Patent · US Active

Polymorphic non-attributable website monitor

US12255908B2 · kind B2 · utility

0Cited by
5References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateFeb 6, 2023
Grant dateMar 18, 2025
Priority date
Expiry dateOct 20, 2043

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1483
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Polymorphic non-attributable processes and architectures to monitor threat domains (e.g., pharming or phishing websites) are disclosed. Obfuscated requests may be generated by control servers to be blended in with normal traffic sent over cloud networks with randomized exit nodes or with normal traffic sent through an anonymization network. Requests may be sent at randomized intervals or time periods determined algorithmically. The requests are obfuscated in order to mask the origination information and location so that the threat actor does not detect that the website is being monitored. User agents may be spoofed and requests may present as if they originated from residential IP addresses. Automatic real-time monitoring can be provided to determine when sites resolve and are addressable. Fingerprint information, screenshots, security certificate, and other threat domain data can be captured. Request responses can be scanned for threat indicia.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.