Patent · US Active

Method and system for domain maliciousness assessment via real-time graph inference

US11206275B2 · kind B2 · utility

1Cited by
6References
18Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 30, 2019
Grant dateDec 21, 2021
Priority date
Expiry dateFeb 26, 2040

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L41/16
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

The presently disclosed method and system exploits information and traces contained in DNS data to determine the maliciousness of a domain based on the relationship it has with other domains. A method may comprise providing data to a machine learning module that was previously trained on domain and IP address attributes or classifiers. The method then may comprise classifying apex domains and IP addresses based on the IP address and domain attributes or classifiers. Additionally, the method may comprise associated each of the domains and IP addresses based on the corresponding classification. The method may further comprise building a weighted domain graph at real-time utilizing the DNS data based on the aforementioned associations among domains. The method may then comprise assessing the maliciousness of a domain based on the weighted domain graph that was built.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.