Method and system for domain maliciousness assessment via real-time graph inference
US11206275B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | May 30, 2019 |
| Grant date | Dec 21, 2021 |
| Priority date | — |
| Expiry date | Feb 26, 2040 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L41/16
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
The presently disclosed method and system exploits information and traces contained in DNS data to determine the maliciousness of a domain based on the relationship it has with other domains. A method may comprise providing data to a machine learning module that was previously trained on domain and IP address attributes or classifiers. The method then may comprise classifying apex domains and IP addresses based on the IP address and domain attributes or classifiers. Additionally, the method may comprise associated each of the domains and IP addresses based on the corresponding classification. The method may further comprise building a weighted domain graph at real-time utilizing the DNS data based on the aforementioned associations among domains. The method may then comprise assessing the maliciousness of a domain based on the weighted domain graph that was built.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.