A method and system for detecting and preventing bulk messages in
real-time is provided. A detection server detects and prevents bulk
messages in real-time by analyzing the network traffic pattern of
attributes of messages, such as email messages, that are passing through
the network against an expected network traffic pattern. The expected
network traffic pattern may be specified as a combination of a rate and
one or more thresholds, where each threshold has a corresponding status.
The rate specifies a quantity of an attribute measured with respect to a
quantity of time. A status associated with a threshold is attained when
the rate is exceeded the requisite threshold number of times. The status
indicates an action that is to be taken in processing the email message
containing the attribute. An email message can then be processed in
accordance with a status assigned to an attribute of the email message.