IP Library Granted Patent US 10,027,688
Granted Patent B2
US 10,027,688 · App. 12/538,612 · Granted Jul 17, 2018

Method and system for detecting malicious and/or botnet-related domain names

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,027,688
App. No.
12/538,612
Granted
Jul 17, 2018
Kind
B2
Abstract

A method and system of detecting a malicious and/or botnet-related domain name, comprising: reviewing a domain name used in Domain Name System (DNS) traffic in a network; searching for information about the domain name, the information related to: information about the domain name in a domain name white list and/or a domain name suspicious list; and information about the domain name using an Internet search engine, wherein the Internet search engine determines if there are no search results or search results with a link to at least one malware analysis site; and designating the domain name as malicious and/or botnet-related based on the information.

Claims (46)

1. A method of detecting at least one malicious and/or botnet-related domain name, comprising:

performing processing associated with collecting at least one domain name by monitoring Domain Name System (DNS) traffic in at least one network;

performing processing associated with obtaining, during a time period, information about the at least one domain name, comprising determining if the at least one domain name is in at least one domain name white list;

wherein the obtained information further comprises statistics related to the at least one domain name comprising a total number of queries to the at least one domain name during the time period and a total number of distinct source IP addresses that queried the at least one domain name during the time period;

responsive to determining that the at least one domain name is not in the at least one domain name white list, performing processing associated with automatically obtaining, using at least one Internet search engine, search results for the at least one domain name;

performing processing associated with analyzing the search results to determine whether at least one search result associated with the at least one domain name comprises a known malware site; and

performing processing associated with classifying the at least one domain name as at least one of malicious, suspicious, and legitimate based on the analyzed search results.

2. The method of claim 1 , further comprising, calculating a suspiciousness score based on the total number of queries to the at least one domain name during the time period and the total number of distinct source IP addresses that queried the at least one domain name during the time period,

wherein the classifying the at least one domain name as at least one of malicious, suspicious, and legitimate is further based on the suspiciousness score.

3. The method of claim 1 , wherein the at least one domain name to be monitored is part of at least one sample chosen from a plurality of domain names; and

wherein a size of the at least one sample is based on a probability factor.

4. The method of claim 3 , further comprising generating a pseudorandom number;

wherein the at least one domain name is not selected for monitoring if the probability factor is less than the pseudorandom number.

5. The method of claim 2 , wherein the at least one domain name is ranked based on the suspiciousness score, and

wherein the classifying the at least one domain name as at least one of malicious, suspicious, and legitimate is further based the ranking being above a predetermined threshold.

6. The method of claim 1 , wherein the obtained information further comprises performing at least one reverse lookup on the at least one domain name.

7. The method of claim 1 , wherein the at least one domain name to be monitored is filtered.

8. The method of claim 1 , wherein the at least one domain name to be monitored is filtered by determining if a second level domain (2LD) of the at least one domain name is in at least one domain name white list.

9. The method of claim 8 , wherein the at least one domain name to be monitored is further filtered by determining if a top level domain (TLD) of the at least one domain name is in at least one domain name suspicious list.

10. The method of claim 9 , wherein the at least one domain name to be monitored is further filtered by determining if the second level domain (2LD) of the at least one domain name is in a Dynamic Domain Name System (DDNS) 2LD suspicious list.

11. The method of claim 1 , wherein the obtained information further comprises:

determining whether a resolved IP address of the at least one domain name is that of at least one DSL or at least one dial-up connection; and/or

determining a geographic location of the at least one resolved IP address, at least one Autonomous System (AS) number, or at least one AS name.

12. A computerized system for performing malware analysis on at least one guest environment, the system comprising:

at least one server coupled to at least one network;

at least one user terminal coupled to the at least one network;

at least one application coupled to the at least one server and/or the at least one user terminal, wherein the at least one application is configured for:

performing processing associated with collecting at least one domain name by monitoring Domain Name System (DNS) traffic in at least one network;

performing processing associated with obtaining information about the at least one domain name, wherein the information is utilized to classify the at least one domain name, and the information is information about the at least one domain name in at least one domain name white list;

wherein the obtained information further comprises statistics related to the at least one domain name comprising a total number of queries to the at least one domain name during the time period and a total number of distinct source IP addresses that queried the at least one domain name during the time period;

responsive to determining that the at least one domain name is not in the at least one domain name white list, performing processing associated with automatically obtaining, using at least one Internet search engine, search results for the at least one domain name;

performing processing associated with analyzing the search results to determine whether at least one search result associated with the at least one domain name comprises a known malware site; and

performing processing associated with determining at least one likelihood that the at least one domain name is being used as at least one command and control domain for at least one botnet based at least in part on the analyzed search results.

13. The system of claim 12 , wherein the at least one domain name is monitored and statistics are gathered related to the at least one domain name.

14. The system of claim 13 , wherein the at least one domain name to be monitored is part of at least one sample chosen from a plurality of domain names.

15. The system of claim 12 , wherein the at least one domain name is further classified as malicious or suspicious based on the analyzed search results.

16. The system of claim 12 , wherein the at least one domain name is ranked based on probabilities related to at least one of how malicious the at least one domain name is and how botnet-related the at least one domain name is,

wherein the determining at least one likelihood that the at least one domain name is being used as at least one command and control domain for at least one botnet is based on the rank.

17. The system of claim 12 , wherein the information further comprises performing at least one reverse lookup on the at least one domain name.

18. The system of claim 12 , wherein the at least one domain name to be monitored is filtered.

19. The system of claim 12 , wherein the at least one domain name to be monitored is filtered by determining if a second level domain (2LD) of the at least one domain name is in at least one domain name white list.

20. The system of claim 19 , wherein the at least one domain name to be monitored is further filtered by determining if a top level domain (TLD) of the at least one domain name is in at least one domain name suspicious list.

21. The system of claim 20 , wherein the at least one domain name to be monitored is further filtered by determining if the second level domain (2LD) of the at least one domain name is in a Dynamic Domain Name System (DDNS) 2LD suspicious list.

22. The system of claim 12 , wherein the information is related to at least one of:

information regarding whether or not a resolved IP address of the at least one domain name is that of at least one DSL or at least one dial-up connection; and

information on geographic location of the at least one resolved IP address, at least one Autonomous System (AS) number, or at least one AS name.

Assignments (20)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0861 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: FORTRA, LLC (FORMERLY KNOWN AS HELP/SYSTEMS, LLC)
Reel/Frame 073783/0406 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0911 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERV ICES LLC
To: FORTRA, LLC (F/K/A HELP/SYSTEMS, LLC)
Reel/Frame 073662/0442 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: DAMBALLA, INC.
Reel/Frame 070086/0189 →
CHANGE OF NAME Recorded Dec 15, 2022
From: HELP/SYSTEMS, LLC
To: FORTRA, LLC
Reel/Frame 062136/0777 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0911 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0861 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2019
From: DAMBALLA, INC.
To: HELP/SYSTEMS, LLC
Reel/Frame 048386/0329 →
RELEASE OF SECURITY INTEREST Recorded Feb 8, 2019
From: PNC BANK, NATIONAL ASSOCIATION
To: COURION INTERMEDIATE HOLDINGS, INC.; CORE SECURITY SDI CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; CORE SECURITY LIVE CORPORATION; CORE SECURITY HOLDINGS, INC.; DAMABLLA, INC.
Reel/Frame 048281/0835 →
RELEASE OF SECURITY INTEREST Recorded Jan 4, 2018
From: SARATOGA INVESTMENT CORP. SBIC LP
To: DAMBALLA, INC.
Reel/Frame 044535/0907 →
SECURITY INTEREST Recorded Dec 27, 2017
From: DAMBALLA, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 044492/0654 →
PATENT SECURITY AGREEMENT Recorded Oct 10, 2016
From: DAMBALLA, INC.
To: SARATOGA INVESTMENT CORP. SBIC LP, AS ADMINISTRATIVE AGENT
Reel/Frame 040297/0988 →
RELEASE OF SECURITY INTEREST Recorded Sep 8, 2016
From: SILICON VALLEY BANK
To: DAMBALLA, INC.
Reel/Frame 039678/0960 →
SECURITY INTEREST Recorded May 14, 2015
From: DAMBALLA, INC.
To: SILICON VALLEY BANK
Reel/Frame 035639/0136 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2009
From: PERDISCI, ROBERTO; LEE, WENKE
To: DAMBALLA, INC.
Reel/Frame 023305/0708 →
Cited By (4)
US 12,267,369 US 12,309,116 US 12,388,777 US 12,506,772