Tertiary classification of communications
First Claim
1. A system, comprising:
- one or more processors configured to;
obtain information associated with a plurality of electronic communications associated with an entity;
generate, in a whitelist, an entry including information associated with a given email address, wherein the entry including the information associated with the given email address is generated based at least in part on a determination, from the obtained information associated with the plurality of electronic communications associated with the entity, that at least a threshold number of electronic communications have been exchanged between the entity and the given email address, and that the at least threshold number of emails were exchanged during a period of time that exceeds a threshold period of time;
subsequent to generating the whitelist entry, receive an electronic communication to be classified; and
perform a classification of the received electronic communication based at least in part on a determination of whether the received electronic communication corresponds to an entry in the whitelist, wherein performing the classification includes assigning to the received electronic communication a single one of three different classifications according to a tertiary classification scheme, wherein the three classifications include good, bad, and undetermined;
based at least in part on the bad or undetermined classification, change the appearance of the received electronic communication by at least one of;
redacting a first portion of the received electronic communication, textually or visually clarifying the received electronic communication, highlighting a second portion of the received electronic communication, and marking the message as highly suspicious;
wherein the one or more processors are further configured to perform an action based at least in part on the bad or undetermined classification, wherein the action comprises at least one of;
delivering the received electronic communication in a folder selected based at least in part on the classification,delivering the received electronic communication to an account selected based at least in part on the classification,holding the received electronic communication in a repository,forwarding the received electronic communication to a remote classifier, andforwarding the received electronic communication for human review, wherein a reputation score is maintained for a human reviewer, and wherein the reputation score indicates a review accuracy of the human reviewer; and
a memory coupled to the one or more processors and configured to provide the one or more processors with instructions.
1 Assignment
0 Petitions
Accused Products
Abstract
Information associated with a plurality of electronic communications associated with an entity is obtained. An entry including information associated with a given email address is generated in a whitelist. The entry including the information associated with the given email address is generated based at least in part on a determination, from the obtained information associated with the plurality of electronic communication associated with the entity, that at least a threshold number of electronic communications have been exchanged between the entity and the given email address, and that the at least threshold number of emails were exchanged during a period of time that exceeds a threshold period of time. Subsequent to generating the whitelist entry, an electronic communication to be classified is received. A classification of the received electronic communication is performed based at least in part on a determination of whether the received electronic communication corresponds to an entry in the whitelist.
-
Citations
17 Claims
-
1. A system, comprising:
-
one or more processors configured to;
obtain information associated with a plurality of electronic communications associated with an entity;generate, in a whitelist, an entry including information associated with a given email address, wherein the entry including the information associated with the given email address is generated based at least in part on a determination, from the obtained information associated with the plurality of electronic communications associated with the entity, that at least a threshold number of electronic communications have been exchanged between the entity and the given email address, and that the at least threshold number of emails were exchanged during a period of time that exceeds a threshold period of time; subsequent to generating the whitelist entry, receive an electronic communication to be classified; and perform a classification of the received electronic communication based at least in part on a determination of whether the received electronic communication corresponds to an entry in the whitelist, wherein performing the classification includes assigning to the received electronic communication a single one of three different classifications according to a tertiary classification scheme, wherein the three classifications include good, bad, and undetermined; based at least in part on the bad or undetermined classification, change the appearance of the received electronic communication by at least one of; redacting a first portion of the received electronic communication, textually or visually clarifying the received electronic communication, highlighting a second portion of the received electronic communication, and marking the message as highly suspicious; wherein the one or more processors are further configured to perform an action based at least in part on the bad or undetermined classification, wherein the action comprises at least one of; delivering the received electronic communication in a folder selected based at least in part on the classification, delivering the received electronic communication to an account selected based at least in part on the classification, holding the received electronic communication in a repository, forwarding the received electronic communication to a remote classifier, and forwarding the received electronic communication for human review, wherein a reputation score is maintained for a human reviewer, and wherein the reputation score indicates a review accuracy of the human reviewer; and a memory coupled to the one or more processors and configured to provide the one or more processors with instructions. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A method, comprising:
-
obtaining information associated with a plurality of electronic communications associated with an entity; generating, in a whitelist, an entry including information associated with a given email address, wherein the entry including the information associated with the given email address is generated based at least in part on a determination, from the obtained information associated with the plurality of electronic communications associated with the entity, that at least a threshold number of electronic communications have been exchanged between the entity and the given email address, and that the at least threshold number of emails were exchanged during a period of time that exceeds a threshold period of time; subsequent to generating the whitelist entry, receiving an electronic communication to be classified; and performing, using one or more processors, a classification of the received electronic communication based at least in part on a determination of whether the received electronic communication corresponds to an entry in the whitelist, wherein performing the classification includes assigning to the received electronic communication a single one of three different classifications according to a tertiary classification scheme, wherein the three classifications include good, bad, and undetermined; based at least in part on the bad or undetermined classification, changing the appearance of the received electronic communication by at least one of;
redacting a first portion of the received electronic communication, textually or visually clarifying the received electronic communication, highlighting a second portion of the received electronic communication, and marking the message as highly suspicious;wherein the one or more processors are further configured to perform an action based at least in part on the bad or undetermined classification, wherein the action comprises at least one of; delivering the received electronic communication in a folder selected based at least in part on the classification, delivering the received electronic communication to an account selected based at least in part on the classification, holding the received electronic communication in a repository, forwarding the received electronic communication to a remote classifier, and forwarding the received electronic communication for human review, wherein a reputation score is maintained for a human reviewer, and wherein the reputation score indicates a review accuracy of the human reviewer. - View Dependent Claims (10, 11, 12, 13, 14, 15, 16)
-
-
17. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:
-
obtaining information associated with a plurality of electronic communications associated with an entity; generating, in a whitelist, an entry including information associated with a given email address, wherein the entry including the information associated with the given email address is generated based at least in part on a determination, from the obtained information associated with the plurality of electronic communications associated with the entity, that at least a threshold number of electronic communications have been exchanged between the entity and the given email address, and that the at least threshold number of emails were exchanged during a period of time that exceeds a threshold period of time; subsequent to generating the whitelist entry, receiving an electronic communication to be classified; and performing, using one or more processors, a classification of the received electronic communication based at least in part on a determination of whether the received electronic communication corresponds to an entry in the whitelist, wherein performing the classification includes assigning to the received electronic communication a single one of three different classifications according to a tertiary classification scheme, wherein the three classifications include good, bad, and undetermined; based at least in part on the bad or undetermined classification, changing the appearance of the received electronic communication by at least one of; redacting a first portion of the received electronic communication, textually or visually clarifying the received electronic communication, highlighting a second portion of the received electronic communication, and marking the message as highly suspicious; wherein the one or more processors are further configured to perform an action based at least in part on the bad or undetermined classification, wherein the action comprises at least one of; delivering the received electronic communication in a folder selected based at least in part on the classification, delivering the received electronic communication to an account selected based at least in part on the classification, holding the received electronic communication in a repository, forwarding the received electronic communication to a remote classifier, and forwarding the received electronic communication for human review, wherein a reputation score is maintained for a human reviewer, and wherein the reputation score indicates a review accuracy of the human reviewer.
-
Specification