Invention Grant
US08677490B2 Method for inferring maliciousness of email and detecting a virus pattern 有权
推测电子邮件恶意和检测病毒模式的方法

  • Patent Title: Method for inferring maliciousness of email and detecting a virus pattern
  • Patent Title (中): 推测电子邮件恶意和检测病毒模式的方法
  • Application No.: US11913280
    Application Date: 2006-12-08
  • Publication No.: US08677490B2
    Publication Date: 2014-03-18
  • Inventor: In Seon Yoo
  • Applicant: In Seon Yoo
  • Applicant Address: KR Seoul
  • Assignee: Samsung SDS Co., Ltd.
  • Current Assignee: Samsung SDS Co., Ltd.
  • Current Assignee Address: KR Seoul
  • Agency: Sughrue Mion, PLLC
  • Priority: KR10-2006-0111617 20061113
  • International Application: PCT/KR2006/005340 WO 20061208
  • International Announcement: WO2008/060010 WO 20080522
  • Main IPC: G06F11/00
  • IPC: G06F11/00 G06F15/16 G06F11/30
Method for inferring maliciousness of email and detecting a virus pattern
Abstract:
Provided is a method of distinguishing an abnormal e-mail and determining whether an e-mail is affected with a virus. The method includes the steps of: decoding a received e-mail packet in a readable format and then analyzing and classifying a header of the packet according to header information; determining whether each classified piece of header information is normal or abnormal, and giving a specific value to the corresponding header information according to the determination result; distinguishing an abnormal e-mail using the specific values given to the respective pieces of header information according to a logical inference rule; and when there is an executable attachment file among the header information of the e-mail distinguished as abnormal, determining whether the abnormal e-mail is infected with a virus using distribution of similarity among data. The method effectively distinguishes an abnormal e-mail and determines whether an e-mail is infected with a virus without a database for spam filtering or a database of virus information, and thus is capable of stopping the propagation of new viruses. Therefore, an e-mail server can have a security technique and handle abnormal e-mail in a step before operation of a spam filter server or an antivirus server. Consequently, it is possible to manage a mail server more securely.
Information query
Patent Agency Ranking
0/0