发明名称 Method and system for detecting malware containing E-mails based on inconsistencies in public sector From addresses and a sending IP address
摘要 A method and apparatus for detecting malware containing e-mails based on inconsistencies between a governmental agency "From" address and a sending IP address whereby an incoming e-mail is analyzed to determine if the incoming e-mail includes a "From" address having a domain suffix that is normally associated with a governmental agency, such as a .gov, .gov.uk, .go.jp, or any similar governmental domain suffix. The connecting IP address or IP addresses within the received headers associated with the incoming e-mail are then analyzed to determine the geographical locations through which the incoming e-mail passed. If the geographical locations associated with these sending IP addresses of the incoming e-mail are not consistent with the country indicated by the domain suffix in the governmental "From" address of the incoming e-mail then the protective action is taken.
申请公布号 US8595830(B1) 申请公布日期 2013.11.26
申请号 US20100844738 申请日期 2010.07.27
申请人 LEE MARTIN;SYMANTEC CORPORATION 发明人 LEE MARTIN
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址