IP Library Granted Patent US 10,200,405
Granted Patent B2
US 10,200,405 · App. 15/692,980 · Granted Feb 5, 2019

Tokenization of domain names for domain name impersonation detection using matching

Inventor: Michael Schiffman (Henderson, NV)
Assignee: Farsight Security, Inc.
H04L63/1483G06F17/30985H04L41/0631H04L61/10H04L61/1511H04L61/301H04L65/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,200,405
App. No.
15/692,980
Granted
Feb 5, 2019
Kind
B2
Abstract

Systems and methods are described for detecting domain name impersonation in the domain name system (DNS). A nefarious party may register a domain name in the DNS that impersonates a domain name associated with a company in an attempt to lure users to malicious destination network addresses based on their trust of that company. This may lead to the dilution of the company's online presence as its domains come to be associated with malicious activity. In embodiments, a system is described which receives inputs from a subscriber including the domain names the subscriber wishes to protect, ignore, or give special scrutiny to. The system receives instances of domain names registered in the DNS and performs methods to determine if the domain name is attempting to impersonate the domain names of the subscriber. Alerts are generated so that the subscriber may take corrective action.

Claims (32)

1. A method for processing a domain name system (DNS) name string to obtain a plurality of candidate tokens to detect impersonation, comprising:

(a) parsing a DNS name string based on a delimiting character to generate a plurality of labels;

(b) obtaining a plurality of subsets of labels from the plurality of labels, each of the subsets of labels consisting of a number of labels;

(c) concatenating the labels from each of the subset of labels obtained in (b) according to the order the labels appear in the processed DNS name string when read sequentially to generate a plurality of candidate tokens; and

(d) analyzing each candidate token of the plurality of candidate tokens to determine whether the respective candidate token matches a subscriber string associated with a subscriber.

2. The method of claim 1 , further comprising:

(e) detecting the DNS name string as being newly registered with a domain name system, wherein steps (a)-(d) occur when the DNS name string is detected as being newly registered.

3. The method of claim 1 , further comprising:

(e) determining that the DNS name string is not present in a white list associated with the subscriber, wherein steps (a)-(d) occur when the DNS name string is determined to be not present in the white list.

4. The method of claim 1 , wherein the analyzing (d) comprises analyzing at least one candidate token of the plurality of candidate tokens to determine whether the candidate token impersonates any subscriber string from a plurality of subscriber strings.

5. The method of claim 1 , wherein each label in the plurality of labels corresponds to a substring within the processed DNS name string, wherein the substring appears between successive instances of the delimiting character within the processed DNS name string.

6. The method of claim 4 , wherein each subset of labels obtained in (b) comprises labels that appear consecutively, separated by the delimiting character, in the processed DNS name string.

7. The method of claim 1 , wherein the delimiting character is a period character.

8. The method of claim 1 , wherein the analysis (d) is conducted at least in part using a Levenshtein Distance algorithm.

9. The method of claim 1 , wherein the analysis (d) is conducted at least in part using a Homograph algorithm.

10. The method of claim 1 , wherein the analysis (d) is conducted at least in part using an algorithm that looks for phonetic matches between strings.

11. A non-transitory program storage device having instructions stored thereon that, when executed by at least one computing device, causes the at least one computing device to perform a method for determining when at least one of a plurality of candidate tokens from a Domain Name System (DNS) name string is impersonating at least one of a plurality of subscriber strings, the method comprising:

(a) parsing a DNS name string based on a delimiting character to generate a plurality of labels;

(b) obtaining a plurality of subsets of labels from the plurality of labels, each of the subsets of labels consisting of a number of labels;

(c) concatenating the labels from each subset of labels obtained in (b) according to the order the labels appear in the processed DNS name string when read sequentially to generate a plurality of candidate tokens; and

(d) analyzing each candidate token of the plurality of candidate tokens to determine whether the respective candidate token matches a subscriber string associated with a subscriber.

12. The program storage device of claim 11 , the method further comprising:

(e) detecting the DNS name string as being newly registered with a domain name system, wherein steps (a)-(d) occur when the DNS name string is detected as being newly registered.

13. The program storage device of claim 11 , the method further comprising:

(e) determining that the DNS name string is not present in a white list associated with the subscriber, wherein steps (a)-(d) occur when the DNS name string is determined to be not present in the white list.

14. The program storage device of claim 11 , wherein the analyzing (d) comprises analyzing at least one candidate token of the plurality of candidate tokens to determine whether the candidate token impersonates any subscriber string from a plurality of subscriber strings.

15. The program storage device of claim 11 , wherein each label in the plurality of labels corresponds to a substring within the processed DNS name string, wherein the substring appears between successive instances of the delimiting character within the processed DNS name string.

16. The program storage device of claim 14 , wherein each subset of labels obtained in (b) comprises labels that appear consecutively, separated by the delimiting character, in the processed DNS name string.

17. The program storage device of claim 11 , wherein the delimiting character is a period character.

18. The program storage device of claim 11 , wherein the analysis (d) is conducted at least in part using a Levenshtein Distance algorithm.

19. The program storage device of claim 11 , wherein the analysis (d) is conducted at least in part using a Homograph algorithm.

20. The program storage device of claim 11 , wherein the analysis (d) is conducted at least in part using an algorithm that looks for phonetic matches between strings.

Assignments (3)
SECURITY INTEREST Recorded Oct 14, 2025
From: DOMAINTOOLS, LLC; FARSIGHT SECURITY, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 072569/0441 →
SECURITY INTEREST Recorded Feb 22, 2022
From: FARSIGHT SECURITY, INC.
To: SILICON VALLEY BANK
Reel/Frame 059060/0333 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2017
From: SCHIFFMAN, MICHAEL
To: FARSIGHT SECURITY, INC.
Reel/Frame 043474/0383 →
Continuity (3)
Continuation 15598038 · May 17, 2017
Continuation 15598023 · May 17, 2017
Related Publication 20180337947A1 · Nov 22, 2018
Cited By (1)
US 12,278,822