Systems and methods for automatically detecting backdoors
US-8990944-B1 · Mar 24, 2015 · US
US9961090B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9961090-B2 |
| Application number | US-201514743325-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 18, 2015 |
| Priority date | Jun 18, 2015 |
| Publication date | May 1, 2018 |
| Grant date | May 1, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems, methods, apparatuses, and computer-readable media configured to receive a search query and identify one or more messages matching at least a portion of the search query are provided. The identified one or more messages may be displayed, in some examples, and user input may be received identified at least one message of the identified one or more messages for further processing, such as quarantine. In some examples, the at least one message may be transmitted to an account search server which may search a plurality of user accounts, such as email accounts. The account search server may identify one or more occurrences of the at least one message in one or more accounts of the plurality of accounts and may remove the occurrence of the at least one message from the account and transfer the at least one message to a quarantine location.
Opening claim text (preview).
What is claimed is: 1. A system, comprising: a message identifying server including at least a first processor, a first communication interface and a first memory storing computer-executable instructions that, when executed, cause the at least a first processor to: receive a search query; search a plurality of received messages to identify one or more messages matching at least a portion of the search query; display the identified one or more messages matching the at least a portion of the search query on a display of the message identifying server; and receive selection of at least one of the identified one or more messages matching the at least a portion of the search query for further processing; and an account searching server, the account searching server including at least a second processor, a second communication interface and a second memory storing computer-executable instructions that, when executed, cause the at least a second processor to: receive metadata associated with the selected at least one of the identified one or more messages matching the at least a portion of the search query from the message identifying server via the second communication interface; receive identification of a plurality of user accounts to be searched for occurrences of the selected at least one of the identified one or more messages matching the at least a portion of the search query; search the identified plurality of user accounts for occurrences of the metadata associated with the selected at least one of the identified one or more messages matching the at least a portion of the search query; responsive to identifying an occurrence of the metadata associated with the selected at least one of the identified one or more messages matching the at least a portion of the search query, remove the occurrence of the selected at least one of the identified one or more messages matching the at least a portion of the search query from a user account in which the occurrence was identified; and transmit the occurrence of the selected at least one of the identified one or more messages matching the at least a portion of the search query to a quarantine location. 2. The system of claim 1 , wherein receiving a search query includes receiving information identifying a single message. 3. The system of claim 1 , wherein receiving the search query includes receiving a file including a plurality of messages identified as potentially malicious. 4. The system of claim 1 , wherein receiving the search query includes receiving a customized search query including at least one of: a sender, a recipient, a subject, and a keyword. 5. The system of claim 4 , wherein identifying one or more messages matching at least a portion of the search query includes using grouping logic to search, via a log repository, a plurality of received messages to identify the one or more messages matching at least a portion of the search query. 6. The system of claim 1 , wherein the plurality of received messages are email messages and the plurality of user accounts are email accounts of a plurality of users. 7. The system of claim 1 , wherein the account searching server further includes instructions that, when executed, cause the at least the second processor to: transmit a status of the occurrence of the selected at least one of the identified one or more messages to the message matching the at least a portion of the search query identifying server; and display the status on the display of the message identifying server. 8. The system of claim 7 , wherein the status includes an indication that the occurrence has been transmitted to the quarantine location and identification from a user account from which the occurrence was removed. 9. The system of claim 1 , wherein receiving the search query includes receiving a comma separated value file uploaded to the message identifying server. 10. An apparatus, comprising: at least one processor; a communication interface; and at least one memory storing computer-executable instructions that, when executed, cause the apparatus to: receive a search query; search a plurality of received message to identify one or more received messages matching at least a portion of the search query; display the identified one or more messages matching the at least a portion of the search query on a display of the apparatus; receive selection of at least one of the identified one or more messages matching the at least a portion of the search query for further processing; transmit metadata associated with the selected at least one of the identified one or more messages matching the at least a portion of the search query to an account searching server via the communication interface; receive, from the account searching server and via the communication interface, identified occurrences of the selected at least one of the identified one or more messages matching the at least a portion of the search query found in one or more user accounts based on the metadata; and receive, from the account searching server and via the communication interface, an indication that the identified occurrences have been removed from the one or more user accounts and have been transmitted to a quarantine location. 11. The apparatus of claim 10 , wherein receiving a search query includes receiving information identifying a single message. 12. The apparatus of claim 10 , wherein receiving the search query includes receiving a file including a plurality of messages identified as potentially malicious. 13. The apparatus of claim 10 , wherein receiving the search query includes receiving a customized search query including at least one of: a sender, a recipient, a subject, and a keyword. 14. The apparatus of claim 13 , wherein identifying one or more messages matching at least a portion of the search query includes using grouping logic to search, via a log repository, a plurality of received messages to identify the one or more messages matching at least a portion of the search query. 15. The apparatus of claim 10 , wherein the plurality of received messages are email messages. 16. The apparatus of claim 10 , further including instructions that, when executed, cause the apparatus to: receive, from the account searching server, a status of the occurrence of the selected at least one of the identified one or more messages matching the at least a portion of the search query; and display the status on the display of the apparatus. 17. The apparatus of claim 16 , wherein the status includes an indication that the occurrence has been transmitted to the quarantine location and identification from a user account from which the occurrence was removed. 18. A method, comprising: receiving, by a message identifying server including at least a first processor, a first communication interface and a first memory a search query; searching a plurality of received messages to identify, by the message identifying server, one or more messages matching at least a portion of the search query; displaying, by the message identifying server, the identified one or more messages matching the at least a portion of the search query on a display; receiving, by the message identifying server, selection of at least one of the identified one or more messages matching the at least a portion of the search query for further processing; transmitting, by the message identifying server and to an account searching server, metadata associated with the selected at least one of the identified one or more messages matching the a
involving event detection and direct action · CPC title
by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title
the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.