Stopping and remediating outbound messaging abuse
First Claim
1. Logic, encoded in non-transitory media, that includes instructions for execution and that, when executed by a processor, is operable to perform operations comprising:
- applying a reputation value, based on a subscriber profile associated with a subscriber account, to an outbound message originated via the subscriber account, the outbound message being either an email message or an instant message;
applying a spam filter to the outbound message;
adding a blind carbon copy recipient to the outbound message, based on reputation data of the outbound message; and
revising the reputation value of the subscriber account based on a plurality of metrics, including a detection of spam, the plurality of metrics further including a deviation from the subscriber profile based, at least in part, on behavior data extracted from a plurality of messages originated via the subscriber account.
12 Assignments
0 Petitions
Accused Products
Abstract
Systems and methods are provided for allowing subscriber message sending profiles to be maintained and used in conjunction with behavior-based anomaly detection techniques and traditional content-based spam signature filtering to enable application of appropriate message disposition policies to outbound subscriber message traffic. According to one embodiment, subscriber profiles are constructed for multiple subscriber accounts associated with a service provider based on outbound message flow originated from the subscriber accounts. Then, possible subscriber account misuse may be discovered by performing behavior-based anomaly detection, including a comparison of a subscriber profile associated with the subscriber account with recent subscriber account usage information, to identify one or more behavioral anomalies in outbound message flow originated from a subscriber account, the behavior-based anomaly detection.
-
Citations
20 Claims
-
1. Logic, encoded in non-transitory media, that includes instructions for execution and that, when executed by a processor, is operable to perform operations comprising:
-
applying a reputation value, based on a subscriber profile associated with a subscriber account, to an outbound message originated via the subscriber account, the outbound message being either an email message or an instant message; applying a spam filter to the outbound message; adding a blind carbon copy recipient to the outbound message, based on reputation data of the outbound message; and revising the reputation value of the subscriber account based on a plurality of metrics, including a detection of spam, the plurality of metrics further including a deviation from the subscriber profile based, at least in part, on behavior data extracted from a plurality of messages originated via the subscriber account. - View Dependent Claims (2, 3, 4, 5, 6, 18)
-
-
7. A method, comprising:
-
applying a reputation value, based on a subscriber profile associated with a subscriber account, to an outbound message originated via the subscriber account, the outbound message being either an email message or an instant message; applying a spam filter to the outbound message; adding a blind carbon copy recipient to the outbound message, based on reputation data of the outbound message; and revising the reputation value of the subscriber account based on a plurality of metrics, including a detection of spam, the plurality of metrics further including a deviation from the subscriber profile based, at least in part, on behavior data extracted from a plurality of messages originated via the subscriber account. - View Dependent Claims (8, 9, 10, 11, 19)
-
-
12. A system, comprising:
-
a processor configured to apply a reputation value, based on a subscriber profile associated with a subscriber account, to an outbound message originated via the subscriber account, the outbound message being either an email message or an instant message, the processor further configured to apply a spam filter to the outbound message, to add a blind carbon copy recipient to the outbound message, based on reputation data of the outbound message, and to revise the reputation value of the subscriber account based on a plurality of metrics, including a detection of spam, the plurality of metrics further including a deviation from the subscriber profile based, at least in part, on behavior data extracted from a plurality of messages originated via the subscriber account. - View Dependent Claims (13, 14, 15, 16, 17, 20)
-
Specification