System and method for communication management through analysis of recipient behavior and/or contact relationships
US-2017005954-A1 · Jan 5, 2017 · US
US10050922B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10050922-B2 |
| Application number | US-201615066031-A |
| Country | US |
| Kind code | B2 |
| Filing date | Mar 10, 2016 |
| Priority date | Mar 25, 2015 |
| Publication date | Aug 14, 2018 |
| Grant date | Aug 14, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A mail processing server includes a storage unit and a computation unit. The storage unit stores operation log data recording operations that a plurality of users performed on received email messages. Upon detection of a target email message addressed to a plurality of destination users, the computation unit produces priority data that describes priorities of individual destination users specified in the target email message, based on the operation log data in the storage unit.
Opening claim text (preview).
What is claimed is: 1. A mail processing server comprising: a memory configured to store operation log data recording operations that a plurality of users performed on received email messages, the operation log data including records of the email messages, the records each containing a reception timestamp indicating when an email message was received, an action timestamp indicating when a user executed a risky action on the email message, and a user name indicating who executed the risky action; and a processor configured to perform a procedure including: producing, upon detection of a fraudulent email message that causes an undesired problem and is addressed to a plurality of destination users, priority data that describes priorities of individual destination users specified in the fraudulent email message, based on the operation log data in the memory, wherein the producing includes giving a priority to each of the destination users, the priority having a value that increases with a decrease in a period from reception of an email message addressed to the destination user to execution, by the destination user, of a risky action on the email message addressed to the destination user; and deleting the fraudulent email message from mailboxes of the destination users in descending order of the priorities of the destination users. 2. The mail processing server according to claim 1 , wherein the procedure further includes: transmitting a message to the destination users in descending order of the priorities of the destination users, the message indicating the detection of the fraudulent email message. 3. The mail processing server according to claim 1 , wherein the procedure further includes: investigating terminal devices of the destination users in descending order of the priorities of the destination users, to determine whether the fraudulent email message has been downloaded to any of the terminal devices; and commanding the terminal device that has downloaded the fraudulent email message to delete the downloaded fraudulent email message. 4. The mail processing server according to claim 1 , wherein the producing priority data includes: extracting a subset of the email messages that shares a characteristic property with the fraudulent email message; and giving successively lower priorities to the destination users sorted in ascending order of times taken from reception of the subset of the email messages to execution of a specified action on the subset of the email messages. 5. The mail processing server according to claim 4 , wherein the producing priority data includes: calculating, based on the operation log data, an execution ratio representing a ratio of specific actions performed in a specific time after email reception, the execution ratio being calculated for the individual destination users and for each of a plurality of characteristic properties of the email messages; and giving priorities to the individual destination users, based on the execution ratios calculated about the characteristic properties of the fraudulent email message. 6. A mail processing method comprising: producing by a processor, upon detection of a fraudulent email message that causes an undesired problem and is addressed to a plurality of destination users, priority data that describes priorities of individual destination users specified in the fraudulent email message, based on operation log data recording operations that a plurality of users performed on received email messages, the operation log data including records of the email messages, the records each containing a reception timestamp indicating when an email message was received, an action timestamp indicating when a user executed a risky action on the email message, and a user name indicating who executed the risky action, wherein the producing includes giving a priority to each of the destination users, the priority having a value that increases with a decrease in a period from reception of an email message addressed to the destination user to execution, by the destination user, of a risky action on the email message addressed to the destination user; and deleting the fraudulent email message from mailboxes of the destination users in descending order of the priorities of the destination users. 7. A non-transitory computer-readable storage medium storing therein a program that causes a computer to perform a procedure comprising: producing, upon detection of a fraudulent email message addressed to a plurality of destination users, priority data that describes priorities of individual destination users specified in the fraudulent email message, based on operation log data recording operations that a plurality of users performed on received email messages, the operation log data including records of the email messages, the records each containing a reception timestamp indicating when an email message was received, an action timestamp indicating when a user executed a risky action on the email message, and a user name indicating who executed the risky action, wherein the producing includes giving a priority to each of the destination users, the priority having a value that increases with a decrease in a period from reception of an email message addressed to the destination user to execution, by the destination user, of a risky action on the email message addressed to the destination user; and deleting the fraudulent email message from mailboxes of the destination users in descending order of the priorities of the destination users.
service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title
the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title
Electricity · mapped topic
Electricity · mapped topic
Delivery according to priorities · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.