US2023269267A1PendingUtilityA1

Systems and methods for external detection of misconfigured systems

Assignee: BITSIGHT TECH INCPriority: Apr 17, 2018Filed: Apr 19, 2023Published: Aug 24, 2023
Est. expiryApr 17, 2038(~11.7 yrs left)· nominal 20-yr term from priority
Inventors:Joao Gouveia
H04L 63/1433H04L 61/302H04L 63/1408H04L 61/4511
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computer-implemented method is provided for external detection of a vulnerable system coupled to a communication network. The method can include measuring communication traffic on the communication network to identify one or more domain names, which in turn can originate from server systems in the communication network. The method can further include identifying the domain names based on metadata from the domain names and/or the measured communication traffic, where each domain name has an associated property indicative of its vulnerability. The method can further include determining whether any one (or more) of the domain names is registered at a domain name registry and, if the domain name is not registered, registering the domain name.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method for external detection of a vulnerable system, the vulnerable system coupled to a communication network based on domain name properties, the method comprising:
 receiving communication traffic in the communication network to identify at least one domain name associated with a vulnerable system, the communication traffic originating from at least one server system in the communication network;   executing queries on the communication traffic to extract metadata while monitoring the communication traffic;   identifying the domain name having an associated property indicative of vulnerability of the domain name based on the metadata, wherein the domain name having the associated property indicative of vulnerability comprises a domain name associated with malicious activity; and   if the domain name is not registered with a domain name registry, registering the domain name and detecting the vulnerable system associated with the malicious activity.   
     
     
         2 . The method of  claim 1 , wherein the vulnerable system is a malware-infected server system. 
     
     
         3 . The method of  claim 1 , wherein the vulnerable system is a misconfigured server system. 
     
     
         4 . The method of  claim 1 , wherein the metadata further comprises a geographical location associated with each domain name. 
     
     
         5 . The method of  claim 1 , further comprising:
 associating the registered domain name with a server system configured to monitor communication traffic to the registered domain name.   
     
     
         6 . The method of  claim 1 , wherein each domain name is selected from the group consisting of: (i) an unregistered domain name, (ii) a misconfigured domain name, (iii) an abandoned domain name, and (iv) an algorithm-generated domain name. 
     
     
         7 . The method of  claim 1 , wherein receiving communication traffic data comprises:
 receiving communication traffic data from at least one Internet Service Provider (ISP).   
     
     
         8 . The method of  claim 1 , further comprising:
 comparing a relative magnitude of communication traffic to an expected amount of communication traffic.   
     
     
         9 . The method of  claim 1 , wherein receiving communication traffic data comprises:
 measuring a frequency of communication traffic to the domain name.   
     
     
         10 . The method of  claim 1 , wherein the metadata comprises at least one of the group consisting of: (a) geographical location of the communication traffic, (b) frequency of the communication traffic, (c) magnitude of the communication traffic, (d) aggregated counters of a number of unique Internet Protocol (IP) addresses per country, € a number of events observed per period, and (f) a ratio of unique IP addresses to a sum of a portion of the communication traffic. 
     
     
         11 . A system for external detection of a vulnerable system coupled to a communication network, the system comprising:
 at least one computer systems programmed to perform operations comprising:
 receiving communication traffic in the communication network to identify at least one domain name associated with a vulnerable system, the communication traffic originating from at least one server system in the communication network; 
 executing queries on the communication traffic to extract metadata while monitoring the communication traffic; 
 identifying the domain name having an associated property indicative of vulnerability of the domain name based on the metadata, wherein the domain name having the associated property indicative of vulnerability comprises a domain name associated with malicious activity; and 
 if the domain name is not registered with a domain name registry, registering the domain name and detecting the vulnerable system associated with the malicious activity. 
   
     
     
         12 . The system of  claim 11 , wherein the vulnerable system is a malware-infected server system. 
     
     
         13 . The system of  claim 11 , wherein the vulnerable system is a misconfigured server system. 
     
     
         14 . The system of  claim 11 , wherein the operations further comprise:
 associating the registered domain name with a server system configured to monitor communication traffic to the registered domain name.   
     
     
         15 . The system of  claim 11 , wherein each domain name is selected from the group consisting of: (i) an unregistered domain name, (ii) a misconfigured domain name, (iii) an abandoned domain name, and (iv) an algorithm-generated domain name. 
     
     
         16 . The system of  claim 11 , wherein receiving communication traffic data comprises:
 receiving communication traffic data from at least one Internet Service Provider (ISP).   
     
     
         17 . The system of  claim 11 , wherein the operations further comprise:
 comparing a relative magnitude of communication traffic to an expected amount of communication traffic.   
     
     
         18 . The system of  claim 11 , wherein receiving communication traffic data comprises:
 measuring a frequency of communication traffic to the domain name.   
     
     
         19 . The system of  claim 11 , wherein the metadata comprises at least one of the group consisting of: (a) geographical location of the communication traffic, (b) frequency of the communication traffic, (c) magnitude of the communication traffic, (d) aggregated counters of a number of unique Internet Protocol (IP) addresses per country, (e) a number of events observed per period, and (f) a ratio of unique IP addresses to a sum of a portion of the communication traffic.

Join the waitlist — get patent alerts

Track US2023269267A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.