IP Library Granted Patent US 8,869,271
Granted Patent B2
US 8,869,271 · App. 12/698,922 · Granted Oct 21, 2014

System and method for risk rating and detecting redirection activities

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,869,271
App. No.
12/698,922
Granted
Oct 21, 2014
Kind
B2
Abstract

A method in one example implementation includes sending a first request to a first network address on a first server and determining whether the first network address has been redirected on the server to a second network address. The method further includes searching a memory element for a predetermined risk rating associated with the second network address if the first network address has been redirected to the second network address. The method also includes providing a risk response to a client if a predetermined risk rating is found. In more specific embodiments, the risk response includes sending an alert to the client or blocking the client from accessing the second network address if the predetermined risk rating indicates the second network address is malicious. In other more specific embodiments, the first network address is redirected to one or more other network addresses before being redirected to the second network address.

Claims (56)

1. A method, comprising:

receiving, from a client device in a network environment, a first network address to be evaluated;

searching predetermined risk ratings in a memory element for a first predetermined risk rating associated with the first network address;

configuring, when none of the predetermined risk ratings indicates the first network address is malicious, a first request to the first network address to prevent a redirection to another network address from being followed;

sending the first request to the first network address;

determining whether a first response to the first request indicates a first redirection from the first network address to a second network address; and

searching the predetermined risk ratings for a second predetermined risk rating associated with the second network address if the first redirection from the first network address to the second network address is indicated in the first response,

wherein, if the second predetermined risk rating is found and indicates the second network address is malicious, the first redirection is not followed and information is provided to the client device based on the second predetermined risk rating.

2. The method of claim 1 , wherein the providing the information based on the second predetermined risk rating comprises sending an alert to the client device.

3. The method of claim 1 , wherein the client device is blocked from accessing the second network address if the second predetermined risk rating indicates the second network address is malicious.

4. The method of claim 1 , wherein the first response includes a status code indicating whether the first network address has been redirected, wherein the first response includes the second network address if the status code indicates the first network address has been redirected.

5. The method of claim 1 , further comprising:

sending a second request to the second network address hosted on a second server device if the second predetermined risk rating is found and indicates the second network address is trustworthy;

searching the predetermined risk ratings for a third predetermined risk rating associated with a third network address if a second response to the second request indicates a second redirection from the second network address to the third network address, wherein the second redirection is not followed if the third predetermined risk rating is found and indicates the third network address is malicious.

6. The method of claim 1 , further comprising:

sending the second network address to a malware analysis system for determining a new risk rating for the second network address if the memory element does not include a predetermined risk rating associated with the second network address.

7. The method of claim 6 , wherein the malware analysis system updates the memory element with the new risk rating and associates the new risk rating with the second network address.

8. The method of claim 1 , wherein the first network address is a Uniform Resource Locator (URL) link retrieved from a selected one of a group consisting of a web page, a document file, a media file, or a flash file.

9. The method of claim 8 , wherein the URL link is embedded in the web page, the document file, the media file or the flash file.

10. One or more non-transitory tangible media that includes code for execution and when executed by a processor is operable to perform operations comprising:

receiving, from a client device in a network environment, a first network address to be evaluated;

searching predetermined risk ratings in a memory element for a first predetermined risk rating associated with the first network address;

configuring, when none of the predetermined risk ratings indicates the first network address is malicious, a first request to the first network address to prevent a redirection to another network address from being followed;

sending the first request to the first network address;

determining whether a first response to the first request indicates a first redirection from the first network address has to a second network address; and

searching the predetermined risk ratings for a second predetermined risk rating associated with the second network address if the first redirection from the first network address to the second network address is indicated in the first response,

wherein, if the second predetermined risk rating is found and indicates the second network address is malicious, the first redirection is not followed and information is provided to the client device based on the second predetermined risk rating.

11. The one or more non-transitory tangible media of claim 10 , wherein the first response includes a status code indicating whether the first network address has been redirected, wherein the first response includes the second network address if the status code indicates the first network address has been redirected.

12. The one or more non-transitory tangible media of claim 10 , the operations further comprising:

sending a second request to the second network address when the none of the predetermined risk ratings indicates the second network address is malicious; and

searching the predetermined risk ratings for a third predetermined risk rating associated with a third network address if a second response to the second request indicates a second redirection from the second network address to the third network address, wherein the second redirection is not followed if the third predetermined risk rating is found and indicates the third network address is malicious.

13. The one or more non-transitory tangible media of claim 10 , wherein the first network address is a Uniform Resource Locator (URL) link retrieved from a selected one of a group comprising a web page, a document file, a media file, or a flash file.

14. An apparatus, comprising:

a redirection module;

a memory element configured to store one or more network addresses each having an associated risk rating; and

a processor operable to execute instructions associated with the redirection module, including:

receiving, from a client device in a network environment, a first network address to be evaluated;

searching predetermined risk ratings in the memory element for a first predetermined risk rating associated with the first network address;

configuring, when none of the predetermined risk ratings indicates the first network address is malicious, a first request to the first network address to prevent a redirection to another network address from being followed;

sending the first request to the first network address;

determining whether a first response to the first request indicates a first redirection from the first network address to a second network address; and

searching the predetermined risk ratings for a second predetermined risk rating associated with the second network address if the first redirection from the first network address has been redirected to the second network address is indicated in the first response,

wherein, if the second predetermined risk rating is found and indicates the second network address is malicious, the first redirection is not followed and information is provided to the client device based on the second predetermined risk rating.

15. The apparatus of claim 14 , wherein the first response includes a status code indicating whether the first network address has been redirected, wherein the first response includes the second network address if the status code indicates the first network address has been redirected.

16. The apparatus of claim 14 , wherein the processor is operable to perform further instructions, including sending the second network address to a malware analysis system for determining a new risk rating for the second network address if the memory element does not include a predetermined risk rating associated with the second network address.

17. The one or more non-transitory tangible media of claim 10 , the operations further comprising:

sending a second request to the second network address hosted on a second server device if none of the predetermined risk ratings is associated with the second network address;

determining whether a second response to the second request indicates a second redirection from the second network address to a third network address; and

updating the predetermined risk ratings with a new risk rating for the second network address, wherein the new risk rating indicates that the second network address is unknown if the second network address has not been redirected, and wherein the new risk rating indicates that the second network address is malicious if the second response indicates a second redirection from the second network address to the third network address and if the third network address is determined to be malicious.

18. The one or more non-transitory tangible media of claim 10 , the operations further comprising:

updating the predetermined risk ratings to indicate that the first network address is malicious if the second predetermined risk rating indicates the second network address is malicious.

19. The apparatus of claim 14 , wherein the processor is operable to execute further instructions associated with the redirection module, including:

sending a second request to the second network address when the none of the predetermined risk ratings indicates the second network address is malicious; and

searching the predetermined risk ratings for a third predetermined risk rating associated with a third network address if a second response to the second request indicates a second redirection from the second network address to the third network address, wherein the second redirection is not followed if the third predetermined risk rating is found and indicates the third network address is malicious.

20. The apparatus of claim 14 , wherein the processor is operable to execute further instructions associated with the redirection module, including:

updating the predetermined risk ratings to indicate that the first network address is malicious if the second predetermined risk rating indicates the second network address is malicious.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2010
From: JAYARAMAN, SHANKAR; SINGH, VIKAS; SREEDHARAN, JAYESH K.
To: MCAFEE, INC.
Reel/Frame 023888/0001 →