US2013311677A1PendingUtilityA1

Method and system for monitoring and redirecting http requests away from unintended web sites

Assignee: DESVIO INCPriority: May 6, 2010Filed: Jul 30, 2013Published: Nov 21, 2013
Est. expiryMay 6, 2030(~3.8 yrs left)· nominal 20-yr term from priority
H04L 61/301G06F 16/9566H04L 67/563H04L 61/4511H04L 63/1483H04L 45/745
35
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Embodiments are described for a system and method for redirecting Internet traffic away from illegitimate web sites. A redirect process includes a typo identifier engine and a direct navigation engine. The typo identifier engine generates a list of domain names based on common typographical variations of legitimate brand domains, and common direct navigation domains. A web crawler process verifies if the generated domain name are registered. The sites are classified as either legitimate or illegitimate based on a series of defined rules and analysis of parameters, such as site content, registrar identity, and owner. The direct navigation engine compares the user's request with the list of known illegitimate domains found by the typo identifier engine. If a match is found, the system replaces the user requested domain name with a redirected domain name.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of redirecting Internet traffic comprising:
 compiling a redirection list of domain names based on a characteristic of the domain names, wherein the redirection list includes a typographical variation for each domain name to create variable domain names for each domain name, the typographical variation comprising at least one of: swapping characters within the domain name, dropping at least one character from the domain name, and adding at least one character to the domain name;   receiving a user domain name service (DNS) request to navigate to a web site on the Internet, the user request including a domain name;   comparing the domain name included in the user DNS request to the redirection list;   determining a substitute domain name to redirect to based upon information provided at the time of the user request, wherein the information is selected from the group consisting of: the unique user that is making the request, date and time of the request, location of the user making the request, user preference for the requested domain, and user preference for use of a service associated with the requested domain; and   returning a network address of the substitute domain name if the domain name is on the redirection list,   wherein the receiving, comparing and returning steps are performed prior to transmission of an HTTP request corresponding to the substitute domain name.   
     
     
         2 . The method of  claim 1  wherein the characteristic of the domains is selected from the group consisting of: a spelling of the domain name, content associated with the respective domain; and
 presence of threatening programs in the domain. 
 
     
     
         3 . The method of  claim 2  wherein the requested domain name is translated into the IP address in a DNS resolution process. 
     
     
         4 . The method of  claim 3  wherein the derivation of the network address of the substitute domain is performed prior to translating the IP address in the DNS resolution process. 
     
     
         5 . The method of  claim 3  wherein the derivation of the network address of the substitute domain is performed after translating the IP address in the DNS resolution process. 
     
     
         6 . The method of  claim 1  wherein compiling the redirection list of domain names comprises selecting a plurality of common domain names associated with known trademarks referenced over the Internet. 
     
     
         7 . The method of  claim 1 , further comprising appending one or more relevant keywords to each domain name to create extended domain names for each domain name. 
     
     
         8 . The method of  claim 1  wherein a legitimate site is a site which is not to be redirected from, and an illegitimate site is a site that is to be redirected from. 
     
     
         9 . The method of  claim 8  wherein an illegitimate site comprises a site that abuses a trademark associated with at least one domain name of the redirection list. 
     
     
         10 . The method of  claim 9  wherein the illegitimate site is one of a typosquatting site, a phishing site, a malware site, a pay-per-click site, and an affiliate fraud site. 
     
     
         11 . The method of  claim 1  further comprising notifying the user that a redirection is occurring by displaying a message that is viewable within a web browser of a client computer operated by the user. 
     
     
         12 . A system for redirecting Internet traffic, the system comprising:
 a processor-based application executed on a computer and configured to:   compile a redirection list of domain names based on a characteristic of the domain names, wherein the redirection list includes a typographical variation for each domain name to create variable domain names for each domain name, the typographical variation comprising at least one of: swapping characters within the domain name, dropping at least one character from the domain name, and adding at least one character to the domain name;   receive a user domain name service (DNS) request to navigate to a web site on the Internet, the user request including a domain name;   compare the domain name included in the user DNS request to the redirection list;   determine a substitute domain name to redirect to based upon information provided at the time of the user request, wherein the information is selected from the group consisting of: the unique user that is making the request, date and time of the request, location of the user making the request, user preference for the requested domain, and user preference for use of a service associated with the requested domain; and   return a network address of the substitute domain name if the domain name is on the redirection list,   wherein the receiving, comparing and returning steps are performed prior to transmission of an HTTP request corresponding to the substitute domain name.   
     
     
         13 . The system of  claim 12 , wherein the characteristic of the domains is selected from the group consisting of: a spelling of the domain name, content associated with the respective domain; and presence of threatening programs in the domain. 
     
     
         14 . The system of  claim 13 , wherein the requested domain name is translated into the IP address in a DNS resolution process. 
     
     
         15 . The system of  claim 14 , wherein the derivation of the network address of the substitute domain is performed prior to translating the IP address in the DNS resolution process. 
     
     
         16 . The system of  claim 14 , wherein the derivation of the network address of the substitute domain is performed after translating the IP address in the DNS resolution process. 
     
     
         17 . The system of  claim 12 , wherein compiling the redirection list of domain names comprises selecting a plurality of common domain names associated with known trademarks referenced over the Internet. 
     
     
         18 . The system of  claim 12 , wherein the processor-based application is further configured to append one or more relevant keywords to each domain name to create extended domain names for each domain name. 
     
     
         19 . The system of  claim 12 , wherein a legitimate site is a site which is not to be redirected from, and an illegitimate site is a site that is to be redirected from. 
     
     
         20 . The system of  claim 19 , wherein an illegitimate site comprises a site that abuses a trademark associated with at least one domain name of the redirection list. 
     
     
         21 . The system of  claim 20 , wherein the illegitimate site is one of a typosquatting site, a phishing site, a malware site, a pay-per-click site, and an affiliate fraud site. 
     
     
         22 . The system of  claim 12 , wherein the processor-based application is further configured to notify the user that a redirection is occurring by displaying a message that is viewable within a web browser of a client computer operated by the user. 
     
     
         23 . A computer program product, comprising a non-transitory computer-readable medium having a computer-readable program code embodied therein, the computer-readable program code adapted to be executed by one or more processors to implement a method for redirecting Internet traffic, the method comprising:
 compiling a redirection list of domain names based on a characteristic of the domain names, wherein the redirection list includes a typographical variation for each domain name to create variable domain names for each domain name, the typographical variation comprising at least one of: swapping characters within the domain name, dropping at least one character from the domain name, and adding at least one character to the domain name;   receiving a user domain name service (DNS) request to navigate to a web site on the Internet, the user request including a domain name;   comparing the domain name included in the user DNS request to the redirection list;   determining a substitute domain name to redirect to based upon information provided at the time of the user request, wherein the information is selected from the group consisting of: the unique user that is making the request, date and time of the request, location of the user making the request, user preference for the requested domain, and user preference for use of a service associated with the requested domain; and   returning a network address of the substitute domain name if the domain name is on the redirection list,   wherein the receiving, comparing and returning steps are performed prior to transmission of an HTTP request corresponding to the substitute domain name.   
     
     
         24 . The system of  claim 23 , wherein the characteristic of the domains is selected from the group consisting of: a spelling of the domain name, content associated with the respective domain; and presence of threatening programs in the domain. 
     
     
         25 . The system of  claim 24 , wherein the requested domain name is translated into the IP address in a DNS resolution process. 
     
     
         26 . The system of  claim 25 , wherein the derivation of the network address of the substitute domain is performed prior to translating the IP address in the DNS resolution process. 
     
     
         27 . The system of  claim 25 , wherein the derivation of the network address of the substitute domain is performed after translating the IP address in the DNS resolution process. 
     
     
         28 . The system of  claim 23 , wherein compiling the redirection list of domain names comprises selecting a plurality of common domain names associated with known trademarks referenced over the Internet. 
     
     
         29 . The system of  claim 23 , wherein the processor-based application is further configured to append one or more relevant keywords to each domain name to create extended domain names for each domain name. 
     
     
         30 . The system of  claim 23 , wherein a legitimate site is a site which is not to be redirected from, and an illegitimate site is a site that is to be redirected from. 
     
     
         31 . The system of  claim 30 , wherein an illegitimate site comprises a site that abuses a trademark associated with at least one domain name of the redirection list. 
     
     
         32 . The system of  claim 31 , wherein the illegitimate site is one of a typosquatting site, a phishing site, a malware site, a pay-per-click site, and an affiliate fraud site. 
     
     
         33 . The system of  claim 23 , wherein the processor-based application is further configured to notify the user that a redirection is occurring by displaying a message that is viewable within a web browser of a client computer operated by the user.

Join the waitlist — get patent alerts

Track US2013311677A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.