- 专利标题: System and methods for detecting malicious email transmission
-
申请号: US12633493申请日: 2009-12-08
-
公开(公告)号: US08443441B2公开(公告)日: 2013-05-14
- 发明人: Salvatore J. Stolfo , Eleazar Eskin , Shlomo Herskop , Manasi Bhattacharyya
- 申请人: Salvatore J. Stolfo , Eleazar Eskin , Shlomo Herskop , Manasi Bhattacharyya
- 申请人地址: US NY New York
- 专利权人: The Trustees of Columbia University in the City of New York
- 当前专利权人: The Trustees of Columbia University in the City of New York
- 当前专利权人地址: US NY New York
- 代理机构: Baker Botts LLP
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
A system and methods of detecting an occurrence of a violation of an email security policy of a computer system. A model relating to the transmission of prior emails through the computer system is defined which is derived from statistics relating to the prior emails. For selected emails to be analyzed, statistics concerning the selected email are gathered. Such statistics may refer to the behavior or other features of the selected emails, attachments to emails, or email accounts. The determination of whether a violation of an email security policy has occurred is performed by applying the model of prior email transmission to the statistics relating to the selected email. The model may be statistical or probabilistic. A model of prior email transmission may include grouping email recipients into cliques. A determination of a violation of a security policy may occur if email recipients for a particular email are in more than one clique.
公开/授权文献
信息查询