Systems and methods for generating lookalike Uniform Resource Locators (URLs) based on penalty-based genetic algorithms
Systems and methods for generating and utilizing lookalike Uniform Resource Locators (URLs) include receiving an original target domain; generating a first generation of lookalike domains based on the original target domain and a plurality of deception methods; generating a penalty value for each of a plurality of lookalike domains in the first generation of lookalike domains; generating subsequent generations of lookalike domains and penalty values therefor based on penalty values associated with each of a plurality of lookalike domains in a preceding generation of lookalike domains; and repeating the steps for an N number of generations.
1 . A method comprising steps of:
receiving an original target domain;
generating a first generation of lookalike domains based on the original target domain and a plurality of deception methods;
for each of the plurality of lookalike domains in the first generation, generating a penalty value comprising:
generating a deception penalty for each deception in the lookalike domain;
generating a positional coefficient for each deception in the lookalike domain;
determining a positional penalty for each character in the lookalike domain based on the deception penalty and positional coefficient; and
determining the penalty value of the lookalike domain based on the one or more positional penalties and a collective penalty applied to the lookalike domain as a whole;
generating subsequent generations of lookalike domains and penalty values therefor based on penalty values associated with each of a plurality of lookalike domains in a preceding generation of lookalike domains; and
repeating the steps for an N number of generations,
wherein the penalty value for each of the plurality of lookalike domains in subsequent generations is based on inherited positional penalties from its parents and a newly determined collective penalty independent of collective penalties of the parents.
2 . The method of claim 1 , wherein the collective penalty is based on at least one of: presence of non-Latin characters, excessive length, or more than one hyphen in the lookalike domain.
3 . The method of claim 1 , wherein the generating includes utilizing a genetic algorithm to generate the plurality of lookalike domains.
4 . The method of claim 1 , wherein each of the lookalike domains in the first generation of lookalike domains include a deception method therein.
5 . The method of claim 1 , wherein the collective penalty of an offspring lookalike domain is independent of the collective penalties of its parents.
6 . The method of claim 1 , wherein generating subsequent generations of lookalike domains further comprises:
selecting a set of parents from a preceding generation of lookalike domains based on their penalty values; and
generating the subsequent generation of lookalike domains based thereon.
7 . The method of claim 6 , wherein the selecting of parents is based on penalty values determined from both positional penalties and collective penalties.
8 . The method of claim 6 , wherein the selecting and generating are repeated until no penalty value of a lookalike domain in a subsequent generation of lookalike domains is below a threshold.
9 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:
receiving an original target domain;
generating a first generation of lookalike domains based on the original target domain and a plurality of deception methods;
for each of the plurality of lookalike domains in the first generation, generating a penalty value comprising:
generating a deception penalty for each deception in the lookalike domain;
generating a positional coefficient for each deception in the lookalike domain;
determining a positional penalty for each character in the lookalike domain based on the deception penalty and positional coefficient; and
determining the penalty value of the lookalike domain based on the one or more positional penalties and a collective penalty applied to the lookalike domain as a whole;
generating subsequent generations of lookalike domains and penalty values therefor based on penalty values associated with each of a plurality of lookalike domains in a preceding generation of lookalike domains; and
repeating the steps for an N number of generations,
wherein the penalty value for each of the plurality of lookalike domains in subsequent generations is based on inherited positional penalties from its parents and a newly determined collective penalty independent of collective penalties of the parent.
10 . The non-transitory computer-readable medium of claim 9 , wherein the collective penalty is based on at least one of: presence of non-Latin characters, excessive length, or more than one hyphen in the lookalike domain.
11 . The non-transitory computer-readable medium of claim 9 , wherein the generating includes utilizing a genetic algorithm to generate the plurality of lookalike domains.
12 . The non-transitory computer-readable medium of claim 9 , wherein each of the lookalike domains in the first generation of lookalike domains include a deception method therein.
13 . The non-transitory computer-readable medium of claim 9 , wherein the collective penalty of an offspring lookalike domain is independent of the collective penalties of its parents.
14 . The non-transitory computer-readable medium of claim 9 , wherein generating subsequent generations of lookalike domains further comprises:
selecting a set of parents from a preceding generation of lookalike domains based on their penalty values; and
generating the subsequent generation of lookalike domains based thereon.
15 . The non-transitory computer-readable medium of claim 14 , wherein the selecting of parents is based on penalty values determined from both positional penalties and collective penalties.
16 . The non-transitory computer-readable medium of claim 14 , wherein the selecting and generating are repeated until no penalty value of a lookalike domain in a subsequent generation of lookalike domains is below a threshold.