 12,579,260 US 12,639,465