IP Library Granted Patent US 9,516,058
Granted Patent B2
US 9,516,058 · App. 13/205,928 · Granted Dec 6, 2016

Method and system for determining whether domain names are legitimate or malicious

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,516,058
App. No.
13/205,928
Granted
Dec 6, 2016
Kind
B2
Abstract

A system and method for determining whether at least one domain is legitimate or malicious by obtaining passive DNS query information, using the passive DNS query information to measure statistical features of known malicious domain names and known legitimate domain names, and using the statistical features to determine at least one reputation for at least one new domain, where the reputation indicates whether the at least one new domain is likely to be for malicious or legitimate uses.

Claims (25)

1. A method of detecting malicious network behavior by teaching at least one reputation engine to determine whether at least one new domain name is likely to be used for malicious or legitimate uses, the method comprising:

obtaining passive domain name system (DNS) query information, utilizing the at least one reputation engine in communication with at least one database, wherein the passive DNS query information is obtained using passive DNS collectors from DNS information;

utilizing, using the at least one reputation engine, the passive DNS query information to measure statistical features of known malicious domain names and known legitimate domain names, wherein the statistical features comprise network-based features and/or zone-based features, the network-based features describing how operators who own the at least one domain name and IP addresses the at least one domain name points to are able to allocate their network resources, and the zone-based features measuring a set of related historic domain names (RHDNs) of domain names historically associated with the at least one new domain name; and

utilizing the statistical features to determine at least one reputation for the at least one new domain name, by teaching the at least one reputation engine to determine whether the at least one new domain name is likely to be used for malicious or legitimate uses, and thus determine if the network communication is malicious or benign.

2. The method of claim 1 , wherein the statistical features also comprise: evidence-based features.

3. The method of claim 1 , wherein the network-based features comprise: border gateway protocol (BGP) features, autonomous system (AS) features, or registration features, or any combination thereof.

4. The method of claim 1 , wherein the zone-based features comprise: string features and/or top level domain (TLD) features.

5. The method of claim 4 , wherein the evidence-based features comprise: honeypot features and/or blacklist features.

6. The method of claim 1 , wherein at least one reputation engine is utilized to determine the at least one reputation for the at least one new domain.

7. The method of claim 6 , wherein the at least one reputation engine comprises: at least one network profile modeling module; at least one network and zone domain name clustering module; or at least one reputation function module; or any combination thereof.

8. The method of claim 7 , wherein the at least one network profile modeling module utilizes multiple classes of domain names.

9. The method of claim 8 , wherein the multiple classes of domain names comprise: popular domain names; common domain names, Akamai domain names, content delivery network (CDN) domain names, or dynamic DNS domain names, or any combination thereof.

10. A system of detecting malicious network behavior by teaching at least one reputation engine to determine whether at least one new domain name is likely to be used for malicious or legitimate uses, the system comprising:

at least one reputation engine in communication with at least one hardware processor and at least one database, the at least one reputation engine configured for:

obtaining passive domain name system (DNS) query information, wherein the passive DNS query information is obtained using passive DNS collectors;

utilizing the passive DNS query information to measure statistical features of known malicious domain names and known legitimate domain names, wherein the statistical features comprise network-based features and/or zone-based features, the network-based features describing how operators who own the at least one domain name and IP addresses the at least one domain name points to are able to allocate their network resources, and the zone-based features measuring a set of related historic domain names (RHDNs) of domain names historically associated with the at least one new domain name; and

utilizing the statistical features to determine at least one reputation for the at least one new domain name, by teaching the at least one reputation engine to determine whether the at least one new domain name is likely to be used for malicious or legitimate uses, and thus determine if the network communication is malicious or benign.

11. The system of claim 10 , wherein the statistical features also comprise: evidence-based features.

12. The system of claim 10 , wherein the network-based features comprise: border gateway protocol (BGP) features, autonomous system (AS) features, or registration features, or any combination thereof.

13. The system of claim 10 , wherein the zone-based features comprise: string features and/or top level domain (TLD) features.

14. The system of claim 13 , wherein the evidence-based features comprise: honeypot features and/or blacklist features.

15. The system of claim 10 , wherein the at least one reputation engine is utilized to determine the at least one reputation for the at least one new domain.

16. The system of claim 15 , wherein the at least one reputation engine comprises: at least one network profile modeling module; at least one network and zone domain name clustering module; or at least one reputation function module; or any combination thereof.

17. The system of claim 16 , wherein the at least one network profile modeling module utilizes multiple classes of domain names.

18. The system of claim 17 , wherein the multiple classes of domain names comprise: popular domain names; common domain names, Akamai domain names, content delivery network (CDN) domain names, or dynamic DNS domain names, or any combination thereof.

Assignments (22)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0861 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: FORTRA, LLC (FORMERLY KNOWN AS HELP/SYSTEMS, LLC)
Reel/Frame 073783/0406 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0911 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERV ICES LLC
To: FORTRA, LLC (F/K/A HELP/SYSTEMS, LLC)
Reel/Frame 073662/0442 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: DAMBALLA, INC.
Reel/Frame 070086/0189 →
CHANGE OF NAME Recorded Dec 15, 2022
From: HELP/SYSTEMS, LLC
To: FORTRA, LLC
Reel/Frame 062136/0777 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0861 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0911 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2019
From: DAMBALLA, INC.
To: HELP/SYSTEMS, LLC
Reel/Frame 048386/0329 →
RELEASE OF SECURITY INTEREST Recorded Feb 8, 2019
From: PNC BANK, NATIONAL ASSOCIATION
To: COURION INTERMEDIATE HOLDINGS, INC.; CORE SECURITY SDI CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; CORE SECURITY LIVE CORPORATION; CORE SECURITY HOLDINGS, INC.; DAMABLLA, INC.
Reel/Frame 048281/0835 →
CONFIRMATORY LICENSE Recorded Mar 26, 2018
From: GEORGIA TECH RESEARCH CORPORATION
To: NAVY, SECRETARY OF THE UNITED STATES OF AMERICA
Reel/Frame 045738/0394 →
RELEASE OF SECURITY INTEREST Recorded Jan 4, 2018
From: SARATOGA INVESTMENT CORP. SBIC LP
To: DAMBALLA, INC.
Reel/Frame 044535/0907 →
SECURITY INTEREST Recorded Dec 27, 2017
From: DAMBALLA, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 044492/0654 →
PATENT SECURITY AGREEMENT Recorded Oct 10, 2016
From: DAMBALLA, INC.
To: SARATOGA INVESTMENT CORP. SBIC LP, AS ADMINISTRATIVE AGENT
Reel/Frame 040297/0988 →
RELEASE OF SECURITY INTEREST Recorded Sep 8, 2016
From: SILICON VALLEY BANK
To: DAMBALLA, INC.
Reel/Frame 039678/0960 →
SECURITY INTEREST Recorded May 14, 2015
From: DAMBALLA, INC.
To: SILICON VALLEY BANK
Reel/Frame 035639/0136 →
CONFIRMATORY LICENSE Recorded Aug 8, 2013
From: GEORGIA TECH RESEARCH CORPORATION
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 030987/0520 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2011
From: ANTONAKAKIS, MANOS; PERDISCI, ROBERTO; DAGON, DAVID; LEE, WENKE
To: DAMBALLA, INC.
Reel/Frame 027087/0919 →