IP Library Granted Patent US 11,736,521
Granted Patent B2
US 11,736,521 · App. 16/134,317 · Granted Aug 22, 2023

Systems and methods for detecting domain impersonation

Inventors: Simon Paul Tyler (Wiltshire, GB); Jackie Anne Maylor (Wiltshire, GB); Paul Sowden (London, GB); Meni Farjon (Ramat Gan, IL)
Assignee: Mimecast Services Ltd.
H04L63/1483G06F16/907G06F21/44G06F21/51G06F21/606H04L63/1416G06F2221/2119H04L61/4511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,736,521
App. No.
16/134,317
Granted
Aug 22, 2023
Kind
B2
Abstract

The invention is a security system providing domain name authentication for intrusion and malware prevention. The system is configured to analyze domain names, specifically analyze network metadata associated with said domain names, and further identify domain names attempting to impersonate or spoof domain names associated with a trusted entity or party.

Claims (31)

1. A system for domain name authentication, the system comprising:

at least one processor coupled to at least one memory containing instructions executable by the at least one processor to cause the system to:

maintain a database with a plurality of trusted domains;

analyze a domain associated with an undelivered message intended to be delivered to a recipient, wherein analysis of the domain comprises a comparison of the domain with one or more of the plurality of trusted domains;

determine that the domain is similar but not identical to at least one of the trusted domains based on the comparison of the domain with one or more of the plurality of trusted domains;

access at least one domain registration system to determine an identity of a registrar for the domain and an identity of a registrar for at least one of the trusted domains that are similar but not identical to the domain;

compare the identity of the registrar for the domain with the identity of the registrar for the least one of the trusted domains that are similar but not identical to the domain; and

flag the domain as being legitimate or flag the domain as being illegitimate based on whether the identity of the registrar for the domain is the same as or different than the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain.

2. The system of claim 1 , wherein the domain is flagged as being legitimate when the identity of the registrar for the domain is the same as the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain and the domain is flagged as being illegitimate when the identity of the registrar for the domain is different than the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain.

3. The system of claim 1 , wherein the at least one domain registration system comprises a WHOIS database.

4. A system for detecting a spoofed email message from a sender based on detection of the sender's fraudulent domain associated with the spoofed email message, the system comprising:

at least one processor coupled to at least one memory containing instructions executable by the at least one processor to cause the system to:

maintain a database with a plurality of trusted domains;

receive an email message;

compare a domain name given in the received email message with one or more of the plurality of trusted domains and determine a level of resemblance between the domain name and one or more of the trusted domains based on the comparison;

determine that there is a positive level of resemblance between the domain name and the one or more similar but not identical trusted domains of the plurality of trusted domains;

access at least one domain registration system to determine an identity of a registrar for the domain and an identity of a registrar for at least one of the trusted domains that are similar but not identical to the domain;

compare the identity of the registrar for the domain with the identity of the registrar for the least one of the trusted domains that are similar but not identical to the domain; and

flag the domain name as being legitimate and the email message as safe or flag the domain name as being illegitimate and the email message as potentially harmful based on whether the identity of the registrar for the domain is the same as or different than the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain.

5. The system of claim 4 , wherein the domain is flagged as being legitimate when the identity of the registrar for the domain is the same as the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain and the domain is flagged as being illegitimate when the identity of the registrar for the domain is different than the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain.

6. The system of claim 4 , wherein the at least one domain registration system comprises a WHOIS database.

7. A system for detecting one or more dangerous websites including one or more fraudulent domains, the system comprising:

at least one processor coupled to at least one memory containing instructions executable by the at least one processor to cause the system to:

maintain a database with a plurality of trusted domains;

compare an unrecognized domain associated with a website with one or more of the plurality of trusted domains and determine a level of resemblance between the unrecognized domain and one or more of the trusted domains based on the comparison;

determine that there is a positive level of resemblance between the unrecognized domain and one or more similar but not identical trusted domains of the plurality of trusted domains;

access at least one domain registration system to determine an identity of a registrar for the domain and an identity of a registrar for at least one of the trusted domains that are similar but not identical to the domain;

compare the identity of the registrar for the domain with the identity of the registrar for the least one of the trusted domains that are similar but not identical to the domain; and

flag the domain as being legitimate and the website as safe or flag the domain as being illegitimate and the website as potentially dangerous based on whether the identity of the registrar for the domain is the same as or different than the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain.

8. The system of claim 7 , wherein the domain is flagged as being legitimate when the identity of the registrar for the domain is the same as the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain and the domain is flagged as being illegitimate when the identity of the registrar for the domain is different than the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain.

9. The system of claim 7 , wherein the at least one domain registration system comprises a WHOIS database.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2022
From: MIMECAST NORTH AMERICA, INC.; MIMECAST SERVICES LIMITED
To: ARES CAPITAL CORPORATION
Reel/Frame 060132/0429 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2020
From: TYLER, SIMON PAUL; MAYLOR, JACKIE ANNE; SOWDEN, PAUL; FARJON, MENI
To: MIMECAST SERVICES LTD.
Reel/Frame 052842/0579 →
Continuity (2)
Provisional Application 62581860 · Nov 6, 2017
Related Publication 20190141077A1 · May 9, 2019
Cited By (1)
US 12,316,671