IP Library Granted Patent US 10,419,477
Granted Patent B2
US 10,419,477 · App. 15/352,723 · Granted Sep 17, 2019

Systems and methods for blocking targeted attacks using domain squatting

Inventors: Deepen Desai (San Ramon, CA); Amit Sinha (San Jose, CA)
Assignee: Zscaler, Inc.
H04L63/1483H04L61/1511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,419,477
App. No.
15/352,723
Granted
Sep 17, 2019
Kind
B2
Abstract

Systems and methods for identifying and addressing domains suspected as malicious domains used for targeted attacks in a cloud-based system include receiving valid domains; receiving an unidentified domain; comparing the unidentified domain to the valid domains to derive a distance calculation of the unidentified domain to each of the valid domains; determining whether the unidentified domain is a cybersquatting attempt of one of the valid domains based on the comparing; and, responsive to the determining the unidentified domain is a cybersquatting attempt, one of notifying an operator/user and blocking the unidentified domain in the cloud-based system.

Claims (33)

1. A method for identifying and addressing domains suspected as malicious domains used for targeted attacks in a cloud-based system, the method comprising:

in the cloud-based system, receiving valid domains;

receiving an unidentified domain from a user that is monitored by the cloud-based system such that all Web traffic by the user is monitored by the cloud-based system on a sliding scale between always inline for all Web traffic, somewhat inline for some of the Web traffic, and never inline where the Web traffic is monitored based on Domain Name System (DNS);

comparing the unidentified domain to the valid domains to derive a distance calculation of the unidentified domain to each of the valid domains, wherein the distance calculation is a combination of normalized results from a plurality of distance computations, wherein the plurality of distance are weighted and combined, and wherein weights are dynamically adjusted based on history of detection through the cloud-based system to fine tune detection;

determining whether the unidentified domain is a cybersquatting attempt of one of the valid domains based on the comparing; and

responsive to the determining the unidentified domain is a cybersquatting attempt, notifying an operator/user and blocking the unidentified domain in the cloud-based system.

2. The method of claim 1 , wherein the plurality of distance computations comprise Levenshtein Distance, Sørensen-Dice Coefficient, and Jaccard index.

3. The method of claim 1 , wherein the comparing further comprises analysis of a Top Level Domain (TLD) of the unidentified domain compared to TLDs of the valid domains.

4. The method of claim 1 , wherein the comparing further comprises a determination of whether the unidentified domain was newly registered.

5. The method of claim 1 , wherein the valid domains comprise a top N of domains, N is an integer.

6. The method of claim 1 , wherein the valid domains comprise a specific customer's domain.

7. The method of claim 1 , wherein the unidentified domain is received in the cloud-based system as part of ongoing monitoring.

8. The method of claim 1 , wherein the unidentified domain is received from newly registered domains with a domain registrar.

9. A server in a cloud-based system for identifying and addressing domains suspected as malicious domains used for targeted attacks, the server comprising:

a network interface, a data store, and a processor communicatively coupled to one another, and memory storing computer executable instructions, and in response to execution by the processor, the computer-executable instructions cause the processor to perform steps of

receiving valid domains;

receiving, via the network interface, an unidentified domain from a user that is monitored by the cloud-based system such that all Web traffic by the user is monitored by the cloud-based system on a sliding scale between always inline for all Web traffic, somewhat inline for some of the Web traffic, and never inline where the Web traffic is monitored based on Domain Name System (DNS);

comparing the unidentified domain to the valid domains to derive a distance calculation of the unidentified domain to each of the valid domains, wherein the distance calculation is a combination of normalized results from a plurality of distance computations, wherein the plurality of distance are weighted and combined, and wherein weights are dynamically adjusted based on history of detection through the cloud-based system to fine tune detection;

determining whether the unidentified domain is a cybersquatting attempt of one of the valid domains based on the comparing; and

responsive to the determining the unidentified domain is a cybersquatting attempt, notifying an operator/user and blocking the unidentified domain in the cloud-based system.

10. The server of claim 9 , wherein the plurality of distance computations comprise Levenshtein Distance, Sørensen-Dice Coefficient, and Jaccard index.

11. The server of claim 9 , wherein the comparing further comprises analysis of a Top Level Domain (TLD) of the unidentified domain compared to TLDs of the valid domains.

12. The server of claim 9 , wherein the comparing further comprises a determination of whether the unidentified domain was newly registered.

13. The server of claim 9 , wherein the valid domains comprise a top N of domains, N is an integer.

14. The server of claim 9 , wherein the valid domains comprise a specific customer's domain.

15. The server of claim 9 , wherein the unidentified domain is received in the cloud-based system as part of ongoing monitoring.

16. The server of claim 9 , wherein the unidentified domain is received from newly registered domains with a domain registrar.

17. A non-transitory computer readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

in a cloud-based system, receiving valid domains;

receiving an unidentified domain from a user that is monitored by the cloud-based system such that all Web traffic by the user is monitored by the cloud-based system on a sliding scale between always inline for all Web traffic, somewhat inline for some of the Web traffic, and never inline where the Web traffic is monitored based on Domain Name System (DNS);

comparing the unidentified domain to the valid domains to derive a distance calculation of the unidentified domain to each of the valid domains, wherein the distance calculation is a combination of normalized results from a plurality of distance computations, wherein the plurality of distance are weighted and combined, and wherein weights are dynamically adjusted based on history of detection through the cloud-based system to fine tune detection;

determining whether the unidentified domain is a cybersquatting attempt of one of the valid domains based on the comparing; and

responsive to the determining the unidentified domain is a cybersquatting attempt, notifying an operator/user and blocking the unidentified domain in the cloud-based system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2016
From: DESAI, DEEPEN; SINHA, AMIT
To: ZSCALER, INC.
Reel/Frame 040340/0161 →
Continuity (1)
Related Publication 20180139235A1 · May 17, 2018
Cited By (24)
US 12,192,076 US 12,323,460 US 12,348,525 US 12,477,004 US 12,483,565 US 12,488,058 US 12,495,073 US 12,500,931 US 12,568,096 US 12,572,622 US 12,580,921 US 12,592,930 US 12,592,968 US 12,598,212 US 12,602,450 US 12,609,964 US 12,613,955 US 12,627,629 US 12,647,392 US 12,647,458 US 12,671,716 US 12,676,795 US 12,689,608 US 12,726,516