发明名称 METHOD AND SYSTEM FOR IDENTIFYING NETWORK ADDRESSES ASSOCIATED WITH SUSPECT NETWORK DESTINATIONS
摘要 A method and system for identifying network addresses associated with suspect network destinations is described. One embodiment receives a target Uniform Resource Locator (URL) to be analyzed; segments the target URL into a set of component parts; classifies each component part in the set of component parts as a primary domain, a subdomain, or a page; hashes each component part in the set of component parts to produce a hash value for that component part; compares the hash values of the set of component parts from the target URL with hash values stored in a database, the hash values stored in the database having been obtained by segmenting, classifying, and hashing, in the same manner as the target URL, each of a set of URLs known to be associated with suspect network destinations; computing a score that indicates the extent to which the hash values of the set of component parts from the target URL match hash values stored in the database; and taking corrective action, when the score satisfies a predetermined criterion. In one embodiment, taking correction action includes notifying a user that the target URL is believed to be associated with a suspect network destination. In another embodiment, taking corrective action includes blocking a network connection between a computer and the network destination associated with the target URL.
申请公布号 US2008034073(A1) 申请公布日期 2008.02.07
申请号 US20060462781 申请日期 2006.08.07
申请人 MCCLOY HARRY MURPHEY;SHIFMAN CRAIG MITCHELL 发明人 MCCLOY HARRY MURPHEY;SHIFMAN CRAIG MITCHELL
分类号 G06F15/173 主分类号 G06F15/173
代理机构 代理人
主权项
地址