Detection of image spam
First Claim
1. A method of detecting spam images in electronic mail, the method comprising:
- obtaining one or more known spam e-mails;
obtaining and extracting known spam images from the known spam e-mails;
compressing the extracted known spam images into a common representation having a common size and color palette using a lossy compression function;
using the compressed known spam images to create a corpus of compressed known spam images;
extracting images embedded in a subject electronic mail message;
compressing the extracted images embedded in the subject electronic mail message into a common representation having the common size and color palette using a lossy compression function;
determining if the compressed forms of the extracted images embedded in the subject electronic mail message are identical to the compressed form of any of the extracted known spam images in the corpus of known spam images; and
signaling the subject electronic mail message as embedding a spam image on the basis of a compressed form of an extracted image extracted from the subject electronic mail message being determined to be identical to the compressed form of a known spam image.
3 Assignments
0 Petitions
Accused Products
Abstract
A method of detecting spam images in electronic objects such as emails includes compressing images extracted from the electronic object into a common representation using a lossy compression function and determining if the compressed forms of the extracted images are identical to the compressed form of any known spam image from a corpus of known spam images, which compressed forms are the known spam images compressed into the common representation using the lossy compression function. The electronic objects are signalled as embedding a spam image on the basis of a compressed form of an extracted image extracted from an electronic object being determined to be identical to the compressed form of a known spam image.
29 Citations
29 Claims
-
1. A method of detecting spam images in electronic mail, the method comprising:
-
obtaining one or more known spam e-mails; obtaining and extracting known spam images from the known spam e-mails; compressing the extracted known spam images into a common representation having a common size and color palette using a lossy compression function; using the compressed known spam images to create a corpus of compressed known spam images; extracting images embedded in a subject electronic mail message; compressing the extracted images embedded in the subject electronic mail message into a common representation having the common size and color palette using a lossy compression function; determining if the compressed forms of the extracted images embedded in the subject electronic mail message are identical to the compressed form of any of the extracted known spam images in the corpus of known spam images; and signaling the subject electronic mail message as embedding a spam image on the basis of a compressed form of an extracted image extracted from the subject electronic mail message being determined to be identical to the compressed form of a known spam image. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14)
-
-
15. A system for detecting spam images in electronic mail messages, the system comprising:
-
means for obtaining one or more known spam e-mails; an image extraction engine operative to extract known spam images from the known spam e-mails; a compression unit operative to compress the known spam images into a common representation having a common size and color palette using a lossy compression function; an image extraction engine operative to extract images embedded in the electronic mail messages; a compression unit operative to compress the extracted images embedded in the electronic mail message into a common representation having a common size and color palette using a lossy compression function; a determination unit operative to determine if the compressed forms of the extracted images embedded in the electronic mail message are identical to the compressed form of any known spam image; and a signal unit operative to signal electronic mail messages as embedding a spam image responsive to the determination unit determining that a compressed form of an extracted image embedded in an electronic mail message is identical to the compressed form of a known spam image. - View Dependent Claims (16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29)
-
Specification