US2021344632A1PendingUtilityA1

Detection of spam messages

Assignee: AT & T IP I LPPriority: Apr 29, 2014Filed: Jul 15, 2021Published: Nov 4, 2021
Est. expiryApr 29, 2034(~7.8 yrs left)· nominal 20-yr term from priority
H04L 51/212H04L 51/12
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method of generating a signature for a group of electronic messages that each include a plurality of characters comprises extracting a plurality of blocks of characters from each of the electronic messages, mathematically processing each of the blocks of characters from each electronic message, and generating a signature for the group of electronic messages based at least in part on the mathematically processed blocks of characters. In some embodiments a counting Bloom filter may be used to generate the signature. The signatures generated by these methods may be used to identify spam.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system for identifying a spam message, comprising:
 a hardware processor; and   a memory device storing instructions that, when executed by the hardware processor, perform operations, the operations comprising:   receiving non-consecutive textual characters extracted from known spam messages;   generating a first Bloom filter output array from hash values representing the non-consecutive textual characters extracted from the known spam messages by hashing digital representations of the non-consecutive textual characters according to a hash function, wherein the generating comprises generating the first Bloom filter output array using only non-consecutive textual characters common to all spam messages of the known spam messages;   comparing a second Bloom filter output array according to a hash value representing a text message to the first Bloom filter output array according to the hash values representing the non-consecutive textual characters extracted from the known spam messages to obtain a comparison;   in response to the comparison indicating a match between the first and second Bloom filter output arrays, identifying the text message as the spam message; and   identifying a sender's address or a user account associated with the text message identified as the spam message.   
     
     
         2 . The system of  claim 1 , wherein the operations further comprise:
 processing the non-consecutive textual characters through a counting Bloom filter to generate the Bloom filter output array.   
     
     
         3 . The system of  claim 1 , wherein the operations further comprise:
 identifying, based on the first Bloom filter output array, a user account sending the text message identified as the spam message.   
     
     
         4 . The system of  claim 1 , wherein the operations further comprise:
 receiving short message service messages; and   extracting the textual characters from the short message service messages.   
     
     
         5 . The system of  claim 1 , wherein the operations further comprise:
 receiving short message service messages; and   extracting the textual characters from at least one of the short message service messages.   
     
     
         6 . The system of  claim 1 , wherein the operations further comprise:
 determining an entropy of the Bloom filter output array.   
     
     
         7 . The system of  claim 6 , wherein the operations further comprise:
 identifying a user account as a source of spam in based on the entropy of the Bloom filter output array.   
     
     
         8 . A system for identifying a user account as a source of spam messages, comprising:
 a hardware processor; and   a memory device storing instructions that, when executed by the hardware processor, perform operations, the operations comprising:   receiving non-consecutive textual characters extracted from known spam messages;   generating a Bloom filter output array from hash values representing the non-consecutive textual characters extracted from the known spam messages by hashing digital representations of the non-consecutive textual characters according to a hash function, wherein the generating comprises generating the Bloom filter output array using only non-consecutive textual characters common to all spam messages of the known spam messages;   determining an entropy of the Bloom filter output array;   comparing the entropy of the Bloom filter output array with an entropy threshold; and   identifying a user account as a source of spam in response to the entropy of the Bloom filter output array being less than the entropy threshold.   
     
     
         9 . The system of  claim 8 , wherein the operations further comprise:
 receiving short message service messages; and   extracting the textual characters from the short message service messages.   
     
     
         10 . The system of  claim 8 , wherein the operations further comprise:
 receiving short message service messages; and   extracting the textual characters from at least one of the short message service messages.   
     
     
         11 . The system of  claim 8 , wherein the operations further comprise:
 receiving short message service messages;   hashing blocks of characters extracted from the short message service messages according to a hash function to generate hash values; and   identifying the user account as a source of spam in response to non-zero positions in the entropy of the Bloom filter output array generated from the hash values.   
     
     
         12 . The system of  claim 11 , wherein the operations further comprise:
 incrementing non-zero positions in the entropy of the Bloom filter output array according to a count of the short message service messages.   
     
     
         13 . The system of  claim 8 , wherein the operations further comprise:
 retrieving from storage the entropy threshold.   
     
     
         14 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a processor, facilitate performance of operations, the operations comprising:
 receiving a plurality of electronic messages;   extracting non-consecutive textual characters from the electronic messages;   hashing digital representations of the non-consecutive textual characters according to a hash function, producing hash values representing the non-consecutive textual characters;   generating a Bloom filter output array from the hash values, wherein the generating comprises generating the Bloom filter output array using only non-consecutive textual characters common to all electronic messages of the electronic messages;   determining an entropy of the Bloom filter output array;   comparing the entropy of the Bloom filter output array with an entropy threshold; and   identifying a user account as a source of spam in response to the entropy of the Bloom filter output array being less than the entropy threshold, the entropy of the Bloom filter output providing an indication of how similar messages sent from the user account are to each other.   
     
     
         15 . The non-transitory machine-readable medium of  claim 14 , wherein the extracting non-consecutive textual characters comprises extracting the non-consecutive textual characters from the electronic messages. 
     
     
         16 . The non-transitory machine-readable medium of  claim 14 , wherein the receiving a plurality of electronic messages comprises receiving a plurality of short message service messages and wherein the operations further comprise extracting the textual characters from at least one of the short message service messages. 
     
     
         17 . The non-transitory machine-readable medium of  claim 14 , wherein the operations further comprise:
 retrieving from storage the entropy threshold, the entropy threshold having a predefined value.   
     
     
         18 . The non-transitory machine-readable medium of  claim 14 , wherein the operations further comprise:
 reviewing a plurality of messages from subscriber accounts having respective Bloom filter output arrays;   determining respective entropy values for the respective Bloom filter output arrays;   comparing the respective entropy values with the entropy threshold; and   identifying respective user accounts associated with the respective entropy values as sources of spam responsive to the comparing.   
     
     
         19 . The non-transitory machine-readable medium of  claim 14 , wherein the receiving a plurality of electronic messages comprises receiving a plurality of known spam messages. 
     
     
         20 . The non-transitory machine-readable medium of  claim 14 , wherein the operations further comprise:
 incrementing nonzero positions in the entropy of the Bloom filter output array according to a count of the electronic messages.

Join the waitlist — get patent alerts

Track US2021344632A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.