IP Library Granted Patent US 8,955,136
Granted Patent B2
US 8,955,136 · App. 13/400,548 · Granted Feb 10, 2015

Analyzing traffic patterns to detect infectious messages

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,955,136
App. No.
13/400,548
Granted
Feb 10, 2015
Kind
B2
Abstract

Managing electronic messages comprises receiving a message, forwarding the message, determining that the forwarded message is infectious after the message has been forwarded and preventing the infectious forwarded message from spreading.

Claims (35)

1. A method for classifying an electronic-mail message, the method comprising:

storing a plurality of previously received messages in memory, wherein each previously received message is individually classified as suspicious, and wherein each suspicious classification is based on a probability of infection that is between a probability threshold for legitimate classification and a probability threshold for infectious classification;

receiving a message sent over a communication network; and

executing instructions stored in memory, wherein execution of the instructions by a processor:

determines that the received message is individually classified as suspicious based on the probability threshold and is similar to one or more of the previously received messages classified as suspicious messages,

determines that a total number of similar suspicious messages has exceeded a predefined message threshold, wherein the total number of similar suspicious messages includes the received message and the one or more previously received and classified suspicious messages determined to be similar to the received message, and

classifies the received message as infectious when the predefined message threshold has been met by the total number of similar suspicious messages.

2. The method of claim 1 , further comprising executing instructions by the processor to perform a traffic analysis on the received message to identify a traffic spike in the total number of similar suspicious messages that is consistent with a pattern of a virus outbreak.

3. The method of claim 2 , wherein the traffic analysis is analyzed on a global network level.

4. The method of claim 2 , wherein the traffic analysis is analyzed on a subnet of a local network.

5. The method of claim 1 , further comprising executing instructions by the processor to quarantine the message based on the infectious classification.

6. The method of claim 1 , further comprising executing instructions by the processor to delete the message based on the infectious classification.

7. The method of claim 1 , wherein the message includes an executable attachment having a file name and one or more of the suspicious messages have the same attachment and file name.

8. The method of claim 1 , further comprising executing instructions by the processor to report the received message classified as infectious to another user on the communications network to prevent the spread of the infectious message.

9. A system for classifying an electronic-mail message, the system comprising:

memory for storing a plurality of previously received messages in memory, wherein each previously received message is individually classified as suspicious, and wherein each suspicious classification is based on a probability of infection that is between a probability threshold for legitimate classification and a probability threshold for infectious classification;

a mail server for receiving a message sent over a communication network; and

a network device coupled to the mail server, the network device including a processor for executing instructions stored in memory, wherein execution of the instructions by the processor:

determines that the received message is individually classified as suspicious based on the probability threshold and is similar to one or more of the previously received messages classified as suspicious messages,

determines that a total number of similar suspicious messages has exceeded a predefined message threshold, wherein the total number of similar suspicious messages includes the received message and the one or more previously received and classified suspicious messages determined to be similar to the received message, and

classifies the received message as infectious when the predefined message threshold has been met by the total number of similar suspicious messages.

10. The system of claim 9 , further comprising an infectious message detection mechanism stored in memory and executable by a processor to identify a virus associated with the infectious message.

11. A non-transitory computer-readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method for classifying an electronic-mail message, the method comprising:

storing a plurality of previously received messages, wherein each previously received message is individually classified as suspicious, and wherein each suspicious classification is based on a probability of infection that is between a probability threshold for legitimate classification and a probability threshold for infectious classification;

receiving a message sent over a communication network;

determining that the received message is individually classified as suspicious based on the probability threshold and is similar to one or more of the previously received messages classified as suspicious messages;

determining that a total number of similar suspicious messages has exceeded a predefined message threshold, wherein the total number of similar suspicious messages includes the received message and the one or more previously received and classified suspicious messages determined to be similar to the received message; and

classifying the received message as infectious when the predefined message threshold has been met by the total number of similar suspicious messages.

12. The system of claim 9 , wherein the network device further performs a traffic analysis on the received message to identify a traffic spike in the total number of similar suspicious messages that is consistent with a pattern of a virus outbreak.

13. The system of claim 12 , wherein the traffic analysis is analyzed on a global network level.

14. The system of claim 12 , wherein the traffic analysis is analyzed on a subnet of a local network.

15. The system of claim 9 , wherein the network device quarantines the message based on the infectious classification.

16. The system of claim 9 , wherein the network device deletes the message based on the infectious classification.

17. The system of claim 9 , wherein the message includes an executable attachment having a file name and one or more of the suspicious messages have the same attachment and file name.

18. The system of claim 9 , wherein the network device reports the received message classified as infectious to another user on the communications network to prevent the spread of the infectious message.

Assignments (24)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S NAME PREVIOUSLY RECORDED AT REEL: 027812 FRAME: 0197. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Jul 7, 2021
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 056785/0706 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CHANGE OF NAME Recorded Nov 15, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044771/0107 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Nov 4, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION
Reel/Frame 040564/0886 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Nov 4, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; AVENTAIL LLC; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION
Reel/Frame 040564/0897 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
CONVERSION AND NAME CHANGE Recorded Dec 12, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037278/0603 →
MERGER Recorded Dec 12, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037277/0712 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2012
From: RIHN, JENNIFER; OLIVER, JONATHAN J.
To: MAILFRONTIER, INC.
Reel/Frame 027811/0943 →
CHANGE OF NAME Recorded Mar 6, 2012
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 027812/0327 →
MERGER Recorded Mar 6, 2012
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC. C/O THOMA BRAVO, LLC
Reel/Frame 027812/0197 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2012
From: MAILFRONTIER, INC.
To: SONICWALL, INC.
Reel/Frame 027812/0087 →