IP Library Granted Patent US 10,637,875
Granted Patent B2
US 10,637,875 · App. 15/951,361 · Granted Apr 28, 2020

Automated classification of domain names resolved by malware

Inventor: Erik M. Heuser (Manassas, VA)
Assignee: EMC IP Holding Company LLC
H04L63/1416H04L61/1511H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,637,875
App. No.
15/951,361
Granted
Apr 28, 2020
Kind
B2
Abstract

Techniques are provided for automated classification of domain names resolved by malware. An exemplary method comprises obtaining a domain name included in malware domain resolution requests; obtaining a domain table identifying a plurality of known domains; obtaining a dynamic domain table identifying a plurality of dynamic Domain Name System domains; parsing a full domain name associated with the domain name from the malware domain resolution requests into a Top Level Domain and a Domain; classifying the domain from the malware domain resolution requests name as a dynamic Domain Name System domain if the Top Level Domain and the Domain are found in the dynamic domain table; and storing the classification of the domain name from the malware domain resolution requests as the dynamic Domain Name System domain in the domain table with a complete domain of the domain, a current date and time and a Time-To-Live attribute of the domain from a response of the Domain Name System.

Claims (40)

1. A method, comprising:

obtaining at least one domain name included in one or more malware domain resolution requests;

obtaining a domain table identifying a plurality of known domains in a domain name system;

obtaining a dynamic domain table identifying a plurality of domains classified as a dynamic domain name system domain in a dynamic domain name system;

parsing a full domain name associated with said at least one domain name from said one or more malware domain resolution requests into a top level domain and a domain;

classifying said at least one domain name from said one or more malware domain resolution requests as a dynamic domain name system domain in the dynamic domain name system when said top level domain and said domain are found in said dynamic domain table; and

storing said classification of said at least one domain name from said one or more malware domain resolution requests as said dynamic domain name system domain in said domain table with a complete domain of said at least one domain, a current date and time and a Time-To-Live attribute of said at least one domain from a response of the domain name system.

2. The method of claim 1 , further comprising the steps of obtaining a whitelist table identifying a plurality of trusted domains, and classifying said at least one domain name as a trusted domain if said top level domain and said domain are found in said whitelist table.

3. The method of claim 2 , further comprising the step of classifying said at least one domain name as an uncategorized domain if said top level domain and said domain are not found in said dynamic domain table and said whitelist table.

4. The method of claim 1 , further comprising the step of automatically re-classifying said domain and wherein all sub-domains of the domain are re-categorized to match the domain and top level domain of the re-classified domain.

5. The method of claim 1 , further comprising the step of monitoring communications of malware to obtain said one or more domain resolution requests.

6. The method of claim 1 , further comprising the step of automatically reclassifying a given one of said known domains in said domain table such that all sub-domains of the reclassified known domain are updated to match the top level domain and the domain of said reclassified known domain.

7. The method of claim 1 , wherein the one or more malware domain resolution requests are obtained from a sandbox execution environment.

8. A computer program product, comprising a non-transitory machine-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device perform the following steps:

obtaining at least one domain name included in one or more malware domain resolution requests;

obtaining a domain table identifying a plurality of known domains in a domain name system;

obtaining a dynamic domain table identifying a plurality of domains classified as a dynamic domain name system domain in a dynamic domain name system;

parsing a full domain name associated with said at least one domain name from said one or more malware domain resolution requests into a top level domain and a domain;

classifying said at least one domain name from said one or more malware domain resolution requests as a dynamic domain name system domain in the dynamic domain name system when said top level domain and said domain are found in said dynamic domain table; and

storing said classification of said at least one domain name from said one or more malware domain resolution requests as said dynamic domain name system domain in said domain table with a complete domain of said at least one domain, a current date and time and a Time-To-Live attribute of said at least one domain from a response of the domain name system.

9. The computer program product of claim 8 , further comprising the steps of obtaining a whitelist table identifying a plurality of trusted domains, and classifying said at least one domain name as a trusted domain if said top level domain and said domain are found in said whitelist table.

10. The computer program product of claim 9 , further comprising the step of classifying said at least one domain name as an uncategorized domain if said top level domain and said domain are not found in said dynamic domain table and said whitelist table.

11. The computer program product of claim 8 , further comprising the step of automatically re-classifying said domain and wherein all sub-domains of the domain are re-categorized to match the domain and top level domain of the re-classified domain.

12. The computer program product of claim 8 , further comprising the step of monitoring communications of malware to obtain said one or more domain resolution requests.

13. The computer program product of claim 8 , further comprising the step of automatically reclassifying a given one of said known domains in said domain table such that all sub-domains of the reclassified known domain are updated to match the top level domain and the domain of said reclassified known domain.

14. The computer program product of claim 8 , wherein the one or more malware domain resolution requests are obtained from a sandbox execution environment.

15. A system, comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

obtaining at least one domain name included in one or more malware domain resolution requests;

obtaining a domain table identifying a plurality of known domains in a domain name system;

obtaining a dynamic domain table identifying a plurality of domains classified as a dynamic domain name system domain in a dynamic domain name system;

parsing a full domain name associated with said at least one domain name from said one or more malware domain resolution requests into a top level domain and a domain;

classifying said at least one domain name from said one or more malware domain resolution requests as a dynamic domain name system domain in the dynamic domain name system when said top level domain and said domain are found in said dynamic domain table; and

storing said classification of said at least one domain name from said one or more malware domain resolution requests as said dynamic domain name system domain in said domain table with a complete domain of said at least one domain, a current date and time and a Time-To-Live attribute of said at least one domain from a response of the domain name system.

16. The system of claim 15 , further comprising the steps of obtaining a whitelist table identifying a plurality of trusted domains, and classifying said at least one domain name as a trusted domain if said top level domain and said domain are found in said whitelist table.

17. The system of claim 16 , further comprising the step of classifying said at least one domain name as an uncategorized domain if said top level domain and said domain are not found in said dynamic domain table and said whitelist table.

18. The system of claim 15 , further comprising the step of automatically re-classifying said domain and wherein all sub-domains of the domain are re-categorized to match the domain and top level domain of the re-classified domain.

19. The system of claim 15 , further comprising the step of monitoring communications of malware to obtain said one or more domain resolution requests.

20. The system of claim 15 , further comprising the step of automatically reclassifying a given one of said known domains in said domain table such that all sub-domains of the reclassified known domain are updated to match the top level domain and the domain of said reclassified known domain.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060450/0306 →
RELEASE OF SECURITY INTEREST AT REEL 046286 FRAME 0653 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0093 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
Continuity (2)
Continuation 15274091 · Sep 23, 2016
Related Publication 20180234439A1 · Aug 16, 2018