Scoring domains and ips using domain resolution data to identify malicious domains and ips
Abstract
Domains and IPs are scored using domain resolution data to identify malicious domains and IPs. A domain and IP resolution graph for a set of domains and IPs in a system. A seed set of known malicious domains and known malicious IPs is selected from a malicious domain and malicious IP database. A graphical probabilistic propagation inference from the domain and IP resolution graph and the seed set of known malicious domains and known malicious IPs is generated. A malicious score is calculated for each domain in the set of domains and each IP in the set of IPs, and the malicious domain and malicious IP database is updated.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A method comprising:
selecting a seed set of known malicious domains and known malicious IP addresses (IPs) from a malicious domain and malicious IP database; generating a graphical probabilistic propagation inference based on the seed set, wherein the generating of the graphical probabilistic propagation inference is based on applying a respective known malicious domain and malicious IP of the seed set to each member of a plurality of members of a graphical inference component, and wherein each member computes in parallel and independently malicious scores for other domains and IPs; calculating a malicious score for each domain in a set of domains and each IP in a set of IPs based on the malicious scores computed by the plurality of members; and updating the malicious domain and malicious IP database based on the calculating of the malicious score.
2 . The method of claim 1 wherein the generating of the graphical probabilistic propagation inference comprises generating a graphical inference from each domain in the set of domains and each IP in the set of IPs.
3 . The method of claim 2 further comprising creating a set of combined inferences by combining each graphical inference from each domain in the set of domains and each IP in the set of IPs.
4 . The method of claim 3 wherein the calculating of the malicious score for each domain in the set of domains and each IP in the set of IPs comprises computing the malicious score from each combined inference in the set of combined inferences.
5 . The method of claim 4 wherein the computing of the malicious score comprises computing the malicious score for each domain in the set of domains and each IP in the set of IPs by layers.
6 . The method of claim 5 wherein the computing of the malicious score comprises computing the malicious score for each domain in the set of domains and the malicious score for each IP in the set of IPs starting from a layer depth value d, where d is equal to zero.
7 . The method of claim 6 further comprising:
incrementing d by one;
computing the malicious score for each domain in the set of domains and each IP in the set of IPs in a layer depth where d is equal to d plus one to create a set of malicious scores; and
if d is less than a threshold value repeating incrementing d by one and computing the malicious score for each domain in the set of domains and each IP in the set of IPs
if d is equal to the threshold value, returning the set of malicious scores to the malicious domain and malicious IP database.
8 . A system comprising:
a processor; and a non-volatile computer memory for storing computer instructions coupled to the processor, wherein the processor, responsive to executing the computer instructions, performs operations comprising:
selecting a seed set of known malicious domains and known malicious IP addresses (IPs) from a malicious domain and malicious IP database;
generating a graphical probabilistic propagation inference based on the seed set, wherein the generating of the graphical probabilistic propagation inference is based on applying a respective known malicious domain and malicious IP of the seed set to each member of a plurality of members of a graphical inference component, and wherein each member computes in parallel and independently malicious scores for other domains and IPs; and
updating the malicious domain and malicious IP database based on a calculated malicious score, wherein the calculated malicious score is based on the malicious scores computed by the plurality of members.
9 . The system of claim 8 wherein the generating of the graphical probabilistic propagation inference comprises generating a graphical inference from each domain in a set of domains and each IP in a set of IPs.
10 . The system of claim 9 wherein the operations further comprise creating a set of combined inferences by combining each graphical inference from each domain in the set of domains and each IP in the set of IPs.
11 . The system of claim 10 wherein the calculated malicious score is based on calculating a malicious score for each domain in the set of domains and each IP in the set of IPs.
12 . The system of claim 11 , wherein the calculating of the malicious score for each domain in the set of domains and each IP in the set of IPs comprises computing the malicious score from each combined inference in the set of combined inferences.
13 . The system of claim 12 wherein the calculating of the malicious score for each domain in the set of domains and each IP in the set of IPs comprises computing the malicious score for each domain in the set of domains and each IP in the set of IPs by layers.
14 . The system of claim 13 wherein the computing of the malicious score for each domain in the set of domains and the malicious score for each IP in the set of IPs by layers comprises computing the malicious score for each domain in the set of domains and the malicious score for each IP in the set of IPs starting from a layer depth value d, where d is equal to zero.
15 . The system of claim 14 , the operations further comprising
incrementing d by one; computing the malicious score for each domain in the set of domains and each IP in the set of IPs in a layer depth where d is equal to d plus one to create a set of malicious scores; and if d is less than a threshold value repeating incrementing d by one and computing the malicious score for each domain in the set of domains and each IP in the set of IPs if d is equal to the threshold value, returning the set of malicious scores to the malicious domain and malicious IP database.
16 . A non-transitory, tangible computer-readable medium having computer-executable instructions stored thereon which, when executed by a computer, cause the computer to perform operations comprising:
selecting a seed set of known malicious domains and known malicious IP address (IPs) from a database; generating a graphical probabilistic propagation inference based on the seed set, wherein the generating of the graphical probabilistic propagation inference is based on applying a respective known malicious domain and malicious IP of the seed set to each member of a plurality of members of a graphical inference component, and wherein each member computes in parallel and independently malicious scores for other domains and IPs; and updating the database based on the malicious scores computed by the plurality of members.
17 . The non-transitory, tangible computer-readable medium of claim 16 wherein the generating of the graphical probabilistic propagation inference comprises generating a graphical inference from each domain in a set of domains and each IP in a set of IPs.
18 . The non-transitory, tangible computer-readable medium of claim 17 wherein the operations further comprise creating a set of combined inferences by combining each graphical inference from each domain in the set of domains and each IP in the set of IPs.
19 . The non-transitory, tangible computer-readable medium of claim 18 wherein the updating is based on calculating a malicious score for each domain in the set of domains and each IP in the set of IPs based on the malicious scores computed by the plurality of members.
20 . The non-transitory, tangible computer-readable medium of claim 19 wherein the calculating of the malicious score for each domain in the set of domains and each IP in the set of IPs comprises computing the malicious score for each domain in the set of domains and each IP in the set of IPs by layers.Join the waitlist — get patent alerts
Track US2023076391A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.