摘要 |
A method and system for identifying network addresses associated with suspect network destinations is described. One embodiment receives a target Uniform Resource Locator (URL) to be analyzed; segments the target URL into a set of component parts; classifies each component part in the set of component parts as a primary domain, a subdomain, or a page; hashes each component part in the set of component parts to produce a hash value for that component part; compares the hash values of the set of component parts from the target URL with hash values stored in a database, the hash values stored in the database having been obtained by segmenting, classifying, and hashing, in the same manner as the target URL, each of a set of URLs known to be associated with suspect network destinations; computing a score that indicates the extent to which the hash values of the set of component parts from the target URL match hash values stored in the database; and taking corrective action, when the score satisfies a predetermined criterion. In one embodiment, taking correction action includes notifying a user that the target URL is believed to be associated with a suspect network destination. In another embodiment, taking corrective action includes blocking a network connection between a computer and the network destination associated with the target URL.
|