IP Library Granted Patent US 7,559,085
Granted Patent B1
US 7,559,085 · App. 10/917,714 · Granted Jul 7, 2009

Detection for deceptively similar domain names

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,559,085
App. No.
10/917,714
Granted
Jul 7, 2009
Kind
B1
Abstract

A system including a client configured to obtain a target domain name and an Internet service configured to translate the target domain name into a target identifier and compare the target identifier to a domain name table to obtain a similarity list.

Claims (60)

1. A system comprising:

a local domain name server configured to receive a target domain name from a client and send the target domain name to an Internet service; and

the Internet service comprising a domain name table, wherein the domain name table comprises a plurality of domain names and wherein each of the plurality of domain names is associated with a pre-computed target identifier,

wherein the Internet service is configured to:

receive the target domain name from the local domain name service,

translate the target domain name into a target identifier,

compare the target identifier to the plurality of domain names in the domain name table to obtain a similarity list,

wherein the similarity list comprises at least one of the plurality of domain names,

wherein the pre-computed target identifier associated with at least one of the plurality of domain names is equal to the target identifier,

wherein the target identifier comprises a similarity code for each character in the target domain name,

wherein the similarity code is based on similarity of appearance of each character in a low resolution font,

wherein a first character is assigned the same similarity code as a second character when similar in appearance in the low resolution font, and

wherein the target identifier is the same as the pre-computed target identifier of the at least one of the plurality of domain names when both domain names are similar in appearance in the low resolution font; and

send the similarity list to the local domain name server, wherein the local domain name server sends the similarity list to the client, and wherein the client is configured to display the similarity list to a user.

2. The system of claim 1 , wherein the local domain name server is further configured to obtain a target domain name record corresponding to the target domain name and aggregate the target domain name record with the similarity list in a response to the client.

3. The system of claim 1 , wherein the domain name table is periodically updated.

4. The system of claim 1 , wherein the Internet service further comprises frequency information, wherein the frequency information is periodically updated.

5. The system of claim 1 , wherein the similarity code for each character in the target domain name is concatenated to form the target identifier.

6. The system of claim 1 , wherein the Internet service is further configured to store the similarity code.

7. The system of claim 1 , wherein the similarity list further comprises frequency information associated with the at least one of the plurality of domain names.

8. A method for detecting deceptive domain names comprising:

obtaining a target domain name;

translating the target domain name to obtain a target identifier,

wherein the target identifier comprises a similarity code for each character in the target domain name,

wherein the similarity code is based on similarity of appearance of each character in a low resolution font, and

wherein a first character is assigned the same similarity code as a second character when similar in appearance in the low resolution font;

comparing the target identifier to a plurality of domain names in a domain name table to obtain a similarity list,

wherein each of the plurality of domain names is associated with a pre-computed target identifier,

wherein the pre-computed target identifier associated with at least one of the plurality of domain names is equal to the target identifier, and

wherein the target identifier is the same as the pre-computed target identifier of the at least one of the plurality of domain names when both domain names are similar in appearance in the low resolution font, and wherein the similarity list comprises at least one of the plurality of domain names; and

determining whether the target domain name is deceptive using the similarity list.

9. The method of claim 8 , further comprising:

resolving the target domain name to obtain a target domain name server record;

aggregating the target domain name server record with the similarity list; and

forwarding a response to a client.

10. The method of claim 9 , wherein the client is configured to display the similarity list to a user.

11. The method of claim 9 , wherein the target domain name server record may be obtained from a root domain name server.

12. The method of claim 9 , wherein the target domain name server record may be cached in a local domain name server.

13. The method of claim 8 , wherein the domain name table comprises at least one domain name and an identifier corresponding to the domain name.

14. The method of claim 8 , wherein the similarity code for each character in the target domain name is concatenated to form the target identifier.

15. A computer system for detecting deceptive domain names comprising:

a processor;

a memory;

a storage device; and

software instructions stored in the memory for enabling the computer system under control of the processor, to:

obtain a target domain name;

translate the target domain name to obtain a target identifier,

wherein the target identifier comprises a similarity code for each character in the target domain name,

wherein the similarity code is based on similarity of appearance of each character in a low resolution font, and

wherein a first character is assigned the same similarity code as a second character when similar in appearance in the low resolution font;

compare the target identifier to a plurality of domain names in a domain name table to obtain a similarity list,

wherein each of the plurality of domain names is associated with a pre-computed target identifier,

wherein the pre-computed target identifier associated with at least one of the plurality of domain names is equal to the target identifier, and

wherein the target identifier is the same as the pre-computed target identifier of the at least one of the plurality of domain names when both domain names are similar in appearance in the low resolution font, and wherein the similarity list comprises at least one of the plurality of domain names; and

determine whether the target domain name is deceptive using the similarity list.

16. The computer system of claim 15 , further comprising software instructions stored in the memory for enabling the computer system under control of the processor, to:

resolve the target domain name to obtain a target domain name server record;

aggregate the target domain name server record with the similarity list; and

forward a response to the client.

17. The computer system of claim 15 , wherein the similarity code for each character in the target domain name is concatenated to form the target identifier.

Assignments (2)
MERGER AND CHANGE OF NAME Recorded Dec 16, 2015
From: ORACLE USA, INC.; SUN MICROSYSTEMS, INC.; ORACLE AMERICA, INC.
To: ORACLE AMERICA, INC.
Reel/Frame 037304/0183 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2004
From: WAHL, MARK F.
To: SUN MICROSYSTEMS, INC.
Reel/Frame 015690/0719 →