IP Reputation Lists for Spam Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current spam filtering technologies are inadequate in effectively managing the escalating volumes of spam email, which burdens IT resources and negatively impacts user experience due to the increasing cost-effectiveness of spamming.

Innovation Solution

A method and system for maintaining reputation lists of IP addresses, where email messages are filtered to identify spam, and statistics are used to generate and update lists of safe, suspect, and open proxy IP addresses, which are then utilized to filter new messages, thereby controlling spam delivery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional spam filtering products are used, then some spam messages are filtered, but the escalating volumes of spam overwhelm the filtering capacity and drain IT resources

Engineering Contradiction:
Improvespam filtering effectivenessVSAvoidIT resource drain
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent segments the filtering approach by creating multiple specialized IP address lists (safe IP addresses, suspect IP addresses, open proxy IP addresses) rather than using a single monolithic filtering system. Each list serves a specific function in the filtering hierarchy, allowing the system to efficiently handle different types of spam sources without overwhelming resources

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by pre-generating and maintaining reputation lists of IP addresses before spam filtering is needed. These lists are continuously updated based on collected statistics, so when spam filtering is required, the system can quickly reference pre-computed reputation data rather than analyzing each message in real-time, significantly reducing resource drain

Inventive Principle:
Principle #10Preliminary action

2Reliability

If more aggressive filtering is applied to reduce spam, then spam detection improves, but legitimate emails may be incorrectly blocked

Engineering Contradiction:
Improvespam detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different reputation characteristics to different IP addresses based on their specific behavior patterns. Instead of treating all IPs uniformly, the system creates specialized lists (safe, suspect, open proxy) with distinct filtering rules, allowing aggressive filtering of known spam sources while preserving legitimate traffic from trusted senders

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback by continuously collecting statistics on email messages and spam identification results, then using this feedback to update and refine the IP address reputation lists. This closed-loop approach allows the system to learn from past filtering decisions and adjust its behavior to reduce false positives while maintaining high spam detection accuracy

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8010609B2Method and apparatus for maintaining reputation lists of IP addresses to detect email spam
Publication Date: 2011.08.30 GEN DIGITAL INC
  • US8010609B2 patent drawing
  • US8010609B2 patent drawing
  • US8010609B2 patent drawing

AI summary

A method and system to maintain lists of IP addresses for detection of email spam are described. In one embodiment, the method includes receiving email messages from senders associated with Internet Protocol (IP) addresses, filtering the email messages to identify spam, and sending statistics pertaining to the email messages and the identified spam to a server. The method further includes receiving, from the server, IP address lists generated based on the statistics, and filtering new email messages using the IP address lists. The IP address lists received from the server may include a list of safe IP addresses, a list of suspect IP addresses and a list of open proxy IP addresses.