Patent · US Active

Identification of malware sites using unknown URL sites and newly registered DNS addresses

US9473528B2 · kind B2 · utility

6Cited by
33References
28Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJan 13, 2015
Grant dateOct 18, 2016
Priority date
Expiry dateJan 13, 2035

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2111
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

In some embodiments, identification of malware sites using unknown URL sites and newly registered DNS addresses includes performing a heuristic analysis for information associated with a network site; and assigning a score based on the heuristic analysis, in which the score indicates whether the network site is potentially malicious. In some embodiments, the system includes a security appliance that is in communication with the Internet. In some embodiments, the network site is associated with a network domain and/or a network uniform resource locator (URL). In some embodiments, performing a heuristic analysis for information associated with a network site further includes determining if a network site has recently been registered. In some embodiments, performing a heuristic analysis for information associated with a network site further includes determining if a network site is associated with recently changed DNS information. In some embodiments, performing a heuristic analysis for information associated with a network site further includes determining geographical information as well as an IP network location associated with the network site.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.