Patent · US Active

Domain clustering for malicious campaign identification

US11689548B2 · kind B2 · utility

0Cited by
2References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 11, 2019
Grant dateJun 27, 2023
Priority date
Expiry dateSep 11, 2040

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/061
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method for identification of malicious domains is provided. The method extracts a set of domain information from one or more input streams. The set of domain information includes a set of domains and a set of domain characteristics describing each domain. The method clusters the set of domains to generate a set of campaign clusters of related domains. The clusters are based on the set of domain characteristics. The method modifies the set of campaign clusters with a set of threat intelligence ratings to generate a set of enriched campaign clusters. A portion of the set of threat intelligence ratings correspond to one or more domains within the set of campaign clusters. The method determines a cluster designation for each campaign cluster of the set of enriched campaign clusters and distributes the cluster designations for each campaign cluster to one or more threat intelligence resource.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.