METHOD AND SYSTEM FOR DOMAIN MALICIOUSNESS ASSESSMENT VIA REAL-TIME GRAPH INFERENCE

Mohamed Nabeel (Inventor), Issa M Khalil (Inventor), Ting Yu (Inventor), Eui J Choo (Inventor), Euijin Choo (Inventor)

Research output: Patent

Abstract

The presently disclosed method and system exploits information and traces contained in DNS data to determine the maliciousness of a domain based on the relationship it has with other domains. A method may comprise providing data to a machine learning module that was previously trained on domain and IP address attributes or classifiers. The method then may comprise classifying apex domains and IP addresses based on the IP address and domain attributes or classifiers. Additionally, the method may comprise associated each of the domains and IP addresses based on the corresponding classification. The method may further comprise building a weighted domain graph at real-time utilizing the DNS data based on the aforementioned associations among domains. The method may then comprise assessing the maliciousness of a domain based on the weighted domain graph that was built.

Original languageEnglish
Patent numberUS2020382533
IPCH04L 29/ 12 A I
Priority date30/05/19
Publication statusPublished - 3 Dec 2020

Fingerprint

Dive into the research topics of 'METHOD AND SYSTEM FOR DOMAIN MALICIOUSNESS ASSESSMENT VIA REAL-TIME GRAPH INFERENCE'. Together they form a unique fingerprint.

Cite this