IP Library Granted Patent US 10,382,469
Granted Patent B2
US 10,382,469 · App. 14/805,744 · Granted Aug 13, 2019

Domain age registration alert

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,469
App. No.
14/805,744
Granted
Aug 13, 2019
Kind
B2
Abstract

Systems and methods of identifying a security risk by monitoring and generating alerts based on attempts to access web domains that have been registered within a short period of time and are therefore identified as “high-risk,” including identifying an attempt to access a domain; receiving a registration date of the domain; and detecting a security risk based on the registration date of the domain.

Claims (36)

1. A method for identifying a network security risk, the method comprising:

generating, using a web filter, a web activity log comprising at least one domain that is the subject of a request via the internet for information and an access date associated with the request, wherein the request is made by a pseudo account created with credentials that are not assigned to a user and stored in a database of known pseudo accounts and known accounts of authorized users, wherein the pseudo account is an account that has been inactive for a determined threshold period of time or an account that has been marked for deletion;

requesting domain age data for the at least one domain using a router device;

receiving a registration date of the at least one domain from a database module;

identifying, using a management console, a domain in the web activity log as a security risk based on the time lapsed between the access date associated with the request for the identified domain and the registration date of the domain being less than a predetermined threshold and based on the request being made by the pseudo account created with credentials that are not assigned to a user; and

restricting access to the domain identified as a security risk using the web filter based on the time lapsed between the access date associated with the request for the identified domain and the registration date of the domain being less than a predetermined threshold and based on the request being made by the pseudo account created with credentials that are not assigned to a user; and

communicating data regarding the pseudo account activity to an account mapping system configured to track pseudo account activity to an account of an authorized user, wherein the account mapping system is in communication with the database of known pseudo accounts and known accounts of authorized users;

tracking the activity associated with the pseudo account to an account of an authorized user; and

performing at least one of:

implementing a security policy update based on the pseudo account being tracked to the account of an authorized user, and

enforcing a security policy based on the pseudo account being tracked to the account of an authorized user.

2. The method of claim 1 , wherein the request for information includes a domain name system (DNS) request.

3. The method of claim 1 , wherein receiving the registration date of the at least one domain comprises querying a database for the date of registration of the at least one domain.

4. The method of claim 1 , further comprising generating an alert based on an identified security risk.

5. The method of claim 1 , further comprising mitigating the identified security risk.

6. A system for identifying a security risk, the system comprising:

one or more computer readable storage media configured as a database module of registration information for a plurality of domains;

one or more hardware processors coupled with the one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media that, when read and executed by the one or more hardware processors, direct the system to implement:

a web filter configured to generate a web activity log comprising at least one domain that is the subject of a request via the internet for information and an access date associated with the request, wherein the request is made by a pseudo account created with credentials that are not assigned to a user and stored in a database of known pseudo accounts and known accounts of authorized users, wherein the pseudo account is an account that has been inactive for a threshold period of time or an account that has been marked for deletion; and

a management console configured to, retrieve a registration date of at least one domain in the web activity log from the database module, and identify a domain in the web activity log as a security risk based on the time lapsed between the access date associated with the identified domain and the registration date of the domain being less than a predetermined threshold and based on the request being made by the pseudo account created with credentials that are not assigned to a user,

wherein the web filter is further configured to restrict access to the domain identified as a security risk using the web filter based on the time lapsed between the access date associated with the request for the identified domain and the registration date of the domain being less than a predetermined threshold and based on the request being made by the pseudo account created with credentials that are not assigned to a user; and

an account mapping system in communication with the database of known pseudo accounts and known accounts of authorized users and configured to:

track pseudo account activity to an account of an authorized user,

track the activity associated with the pseudo account to an account of an authorized user, and

perform at least one of: implementing a security policy update based on the pseudo account being tracked to the account of an authorized user, and enforcing a security policy based on the pseudo account being tracked to the account of an authorized user.

7. The system according to claim 6 , wherein the request for information includes a domain name system request.

8. The system according to claim 6 , wherein the database module is a public database.

9. The system according to claim 6 , wherein the database module is a private database.

10. The system according to claim 6 , wherein the management console is further configured to generate an alert based on the identified security risk.

11. The system according to claim 6 , wherein the management console is further configured to initiate mitigation steps based on the identified security risk.

12. The system according to claim 6 , wherein the management console is a proxy server.

13. The system according to claim 6 , wherein the database module and the management console are co-located on the same network.

14. The system according to claim 6 , wherein the management console is further configured to associate at least one user with the identified security risk is identified based on an authentication record in the database module.

15. The system according to claim 6 , wherein the web activity log includes at least one device label to identify a network asset, wherein the at least one device label is a domain name or an Internet Protocol address.

16. The system according to claim 14 , wherein the authentication record is an active directory log.

Assignments (6)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2018
From: ADAMS, SAMUEL
To: RAPID7, INC.
Reel/Frame 047649/0184 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2018
From: MOORE, H.D.
To: RAPID7, INC.
Reel/Frame 047543/0840 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2018
From: MOORE, H.D.
To: INC., RAPID7, INC.
Reel/Frame 047451/0093 →
Cited By (1)
US 12,450,370