IP Library Granted Patent US 12,301,620
Granted Patent B2
US 12,301,620 · App. 17/653,379 · Granted May 13, 2025

Detecting malicious URL redirection chains

Inventors: David Jursa (Prague, CZ); Jiří Šembera (Pardubice, CZ); Peter Kováč (Prague, CZ); Tomáš Trnka (Prague, CZ); Elnaz Babayeva (Prague, CZ)
Assignee: Avast Software s.r.o.
H04L63/1483G06F16/9566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,620
App. No.
17/653,379
Granted
May 13, 2025
Kind
B2
Abstract

Malicious redirects in a redirect chain as a result of loading a web address are detected and blocked. A suspicion score is determined for a subject redirection domain based at least in part on the subject redirection domain's web address, and a rate of occurrence of the subject redirection domain in redirect chains leading to a malicious landing domain is calculated. Loading the subject redirection domain is blocked if the suspicion score exceeds a suspicion threshold or the rate of occurrence of the subject redirection domain exceeds a rate of occurrence threshold.

Claims (31)

1. A method of detecting malicious web address redirection in a computerized system, comprising:

maintaining a database containing a plurality of malicious landing domains;

identifying a subject redirection domain as a result of loading a web address;

determining a suspicion score for the subject redirection domain based on a similarity between the subject redirection domain's web address and at least another redirection domain's web address;

calculating a rate of occurrence of the subject redirection domain in prior observations of redirect chains leading to any one of the plurality of malicious landing domains, wherein calculating the rate of occurrence comprises calculating a percentage of redirects leading to malicious landing domains over a recent period of time; and

blocking loading the subject redirection domain if the rate of occurrence of the subject redirection domain in prior observations of redirect chains exceeds a rate of occurrence threshold.

2. The method of detecting malicious web address redirection in a computerized system of claim 1 , wherein blocking loading the redirection domain comprises blocking loading the redirector domain before a user reaches the malicious landing domain.

3. The method of detecting malicious web address redirection in a computerized system of claim 1 , wherein the subject redirection domain's web address comprises at least one of a Uniform Resource Locator (URL) and an Internet Protocol (IP) address.

4. The method of detecting malicious web address redirection in a computerized system of claim 1 , wherein at least one of the at least another redirection domain's web address comprises a redirection domain web address in a same redirection chain as the identified subject redirection domain.

5. The method of detecting malicious web address redirection in a computerized system of claim 1 , wherein calculating a rate of occurrence of the subject redirection domain in redirect chains leading to a malicious landing domain comprises querying a database of prior observations of malicious landing domains and associated redirect chains leading to the malicious landing domains.

6. The method of detecting malicious web address redirection in a computerized system claim 1 , wherein calculating a rate of occurrence of the subject redirection domain comprises calculating a number of observations of the subject redirection domain in prior observations of redirection chains leading to a malicious landing domain.

7. The method of detecting malicious web address redirection in a computerized system of claim 1 , wherein calculating a rate of occurrence of the subject redirection domain comprises calculating a percentage rate at which the subject redirection domain was observed in prior observations of redirection chains leading to a malicious landing domain.

8. The method of detecting malicious web address redirection in a computerized system of claim 1 , wherein calculating a rate of occurrence of the subject redirection domain comprises calculating a percentage rate of occurrence of the subject redirection domain in past observations of redirections in redirection chains leading to a malicious landing domain.

9. The method of detecting malicious web address redirection in a computerized system of claim 1 , further comprising reporting redirections leading to a malicious landing domain to a server.

10. A computerized system, comprising:

a processor;

a memory; and

nonvolatile storage configured to store program instructions, the program instructions operable when executed to cause the computerized system to:

maintain a database containing a plurality of malicious landing domains;

identify a subject redirection domain as a result of loading a web address;

determine a suspicion score for the subject redirection domain based on a similarity between the subject redirection domain's web address and at least another redirection domain's web address;

calculate a rate of occurrence of the subject redirection domain in prior observations of redirect chains leading to any one of the plurality of malicious landing domains, wherein calculating the rate of occurrence comprises calculating a percentage of redirects leading to malicious landing domains over a recent period of time; and

block loading the subject redirection domain if the rate of occurrence of the subject redirection domain in prior observations of redirect chains exceeds a rate of occurrence threshold.

11. The computerized system of claim 10 , wherein blocking loading the redirection domain comprises blocking loading the redirector domain before a user reaches the malicious landing domain.

12. The computerized system of claim 10 , wherein the subject redirection domain's web address comprises at least one of a Uniform Resource Locator (URL) and an Internet Protocol (IP) address.

13. The computerized system of claim 10 , wherein at least one of the at least another redirection domain's web address comprises a redirection domain web address in a same redirection chain as the identified subject redirection domain.

14. The computerized system of claim 10 , wherein calculating a rate of occurrence of the subject redirection domain in redirect chains leading to a malicious landing domain comprises querying a database of prior observations of malicious landing domains and associated redirect chains leading to the malicious landing domains.

15. The computerized system claim 10 , wherein calculating a rate of occurrence of the subject redirection domain comprises calculating a number of observations of the subject redirection domain in prior observations of redirection chains leading to a malicious landing domain.

16. The computerized system of claim 10 , wherein calculating a rate of occurrence of the subject redirection domain comprises calculating a percentage rate at which the subject redirection domain was observed in prior observations of redirection chains leading to a malicious landing domain.

17. The computerized system of claim 10 , wherein calculating a rate of occurrence of the subject redirection domain comprises calculating a percentage rate of occurrence of the subject redirection domain in past observations of redirections in redirection chains leading to a malicious landing domain.

18. The computerized system of claim 10 , the program instructions further operable when executed to cause the computerized system to report redirections leading to a malicious landing domain to a server.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: GEN DIGITAL AMERICAS S.R.O.
To: GEN DIGITAL INC.
Reel/Frame 071771/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: AVAST SOFTWARE S.R.O.
To: GEN DIGITAL AMERICAS S.R.O.
Reel/Frame 071777/0341 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2022
From: JURSA, DAVID; ¿EMBERA, JIRÍ; KOVÁC, PETER; TRNKA, TOMÁ¿; BABAYEVA, ELNAZ
To: AVAST SOFTWARE S.R.O.
Reel/Frame 059241/0391 →
Continuity (1)
Related Publication 20230283632A1 · Sep 7, 2023
References Cited (10)
US 8997228B1 · Satish · 2015 [cited by examiner]
US 9912680B2 · Torres et al. · 2018 [cited by applicant]
US 20100031362A1 · Himberger · 2010 [cited by examiner]
US 20180293330A1 · Kovac · 2018 [cited by applicant]
US 20200374313A1 · Manoselvam · 2020 [cited by examiner]
US 20210120013A1 · Hines · 2021 [cited by examiner]
CN 106605205B · 2019 [cited by examiner]
KR 20220102086A · 2022 [cited by examiner]
“Malicious Domain: Preventing the Problem”—Business Reporter, Technology, May 2021 https://www.business-reporter.co.uk/technology/malicious-domains-preventing-the-problem-may 2021 (Year: 2021). [cited by examiner]
“Check a Website's Reputation with Website Categorization API and Other Tools”—Website Categorization Blog, Website Categorization API, Feb. 12, 2021 https://website-categorization.whoisxmlapi.com/blog/check-a-websites-… [cited by examiner]