IP Library Granted Patent US 10,089,411
Granted Patent B2
US 10,089,411 · App. 14/494,761 · Granted Oct 2, 2018

Method and apparatus and computer readable medium for computing string similarity metric

Inventor: Debish Fesehaye Kassa (Champaign, IL)
Assignee: NEUSTAR INC.
G06F17/30985
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,089,411
App. No.
14/494,761
Granted
Oct 2, 2018
Kind
B2
Abstract

A string similarity apparatus, method, and computer readable medium which manages caching of resources. The method includes storing a plurality of software instructions, executing the plurality of software instructions, such as, determining a first number of characters contained by a first string, determining a second number of characters contained by a second string, determining a larger number from among the first number and the second number, setting the larger number to a string length value, determining a maximum number of subsequent characters from the first strings which match subsequent characters from the second string and setting the value, setting the maximum number to a maximum group size value, calculating a resulting value by subtracting the maximum group size value from the string length value, and outputting the resulting value which represents a computational cost of converting the first string into the second string.

Claims (28)

1. A string similarity apparatus arranged to detect a malicious domain name, the string similarity apparatus comprising:

a memory configured to store a plurality of instructions; and

a processor configured to execute the plurality of instructions to perform operations including:

receiving a uniform resource locator (URL) having a domain name character string;

comparing, using the processor, the received domain name character string to a first dataset of non-malicious domain names and a second dataset of malicious domain names, the first and second datasets having respective first dataset and second dataset domain name character strings;

deriving, using the processor, compute-distance string similarity values for the received domain name character string relative to the first dataset and the second dataset, the compute-distance string similarity values based on a computational cost of a distance, from each of the first dataset and the second dataset domain name character strings, of the received domain name character string due to an insertion of a character into or a deletion of a character from the middle of the received domain name character string, including the cost of shifting characters of the received domain name character string as a result of the insertion or deletion; and

detecting, using the processor, the received domain name character string as one of malicious and non-malicious based on the compute-distance string similarity values.

2. The string similarity apparatus of claim 1 , wherein detecting the received domain name character string as malicious is based on a minimum of the compute-distance string similarity values to the second dataset domain name character strings.

3. The string similarity apparatus of claim 2 , the plurality of instructions further comprising adding the received domain name character string to a database of malicious domain names, the database including the second dataset.

4. The string similarity apparatus of claim 1 , wherein detecting the received domain name character string as non-malicious is based on a minimum of the compute-distance string similarity values to the first dataset domain name character strings.

5. The string similarity apparatus of claim 4 , the plurality of instructions further comprising adding the received domain name character string to a database of non-malicious domain names, the database including the first dataset.

6. The string similarity apparatus of claim 1 , wherein the first and second datasets are stored in the memory.

7. The string similarity apparatus of claim 1 , the plurality of instructions further comprising transmitting the received domain name character string detected as the one of malicious and non-malicious via a network to a user apparatus.

8. A method of detecting a malicious domain name, the method comprising:

receiving a uniform resource locator (URL) having a domain name character string;

comparing the received domain name character string to a first dataset of non-malicious domain names and a second dataset of malicious domain names, the first and second datasets having respective first dataset and second dataset domain name character strings;

deriving compute-distance string similarity values for the received domain name character string relative to the first dataset and the second dataset, the compute-distance string similarity values based on a computational cost of a distance, from each of the first dataset and the second dataset domain name character strings, of the received domain name character string due to an insertion of a character into or a deletion of a character from the middle of the received domain name character string, including the cost of shifting characters of the received domain name character string as a result of the insertion or deletion; and

detecting the received domain name character string as one of malicious and non-malicious based on the compute-distance string similarity values.

9. The method of claim 8 , wherein detecting the received domain name character string as malicious is based on a minimum of the compute-distance string similarity values to the second dataset domain name character strings.

10. The method of claim 9 , further comprising adding the received domain name character string to a database of malicious domain names, the database including the second dataset.

11. The method of claim 8 , wherein detecting the received domain name character string as non-malicious is based on a minimum of the compute-distance string similarity values to the first dataset domain name character strings.

12. The method of claim 11 , further comprising adding the received domain name character string to a database of non-malicious domain names, the database including the first dataset.

13. The method of claim 8 , further comprising transmitting the received domain name character string detected as the one of malicious and non-malicious via a network to a user apparatus.

14. A non-transitory computer-readable medium that stores instructions, executable by one or more processors, to cause the one or more processors to perform operations that comprise:

receiving a uniform resource locator (URL) having a domain name character string;

comparing the received domain name character string to a first dataset of non-malicious domain names and a second dataset of malicious domain names, the first and second datasets having respective first dataset and second dataset domain name character strings;

deriving compute-distance string similarity values for the received domain name character string relative to the first dataset and the second dataset, the compute-distance string similarity values based on a computational cost of a distance, from each of the first dataset and the second dataset domain name character strings, of the received domain name character string due to an insertion of a character into or a deletion of a character from the middle of the received domain name character string, including the cost of shifting characters of the received domain name character string as a result of the insertion or deletion; and

detecting the received domain name character string as one of malicious and non-malicious based on the compute-distance string similarity values.

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 058294, FRAME 0161 Recorded Dec 27, 2021
From: JPMORGAN CHASE BANK, N.A.
To: EBUREAU, LLC; IOVATION, INC.; SIGNAL DIGITAL, INC.; TRANS UNION LLC; TRANSUNION INTERACTIVE, INC.; TRANSUNION RENTAL SCREENING SOLUTIONS, INC.; TRANSUNION TELEDATA LLC; AGGREGATE KNOWLEDGE, LLC; TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
Reel/Frame 058593/0852 →
SECOND LIEN PATENT SECURITY AGREEMENT RELEASE Recorded Dec 3, 2021
From: UBS AG, STAMFORD BRANCH
To: NEUSTAR, INC.; MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.
Reel/Frame 058300/0739 →
FIRST LIEN PATENT SECURITY AGREEMENT RELEASE Recorded Dec 3, 2021
From: BANK OF AMERICA, N.A.
To: NEUSTAR, INC.; MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.
Reel/Frame 058300/0762 →
SECURITY INTEREST Recorded Aug 22, 2017
From: MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.; NEUSTAR, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 043633/0440 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Aug 22, 2017
From: MARKETSHARE PARTNERS LLC; AGGREGATE KNOWLEDGE, INC.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR IP INTELLIGENCE, INC.; NEUSTAR, INC.
To: UBS AG, STAMFORD BRANCH
Reel/Frame 043633/0527 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2014
From: KASSA, DEBESSAY FESEHAYE
To: NEUSTAR, INC.
Reel/Frame 033806/0162 →
Continuity (2)
Provisional Application 61923097 · Jan 2, 2014
Related Publication 20150186502A1 · Jul 2, 2015
Cited By (4)
US 12,430,646 US 12,445,410 US 12,455,978 US 12,683,984