Systems and Methods For Message Threat Management
14 Assignments
0 Petitions
Accused Products
Abstract
The present invention is directed to systems and methods for detecting unsolicited and threatening communications and communicating threat information related thereto. Threat information is received from one or more sources; such sources can include external security databases and threat information data from one or more application and/or network layer security systems. The received threat information is reduced into a canonical form. Features are extracted from the reduced threat information; these features in conjunction with configuration data such as goals are used to produce rules. In some embodiments, these rules are tested against one or more sets of test data and compared against the same or different goals; if one or more tests fail, the rules are refined until the tests succeed within an acceptable margin of error. The rules are then propagated to one or more application layer security systems.
-
Citations
73 Claims
-
1-38. -38. (canceled)
-
39. A method for operation upon one or more data processors to classify communications from messaging entities, comprising:
-
receiving a communication from a messaging entity;
using a plurality of message classification techniques to classify the communication;
combining the message classification outputs in order to generate a message profile score;
wherein the message profile score is used in deciding what action is to be taken with respect to the communication associated with the messaging entity. - View Dependent Claims (40, 41, 42, 43, 44, 45, 46, 47, 48, 49)
-
-
50. A system for operation upon one or more data processors to classify communication from messaging entities, comprising:
-
a plurality of message classification techniques;
wherein the plurality of message classification techniques are configured to classify a communication received from a messaging entity;
message profiling logic configured to combine the message classification outputs in order to generate a message profile score;
wherein the message profile score is used in deciding what action is to be taken with respect to the communication associated with the messaging entity. - View Dependent Claims (51, 52, 53, 54, 55, 56, 57, 58, 59)
-
-
60. A system for operation upon one or more data processors to classify communications from messaging entities, comprising:
-
means for receiving a communication that was sent over a network from a messaging entity;
means for using a plurality of message classification techniques to classify the communication;
wherein each message classification technique is associated with a confidence value which is used in generating a message classification output from the message classificaiton technique;
means for combining the message classification outputs in order to generate a message profile score;
wherein the message profile score is used in deciding what action is to be taken with respect to the communication associated with the messaging entity.
-
-
61. An article of manufacture comprising a digital signal for transmission using a network;
-
wherein the digital signal includes a message profile score that has been generated according to method comprising;
receiving a communication that was sent over a network from a messaging entity;
using a plurality of message classification techniques to classify the communication;
combining the message classification outputs in order to generate a message profile score;
wherein the message profile score is used in deciding what action is to be taken with respect to the communication associated with the messaging entity. - View Dependent Claims (62)
-
-
63. A method for operation upon one or more data processors for tuning message classification parameters for use by one or more message classification techniques, comprising:
-
receiving a plurality of input data that is or is representative of a plurality of communications;
receiving updates from a centralized system to tune the message classification parameters associated with the message classification techniques;
wherein a communication is received from a messaging entity;
wherein the tuned message classification parameters are used by the plurality of message classification techniques to classify the received communication;
wherein message classification outputs from the plurality of message classification techniques are combined in order to generate a message profile score;
wherein the message profile score is used in deciding what action is to be taken with respect to the communication associated with the messaging entity. - View Dependent Claims (64, 65, 66, 67, 68, 69, 70, 71, 72)
-
-
73. A system for operation upon one or more data processors for tuning message classification parameters for use by one or more message classification techniques, comprising:
-
input logic to receive a plurality of input data that is or is representative of a plurality of communications;
an update interface operable to receive updated classification information used to tune the message classification parameters associated with the message classification techniques;
wherein a communication is received from a messaging entity;
wherein the tuned message classification parameters are used by the plurality of message classification techniques to classify the communication;
wherein message classification outputs from the plurality of message classification techniques are combined in order to generate a message profile score;
wherein the message profile score is used in deciding what action is to be taken with respect to the communication associated with the messaging entity.
-
Specification