IP Library Granted Patent US 11,671,441
Granted Patent B2
US 11,671,441 · App. 17/014,495 · Granted Jun 6, 2023

Systems and methods for external detection of misconfigured systems

Inventor: Joao Gouveia (Bejos de Azeitao, PT)
Assignee: BitSight Technologies, Inc.
H04L63/1433H04L61/302
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,671,441
App. No.
17/014,495
Granted
Jun 6, 2023
Kind
B2
Abstract

A computer-implemented method is provided for external detection of a vulnerable system coupled to a communication network. The method can include measuring communication traffic on the communication network to identify one or more domain names, which in turn can originate from server systems in the communication network. The method can further include identifying the domain names based on metadata from the domain names and/or the measured communication traffic, where each domain name has an associated property indicative of its vulnerability. The method can further include determining whether any one (or more) of the domain names is registered at a domain name registry and, if the domain name is not registered, registering the domain name.

Claims (50)

1. A computer-implemented method for external detection of a vulnerable system, the vulnerable system coupled to a communication network based on domain name properties, the method comprising:

receiving communication traffic in the communication network to identify at least one domain name associated with a vulnerable system, the communication traffic originating from at least one server system in the communication network;

executing queries on the communication traffic to extract metadata while monitoring the communication traffic;

identifying the domain name having an associated property indicative of vulnerability of the domain name based on the metadata, wherein the domain name having the associated property indicative of vulnerability comprises a misconfigured domain name;

determining whether the misconfigured domain name is registered at a domain name registry;

if the misconfigured domain name is not registered, registering the misconfigured domain name based on a high frequency of domain names; and

detecting the vulnerable system associated with the registered misconfigured domain name.

2. The method of claim 1 , wherein the vulnerable system is a malware-infected server system.

3. The method of claim 1 , wherein the vulnerable system is a misconfigured server system.

4. The method of claim 1 , wherein the metadata further comprises a geographical location associated with each domain name.

5. The method of claim 1 , further comprising:

associating the registered misconfigured domain name with a server system configured to monitor communication traffic to the registered misconfigured domain name.

6. The method of claim 1 further comprising detecting the vulnerable system associated with the registered misconfigured domain name.

7. The method of claim 1 , wherein receiving communication traffic comprises:

receiving communication traffic from at least one Internet Service Provider (ISP).

8. The method of claim 1 further comprising comparing a relative magnitude of communication traffic to an expected amount of communication traffic.

9. The method of claim 1 , wherein receiving communication traffic comprises measuring a frequency of communication traffic to the misconfigured domain name.

10. The method of claim 1 , wherein the metadata comprises at least one of the group consisting of: (a) geographical location of the communication traffic, (b) frequency of the communication traffic, (c) magnitude of the communication traffic, (d) aggregated counters of a number of unique Internet Protocol (IP) addresses per country, (e) a number of events observed per period, and (f) a ratio of unique IP addresses to a sum of a portion of the communication traffic.

11. A system for external detection of a vulnerable system coupled to a communication network, the system comprising:

at least one computer systems programmed to perform operations comprising:

receiving communication traffic in the communication network to identify at least one domain name associated with a vulnerable system, the communication traffic originating from at least one server system in the communication network;

executing queries on the communication traffic to extract metadata while monitoring the communication traffic;

identifying the domain name having an associated property indicative of vulnerability of the domain name based on the metadata, wherein the domain name having the associated property indicative of vulnerability comprises a misconfigured domain name;

determining whether the misconfigured domain name is registered at a domain name registry;

if the misconfigured domain name is not registered, registering the misconfigured domain name based on a high frequency of domain names; and

detecting the vulnerable system associated with the registered misconfigured domain name.

12. The system of claim 11 , wherein the vulnerable system is a malware-infected server system.

13. The system of claim 11 , wherein the vulnerable system is a misconfigured server system.

14. The system of claim 11 , wherein the operations further comprise:

associating the registered domain name with a server system configured to monitor communication traffic to the registered domain name.

15. The system of claim 11 , wherein the operations further comprise detecting the vulnerable system associated with the registered misconfigured domain name.

16. The system of claim 11 , wherein receiving communication traffic comprises:

receiving communication traffic from at least one Internet Service Provider (ISP).

17. The system of claim 11 , wherein the operations further comprise comparing a relative magnitude of communication traffic to an expected amount of communication traffic.

18. The system of claim 11 , wherein receiving communication traffic comprises measuring a frequency of communication traffic to the misconfigured domain name.

19. The system of claim 11 , wherein the metadata comprises at least one of the group consisting of: (a) geographical location of the communication traffic, (b) frequency of the communication traffic, (c) magnitude of the communication traffic, (d) aggregated counters of a number of unique Internet Protocol (IP) addresses per country, (e) a number of events observed per period, and (f) a ratio of unique IP addresses to a sum of a portion of the communication traffic.

20. A computer-implemented method for external detection of a vulnerable system, the vulnerable system coupled to a communication network based on domain name properties, the method comprising:

receiving communication traffic in the communication network to identify at least one domain name associated with a vulnerable system, the communication traffic originating from at least one server system in the communication network;

executing queries on the communication traffic to extract metadata while monitoring the communication traffic;

identifying the domain name having an associated property indicative of vulnerability of the domain name based on the metadata, wherein the domain name having the associated property indicative of vulnerability comprises an abandoned domain name;

determining whether the abandoned domain name is registered at a domain name registry;

if the abandoned domain name is not registered, registering the abandoned domain name based on a high frequency of domain names; and

detecting the vulnerable system associated with the registered abandoned domain name.

21. A computer-implemented method for external detection of a vulnerable system, the vulnerable system coupled to a communication network based on domain name properties, the method comprising:

receiving communication traffic in the communication network to identify at least one domain name associated with a vulnerable system, the communication traffic originating from at least one server system in the communication network;

executing queries on the communication traffic to extract metadata while monitoring the communication traffic;

identifying the domain name having an associated property indicative of vulnerability of the domain name based on the metadata, wherein the domain name having the associated property indicative of vulnerability comprises an algorithm-generated domain name;

determining whether the algorithm-generated domain name is registered at a domain name registry;

if the algorithm-generated domain name is not registered, registering the algorithm-generated domain name based on a high frequency of domain names; and

detecting the vulnerable system associated with the registered algorithm-generated domain name.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2021
From: GOUVEIA, JOAO
To: BITSIGHT TECHNOLOGIES, INC.
Reel/Frame 058268/0868 →
SECURITY INTEREST Recorded Nov 19, 2020
From: BITSIGHT TECHNOLOGIES, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 054481/0727 →
SECURITY INTEREST Recorded Nov 19, 2020
From: BITSIGHT TECHNOLOGIES, INC.
To: SILICON VALLEY BANK
Reel/Frame 054481/0739 →
Continuity (2)
Continuation 15954921 · Apr 17, 2018
Related Publication 20200404017A1 · Dec 24, 2020