US20110314546A1

Electronic Message Analysis for Malware Detection

Claim Score by NHIP

Read claim 1, the broadest

Abstract

An electronic message is analyzed for malware contained in the message. Text of an electronic message may be analyzed to detect and process malware content in the electronic message itself. The present technology may analyze an electronic message and attachments to electronic messages to detect a uniform resource location (URL), identify whether the URL is suspicious, and analyze all suspicious URLs to determine if they are malware. The analysis may include re-playing the suspicious URL in a virtual environment which simulates the intended computing device to receive the electronic message. If the re-played URL is determined to be malicious, the malicious URL is added to a black list which is updated throughout the computer system.

US20110314546A1, drawing sheet 1
Sheet 1 of 10

Term

Term ended

Projected expiry passed 10 November 2025, 0.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

28 claims: 2 independent, 26 dependent

  1. 1
    Broadest claimClaim Score 86, broad(NHIP)A method for detecting malicious network content by a network content processing system, comprising:receiving an electronic message;determining that the electronic message includes content determined to be suspicious;executing the suspicious electronic message content in a virtual environment;and identifying the suspicious electronic message content as malicious based on execution of the suspicious electronic message content in the virtual environment.
  2. 20
    A computer readable storage medium having stored thereon instructions executable by a processor for performing a method for detecting malicious network content, the method comprising:receiving an electronic message;determining that the electronic message includes content determined to be suspicious;executing the suspicious electronic message content in a virtual environment;and identifying the suspicious electronic message content as malicious based on execution of the suspicious electronic message content in the virtual environment.