Patent · US Active

Malicious domain generation algorithm (DGA) detection in memory of a data processing unit using machine learning detection models

US12160437B2 · kind B2 · utility

0Cited by
9References
27Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 13, 2022
Grant dateDec 3, 2024
Priority date
Expiry dateApr 14, 2043

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/145
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Apparatuses, systems, and techniques for classifying one or more candidate uniform resource locators (URLs) as having a domain generation algorithm (DGA) domain using a machine learning (ML) detection system. An integrated circuit is coupled to physical memory of a host device via a host interface. The integrated circuit hosts a hardware-accelerated security service to protect one or more computer programs executed by the host device. The security service extracts a set of features from data stored in the physical memory, the data being domain characters in one or more candidate URLs. The security service classifies, using the ML detection system, the one or more candidate URLs as having a DGA domain or a non-DGA domain using the set of features. The security service outputs an indication of a DGA malware responsive to the one or more candidate URLs being classified as having the DGA domain.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.