发明名称 SYSTEMS AND METHODS OF IDENTIFYING SUSPICIOUS HOSTNAMES
摘要 A method includes receiving a set of strings and applying one or more filters to generate a subset of strings that are determined to correspond to strings of interest. The method also includes retrieving domain name system (DNS) information associated with a first string of the subset. The method includes executing a rule-based engine to determine, based on application of one or more rules to the DNS information, whether to add the first string to a set of suspicious hostnames.
申请公布号 US2017104784(A1) 申请公布日期 2017.04.13
申请号 US201615388256 申请日期 2016.12.22
申请人 Cloudmark, Inc. 发明人 Stemm Mark Richard;Johns Arlyn Robert
分类号 H04L29/06;G06F17/30 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method comprising: receiving, via an input interface, a string that corresponds to a hostname; identifying, at a computing device, a data structure that indicates frequencies of occurrence of each of a plurality of n-grams in a first set of strings; and applying, at the computing device, a filter to determine whether to classify the string as potentially suspicious, the filter including an entropy filter and at least one other filter, wherein the filter is configured to classify the string as potentially suspicious in response to the entropy filter and the at least one other filter each indicating that the string is potentially suspicious, wherein the entropy filter is configured to indicate that the string is potentially suspicious based on an n-gram entropy of the string, and wherein the n-gram entropy of the string is a function of the frequency of occurrence, indicated by the data structure, for each n-gram in the string.
地址 San Francisco CA US