Patent · US Active

Identification of malware sites using unknown URL sites and newly registered DNS addresses

US8966625B1 · kind B1 · utility

163Cited by
17References
24Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 24, 2011
Grant dateFeb 24, 2015
Priority date
Expiry dateJan 26, 2032

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2111
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

In some embodiments, identification of malware sites using unknown URL sites and newly registered DNS addresses includes performing a heuristic analysis for information associated with a network site; and assigning a score based on the heuristic analysis, in which the score indicates whether the network site is potentially malicious. In some embodiments, the system includes a security appliance that is in communication with the Internet. In some embodiments, the network site is associated with a network domain and/or a network uniform resource locator (URL). In some embodiments, performing a heuristic analysis for information associated with a network site further includes determining if a network site has recently been registered. In some embodiments, performing a heuristic analysis for information associated with a network site further includes determining if a network site is associated with recently changed DNS information. In some embodiments, performing a heuristic analysis for information associated with a network site further includes determining geographical information as well as an IP network location associated with the network site.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.