Identifying threats in electronic messages
US7854007B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | May 5, 2006 |
| Grant date | Dec 14, 2010 |
| Priority date | — |
| Expiry date | Jul 2, 2029 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L61/4511
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
Early detection of computer viruses and other message-borne threats is provided by applying heuristic tests to message content and examining sender reputation information when no virus signature information is available. As a result, a messaging gateway can suspend delivery of messages early in a virus outbreak, providing sufficient time for updating an anti-virus checker that can strip virus code from the messages. A dynamic and flexible threat quarantine queue is provided with a variety of exit criteria and exit actions that permits early release of messages in other than first in, first-out order. A message scanning method is described in which early exit from parsing and scanning can occur by matching threat rules only to selected message elements and stopping rule matching as soon as a match on one message element exceeds a threat threshold.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.