发明名称 Domain Reputation Evaluation Process and Method
摘要 A system for the identification and subsequent rating of domains based on a result derived from a proprietary algorithm configured to detect when a new domain is registered, correlate the domain to registrant data, cross-check the data based on domain proximity to known-malignity, and output a proximity score employed to convey the potential for malicious content or intentions available or to be served as content accessible via the domain. The system is equipped with a dynamic domain database configured to provide near-real-time domain registration data across all domain extensions, facilitating the detection and scoring of new domains as soon as practicable after their inception. Domains are routinely re-evaluated for score consistency, helping to better maintain the security of visitors to websites hosted, or automated connections to infrastructure present on the domain.
申请公布号 US2017099314(A1) 申请公布日期 2017.04.06
申请号 US201514872191 申请日期 2015.10.01
申请人 Klatt Michael;Roberts Bruce Wharton;Helming Timothy C. 发明人 Klatt Michael;Roberts Bruce Wharton;Helming Timothy C.
分类号 H04L29/06;H04L29/12 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method for identifying malicious domains on a computer comprising: the computer executing a DNS crawl of all known domains on the internet augmented by passive DNS data; the computer extracting nameserver host names from the DNS data; the computer retrieving email addresses from Whois data; the computer retrieving registrant names from Whois data; the computer identifying which registrant names have a large variation of registration emails through the use of parsed Whois data; the computer excluding registrant names with a large variation of registration emails from input data; the computer employing blacklist data feeds to filter all domains; the computer flagging domains identified in the data feeds; the computer identifying a type of threat from each suspect domain, including Malware, Spam, Phishing, and infrastructure Botnet; the computer generating a proximity score of each domain, with suspect domains having a high proximity score indicating a high likelihood the suspect domain is malicious; and the computer flagging suspect domains as malicious.
地址 Seattle WA US