System and method for detecting sources of abnormal computer network messages
First Claim
1. A method for detecting sources of abnormal message traffic on a network, said method comprising the steps of:
- a) utilizing an abnormality detection engine to detect said abnormal message traffic; and
b) reporting on said abnormal message traffic.
5 Assignments
0 Petitions
Accused Products
Abstract
The present invention relates generally to a system and method for the monitoring of email and other message traffic on a network. The intent of the monitoring to determine if message traffic is abnormal, thus indicating unwanted messages such as spam. A number of methods may be utilized by the invention to recognize unwanted messages, including the calculation of fanout, the number of messages sent by a unique host, unique email address or domain. Also included is fanin, the number of messages received from unique hosts, unique domains or unique email addresses. Further components consider the number of error messages received from a host, variations in bandwidth from a host, and variations in message content from a host.
53 Citations
29 Claims
-
1. A method for detecting sources of abnormal message traffic on a network, said method comprising the steps of:
-
a) utilizing an abnormality detection engine to detect said abnormal message traffic; and
b) reporting on said abnormal message traffic. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14)
-
-
15. A system for detecting sources of abnormal traffic in a network, said system comprising an abnormality detection engine, said abnormality detection engine accepting messages to and from said network and providing a report as output, said abnormality detection engine comprising one or more abnormality detectors, selected from the set of:
- a fanout detector, a fanin detector, an error response detector, a bandwidth variation detector;
or a variation in message content detector. - View Dependent Claims (16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27)
- a fanout detector, a fanin detector, an error response detector, a bandwidth variation detector;
-
28. A computer readable medium, for detecting sources of abnormal message traffic on a network, said medium comprising instructions for:
-
a) utilizing an abnormality detection engine to detect said abnormal message traffic; and
b) reporting on said abnormal message traffic. - View Dependent Claims (29)
-
Specification