发明名称 MALWARE DETECTION SYSTEM BASED ON STORED DATA
摘要 A malware detection system based on stored data that analyzes an electronic message for threats by comparing it to previously received messages in a message archive or to a contacts list. Threat protection rules may be generated dynamically based on the message and contacts history. A message that appears suspicious may be blocked, or the system may insert warnings to the receiver not to provide personal information without verifying the message. Threat checks may look for unknown senders, senders with identities that are similar to but not identical to previous senders or to known contacts, or senders that were added only recently as contacts. Links embedded in messages may be checked by comparing them to links previously received or to domain names of known contacts. The system may flag messages as potential threats if they contradict previous messages, or if they appear unusual compared to the patterns of previous messages.
申请公布号 US2017078321(A1) 申请公布日期 2017.03.16
申请号 US201615010023 申请日期 2016.01.29
申请人 MIMECAST NORTH AMERICA, INC. 发明人 MAYLOR Jackie;TYLER Simon;BAUER Peter;BENAMRAM Gilly;SOWDEN Paul;MALONE Steven;VAN RY Wayne;RIBEIRO Francisco
分类号 H04L29/06;G06F21/62 主分类号 H04L29/06
代理机构 代理人
主权项 1. A malware detection system based on stored data, comprising: a threat protection and detection system executable on a client or server computer or set of client or server computers, wherein the threat protection and detection system comprises a messaging system database comprising an archive of electronic messages, wherein said archive of electronic messages comprises electronic messages previously sent, received or drafted,a contacts list, andsummary data derived from said archive of electronic messages and said contacts list, wherein said summary data consolidates information from said message archive of electronic messages and said contacts list and,a message filter coupled to said messaging system database, and configured to receive an electronic message comprising one or more message parts, said one or more message parts comprising a sender information,one or more receivers information,a message contents,a subject line,one or more attachments,one or more links to websites,a message thread;determine whether said electronic message represents a potential threat, based on an analysis of said one or more message parts, andsaid messaging system database;if said electronic message represents a potential threat, perform one or more of block access to said electronic message or to one or more of said message parts; and,transform said electronic message to provide a warning to a user who attempts to access said electronic message or attempts to access one or more of said one or more message parts,wherein said transform said electronic message to provide said warning comprises one or more of insert text or graphics warning about a potential threat into the subject line of said electronic message and into the message contents of said electronic message, and,transform a link to a website from said electronic message to a protected link, wherein clicking said protected link one or more of shows a website warning to said user before connecting to said website, and, calculates a website maturity score, and if said website maturity score is below a threshold, displays a warning message to said user before connecting to said website.
地址 Watertown MA US