MALWARE DETECTION SYSTEM BASED ON STORED DATA
First Claim
1. A malware detection system based on stored data, comprising:
- a threat protection and detection system executable on a client or server computer or set of client or server computers, wherein the threat protection and detection system comprisesa messaging system database comprisingan archive of electronic messages, wherein said archive of electronic messages comprises electronic messages previously sent, received or drafted,a contacts list, andsummary data derived from said archive of electronic messages and said contacts list, wherein said summary data consolidates information from said message archive of electronic messages and said contacts list and,a message filter coupled to said messaging system database, and configured toreceive an electronic message comprising one or more message parts, said one or more message parts comprisinga sender information,one or more receivers information,a message contents,a subject line,one or more attachments,one or more links to websites,a message thread;
determine whether said electronic message represents a potential threat, based on an analysis ofsaid one or more message parts, andsaid messaging system database;
if said electronic message represents a potential threat, perform one or more ofblock access to said electronic message or to one or more of said message parts; and
,transform said electronic message to provide a warning to a user who attempts to access said electronic message or attempts to access one or more of said one or more message parts,wherein said transform said electronic message to provide said warning comprises one or more ofinsert text or graphics warning about a potential threat into the subject line of said electronic message and into the message contents of said electronic message, and,transform a link to a website from said electronic message to a protected link, wherein clicking said protected link one or more of
shows a website warning to said user before connecting to said website, and,
calculates a website maturity score, and if said website maturity score is below a threshold, displays a warning message to said user before connecting to said website.
5 Assignments
0 Petitions
Accused Products
Abstract
A malware detection system based on stored data that analyzes an electronic message for threats by comparing it to previously received messages in a message archive or to a contacts list. Threat protection rules may be generated dynamically based on the message and contacts history. A message that appears suspicious may be blocked, or the system may insert warnings to the receiver not to provide personal information without verifying the message. Threat checks may look for unknown senders, senders with identities that are similar to but not identical to previous senders or to known contacts, or senders that were added only recently as contacts. Links embedded in messages may be checked by comparing them to links previously received or to domain names of known contacts. The system may flag messages as potential threats if they contradict previous messages, or if they appear unusual compared to the patterns of previous messages.
-
Citations
30 Claims
-
1. A malware detection system based on stored data, comprising:
a threat protection and detection system executable on a client or server computer or set of client or server computers, wherein the threat protection and detection system comprises a messaging system database comprising an archive of electronic messages, wherein said archive of electronic messages comprises electronic messages previously sent, received or drafted, a contacts list, and summary data derived from said archive of electronic messages and said contacts list, wherein said summary data consolidates information from said message archive of electronic messages and said contacts list and, a message filter coupled to said messaging system database, and configured to receive an electronic message comprising one or more message parts, said one or more message parts comprising a sender information, one or more receivers information, a message contents, a subject line, one or more attachments, one or more links to websites, a message thread; determine whether said electronic message represents a potential threat, based on an analysis of said one or more message parts, and said messaging system database; if said electronic message represents a potential threat, perform one or more of block access to said electronic message or to one or more of said message parts; and
,transform said electronic message to provide a warning to a user who attempts to access said electronic message or attempts to access one or more of said one or more message parts, wherein said transform said electronic message to provide said warning comprises one or more of insert text or graphics warning about a potential threat into the subject line of said electronic message and into the message contents of said electronic message, and, transform a link to a website from said electronic message to a protected link, wherein clicking said protected link one or more of
shows a website warning to said user before connecting to said website, and,
calculates a website maturity score, and if said website maturity score is below a threshold, displays a warning message to said user before connecting to said website.- View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 20, 22, 23, 24, 25, 26, 27, 28, 29, 30)
-
18. (canceled)
-
19. (canceled)
-
21. (canceled)
Specification