IP Library Granted Patent US 12,568,094
Granted Patent B2
US 12,568,094 · App. 17/864,551 · Granted Mar 3, 2026

Computing device and method of detecting compromised network devices

Inventor: Anton Victorovich Afonin (Moscow, RU)
Assignee: GROUP-IB GLOBAL PRIVATE LIMITED
H04L63/1416H04L61/4511H04L63/0236H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,094
App. No.
17/864,551
Granted
Mar 3, 2026
Kind
B2
Abstract

A method and a computing device for identifying, in a network infrastructure, network devices compromised by DNS tunneling are provided. The method comprises: receiving a portion of traffic of the network infrastructure; identifying, from the traffic, a plurality of DNS queries having been generated by network devices of the network infrastructure; generating, by the processor, for a given one of the plurality of DNS queries, a respective set of feature; applying, by the processor, to the respective set of features, a pre-trained decision rule; in response to the pre-trained decision rule rendering a positive outcome, increasing a penalty score for a respective network device of the network infrastructure having transmitted the given one of the plurality of DNS queries; and in response to the penalty score associated with the respective network device exceeding a predetermined penalty score threshold, identifying the respective network device as being compromised.

Claims (59)

1 . A computer-implementable method of identifying, in a network infrastructure, compromised network devices that are using DNS tunneling, the computer-implementable method being executable by a computing device located within the network infrastructure, the computing device including at least one processor, the computer-implementable method comprising:

receiving, by the at least one processor, traffic generated by each network device of a plurality of network devices located within the network infrastructure;

identifying, by the at least one processor, from the traffic, a plurality of DNS queries having been generated by respective network devices of the plurality of network devices located within the network infrastructure,

each one of the plurality of DNS queries having been transmitted outside the network infrastructure;

determining, by the at least one processor, in the plurality of DNS queries, presence of DNS queries to predetermined types of domain names, generation of which, by a respective network device of the network infrastructure, is non-indicative of the respective network device being compromised,

the predetermined types of domain names including at least low entropy domain names;

removing, by the at least one processor, from the plurality of DNS queries, the DNS queries to the predetermined types of domain names, thereby generating a refined plurality of DNS queries;

generating, by the at least one processor, for a given one of the refined plurality of DNS queries, a respective set of suspiciousness features, the respective set of suspiciousness features comprising:

statistics of network interactions of the respective network device having transmitted the given one of the refined plurality of DNS queries,

the statistics of network interactions including: (i) for protocols above a Transmission Control Protocol (TCP), a number of TCP sessions; and (ii) for User Datagram Protocol (UDP), a number of datagrams over a predetermined period after the respective network device most recently sent the given one of the refined plurality of DNS queries;

applying, by the at least one processor, to the respective set of suspiciousness features associated with the given one of the refined plurality of DNS queries, a pre-trained decision rule,

the pre-trained decision rule having been trained to determine, based on the respective set of suspiciousness features, whether a respective domain name associated with the given one of the refined plurality of DNS queries is malicious;

in response to the pre-trained decision rule rendering a positive outcome, increasing a respective penalty score for each network device of the network infrastructure having transmitted the given one of the refined plurality of DNS queries;

in response to the respective penalty score associated with a given network device exceeding a predetermined penalty score threshold, identifying, by the at least one processor, the given network device as being compromised; and

generating, by the at least one processor, a warning notification for transmission thereof about the given network device being compromised.

2 . The computer-implementable method of claim 1 , wherein the traffic of the network infrastructure comprises at least one of inbound traffic and outbound traffic.

3 . The computer-implementable method of claim 1 , wherein the receiving the traffic comprises applying, by the at least one processor, a traffic mirroring approach.

4 . The computer-implementable method of claim 1 , wherein the determining, in the plurality of DNS queries, the presence of the DNS queries to the predetermined types of domain names comprises determining, for each one of the plurality of DNS queries, at least one of: a domain name; a sender IP address, and a recipient IP address.

5 . The computer-implementable method of claim 4 , further comprising determining whether at least one recipient IP address is in one of a blacklist and in a whitelist, and

in response to the at least one recipient IP address being in the blacklist, increasing the penalty score for each network device of the network infrastructure having transmitted a respective DNS query including the at least one recipient IP address;

in response to at least one recipient IP address being in the whitelist, identifying the respective DNS query as being one of the DNS queries to the predetermined types of domain names.

6 . The computer-implementable method of claim 1 , wherein the predetermined types of domain names further include:

second level domain names and

domain names having been identified as trusted domain names.

7 . The computer-implementable method of claim 1 , wherein the pre-trained decision rule comprises at least one of (i) a heuristic rule and (ii) a long short-term memory (LSTM) neural network-based rule,

the LSTM neural network-based rule having been determined by a LSTM neural network trained to determine, based on the respective set of suspiciousness features, whether the respective domain name associated with the given one of the refined plurality of DNS queries is malicious.

8 . The computer-implementable method of claim 7 , wherein applying the heuristic rule comprises:

determining, by the at least one processor, for the respective domain name of the given one of the refined plurality of DNS queries, a respective entropy value; and

in response to the respective entropy value being greater than a predetermined entropy value threshold, determining that the respective domain name associated with the given one of the refined plurality of DNS queries is malicious.

9 . The computer-implementable method of claim 7 , wherein applying the heuristic rule comprises:

determining, by the at least one processor, a respective frequency of occurrence, in the respective domain name, of each one of a plurality of predetermined N-grams;

based on respective frequency values, determining an N-gram entropy value for the respective domain name; and

in response to the N-gram entropy value exceeding a predetermined N-gram entropy threshold value, determining that the respective domain name associated with the given one of the refined plurality of DNS queries is malicious.

10 . The computer-implementable method of claim 7 , wherein applying the LSTM neural network-based rule comprises feeding, by the at least one processor, to the LSTM neural network: (i) the respective set of suspiciousness features associated with the given one of the refined plurality of DNS queries; (ii) the statistics of network interactions of the respective network device having transmitted the given one of the refined plurality of DNS queries; and (iii) a current penalty score of the respective network device.

11 . The computer-implementable method of claim 1 , wherein, in response to the pre-trained decision rule rendering the positive outcome, the method further comprises:

determining, by the at least one processor, in past traffic of the network infrastructure, whether there is at least one other network device having transmitted a DNS query including the respective domain name of the given one of the refined plurality of DNS queries;

in response to determining the at least one other network device, executing one of:

increasing the respective penalty score of the at least one other network device; and

increasing respective penalty scores of each network device of the network infrastructure.

12 . The computer-implementable method of claim 1 , wherein, in response to the pre-trained decision rule rendering the positive outcome, the method further comprises:

restricting, by the at least one processor, access to the respective domain name of the given one of the refined plurality of DNS queries, for every network device included into the network infrastructure;

generating, by the at least one processor, a notification of the respective domain name being malicious;

generating, by the at least one processor, a template email for notifying interested parties about the respective domain name being malicious; and

adding the respective domain name to a blacklist of domain names.

13 . A computing device for identifying, in a network infrastructure, compromised network devices that are using DNS tunneling, the computing device being located within the network infrastructure, the computing device comprising at least one processor communicatively coupled to the network infrastructure and a non-transitory computer-readable memory storing instructions, the at least one processor, upon executing the instructions, being configured to:

receive traffic generated by each network device of a plurality of network devices located within the network infrastructure;

identify, from the traffic, a plurality of DNS queries having been generated by respective network devices of the plurality of network devices located within the network infrastructure,

each one of the plurality DNS queries having been transmitted outside the network infrastructure;

determine, in the plurality of DNS queries, presence of DNS queries to predetermined types of domain names, generation of which, by a respective network device of the network infrastructure, is non-indicative of the respective network device being compromised,

the predetermined types of domain names including at least low entropy domain names;

remove, from the plurality of DNS queries, the DNS queries to the predetermined types of domain names, thereby generating a refined plurality of DNS queries;

generate, for a given one of the refined plurality of DNS queries, a respective set of suspiciousness features, the respective set of suspiciousness features comprising:

statistics of network interactions of the respective network device having transmitted the given one of the refined plurality of DNS queries,

the statistics of network interactions including: (i) for protocols above a Transmission Control Protocol (TCP), a number of TCP sessions; and (ii) for User Datagram Protocol (UDP), a number of datagrams over a predetermined period after the respective network device most recently sent the given one of the refined plurality of DNS queries;

apply, to the respective set of suspiciousness features associated with the given one of the refined plurality of DNS queries, a pre-trained decision rule,

the pre-trained decision rule having been trained to determine, based on the respective set of suspiciousness features, whether a respective domain name associated with the given one of the refined plurality of DNS queries is malicious;

in response to the pre-trained decision rule rendering a positive outcome, increase a respective penalty score for each network device of the network infrastructure having transmitted the given one of the refined plurality of DNS queries;

in response to the respective penalty score associated with a given network device exceeding a predetermined penalty score threshold, identify the given network device as being compromised; and

generate a warning notification for transmission thereof about the given network device being compromised.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2025
From: F.A.C.C.T. NETWORK SECURITY LLC
To: GROUP-IB GLOBAL PRIVATE LIMITED
Reel/Frame 071439/0078 →
CHANGE OF NAME Recorded Feb 7, 2024
From: GROUP IB TDS, LTD
To: F.A.C.C.T. NETWORK SECURITY LLC
Reel/Frame 066522/0741 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2022
From: AFONIN, ANTON VICTOROVICH
To: GROUP IB TDS, LTD
Reel/Frame 060503/0541 →
Priority Claims (1)
RU 2021124547 · Aug 19, 2021 · national
Continuity (1)
Related Publication 20230056625A1 · Feb 23, 2023
References Cited (287)
US 7225343B1 · Honig et al. · 2007 [cited by applicant]
US 7496628B2 · Arnold et al. · 2009 [cited by applicant]
US 7712136B2 · Sprosts et al. · 2010 [cited by applicant]
US 7730040B2 · Reasor et al. · 2010 [cited by applicant]
US 7854001B1 · Chen et al. · 2010 [cited by applicant]
US 7865953B1 · Hsieh et al. · 2011 [cited by applicant]
US 7958555B1 · Chen et al. · 2011 [cited by applicant]
US 7984500B1 · Khanna et al. · 2011 [cited by applicant]
US 8132250B2 · Judge et al. · 2012 [cited by applicant]
US 8151341B1 · Gudov · 2012 [cited by applicant]
US 8219549B2 · Gao et al. · 2012 [cited by applicant]
US 8255532B2 · Smith-Mickelson et al. · 2012 [cited by applicant]
US 8260914B1 · Ranjan · 2012 [cited by applicant]
US 8266695B1 · Clay · 2012 [cited by applicant]
US 8285830B1 · Stout et al. · 2012 [cited by applicant]
US 8402543B1 · Ranjan et al. · 2013 [cited by applicant]
US 8448245B2 · Banerjee et al. · 2013 [cited by applicant]
US 8532382B1 · Ioffe · 2013 [cited by applicant]
US 8539582B1 · Aziz et al. · 2013 [cited by applicant]
US 8555388B1 · Wang et al. · 2013 [cited by applicant]
US 8561177B1 · Aziz et al. · 2013 [cited by applicant]
US 8578480B2 · Judge et al. · 2013 [cited by applicant]
US 8600993B1 · Gupta et al. · 2013 [cited by applicant]
US 8612463B2 · Brdiczka et al. · 2013 [cited by applicant]
US 8612560B2 · Oliver et al. · 2013 [cited by applicant]
US 8625033B1 · Marwood et al. · 2014 [cited by applicant]
US 8631489B2 · Antonakakis et al. · 2014 [cited by applicant]
US 8635696B1 · Aziz · 2014 [cited by applicant]
US 8650080B2 · O'Connell et al. · 2014 [cited by applicant]
US 8660296B1 · Ioffe · 2014 [cited by applicant]
US 8677472B1 · Dotan et al. · 2014 [cited by applicant]
US 8762537B2 · Alperovitch et al. · 2014 [cited by applicant]
US 8776229B1 · Aziz · 2014 [cited by applicant]
US 8850571B2 · Staniford et al. · 2014 [cited by applicant]
US 8856239B1 · Oliver et al. · 2014 [cited by applicant]
US 8856937B1 · Wüest et al. · 2014 [cited by applicant]
US 8898787B2 · Thompson et al. · 2014 [cited by applicant]
US 8972412B1 · Christian et al. · 2015 [cited by applicant]
US 8984640B1 · Emigh et al. · 2015 [cited by applicant]
US 9026840B1 · Kim · 2015 [cited by applicant]
US 9060018B1 · Yu et al. · 2015 [cited by applicant]
US 9100335B2 · Oliver et al. · 2015 [cited by applicant]
US 9210111B2 · Chasin et al. · 2015 [cited by applicant]
US 9215239B1 · Wang et al. · 2015 [cited by applicant]
US 9253208B1 · Koshelev · 2016 [cited by applicant]
US 9300686B2 · Pidathala et al. · 2016 [cited by applicant]
US 9330258B1 · Satish et al. · 2016 [cited by applicant]
US 9338181B1 · Burns et al. · 2016 [cited by applicant]
US 9357469B2 · Smith et al. · 2016 [cited by applicant]
US 9456000B1 · Spiro et al. · 2016 [cited by applicant]
US 9584541B1 · Weinstein et al. · 2017 [cited by applicant]
US 9654593B2 · Garg et al. · 2017 [cited by applicant]
US 9723344B1 · Granström et al. · 2017 [cited by applicant]
US 9736178B1 · Ashley · 2017 [cited by applicant]
US 9749336B1 · Zhang et al. · 2017 [cited by applicant]
US 9847973B1 · Jakobsson et al. · 2017 [cited by applicant]
US 9875355B1 · Williams · 2018 [cited by applicant]
US 9888019B1 · Pidathala et al. · 2018 [cited by applicant]
US 9917852B1 · Xu et al. · 2018 [cited by applicant]
US 9934376B1 · Ismael · 2018 [cited by applicant]
US 10044748B2 · Dagon et al. · 2018 [cited by applicant]
US 10129194B1 · Jakobsson · 2018 [cited by applicant]
US 10270744B2 · Yu et al. · 2019 [cited by applicant]
US 10587646B2 · Fakeri-Tabrizi et al. · 2020 [cited by applicant]
US 10715543B2 · Jakobsson · 2020 [cited by examiner]
US 11012414B2 · Moore · 2021 [cited by examiner]
US 11153330B1 · Antoniewicz · 2021 [cited by examiner]
US 12381901B1 · Golden · 2025 [cited by examiner]
US 20020161862A1 · Horvitz · 2002 [cited by applicant]
US 20030009696A1 · Bunker et al. · 2003 [cited by applicant]
US 20060074858A1 · Etzold et al. · 2006 [cited by applicant]
US 20060107321A1 · Tzadikario · 2006 [cited by applicant]
US 20060224898A1 · Ahmed · 2006 [cited by applicant]
US 20060253582A1 · Dixon et al. · 2006 [cited by applicant]
US 20070019543A1 · Wei et al. · 2007 [cited by applicant]
US 20070239999A1 · Honig et al. · 2007 [cited by applicant]
US 20090138342A1 · Otto et al. · 2009 [cited by applicant]
US 20090281852A1 · Abhari et al. · 2009 [cited by applicant]
US 20090292925A1 · Meisel · 2009 [cited by applicant]
US 20100011124A1 · Wei et al. · 2010 [cited by applicant]
US 20100037314A1 · Perdisci et al. · 2010 [cited by applicant]
US 20100076857A1 · Deo et al. · 2010 [cited by applicant]
US 20100095377A1 · Krywaniuk · 2010 [cited by applicant]
US 20100115620A1 · Alme · 2010 [cited by applicant]
US 20100115621A1 · Staniford et al. · 2010 [cited by applicant]
US 20100191737A1 · Friedman et al. · 2010 [cited by applicant]
US 20100205665A1 · Komili et al. · 2010 [cited by applicant]
US 20100235918A1 · Mizrahi et al. · 2010 [cited by applicant]
US 20110222787A1 · Thiemert et al. · 2011 [cited by applicant]
US 20120030293A1 · Bobotek · 2012 [cited by applicant]
US 20120079596A1 · Thomas et al. · 2012 [cited by applicant]
US 20120087583A1 · Yang et al. · 2012 [cited by applicant]
US 20120158626A1 · Zhu et al. · 2012 [cited by applicant]
US 20120209987A1 · Rhinelander et al. · 2012 [cited by applicant]
US 20120233656A1 · Rieschick et al. · 2012 [cited by applicant]
US 20120291125A1 · Maria · 2012 [cited by applicant]
US 20130086677A1 · Ma et al. · 2013 [cited by applicant]
US 20130103666A1 · Sandberg et al. · 2013 [cited by applicant]
US 20130111591A1 · Topan et al. · 2013 [cited by applicant]
US 20130117848A1 · Golshan et al. · 2013 [cited by applicant]
US 20130191364A1 · Kamel et al. · 2013 [cited by applicant]
US 20130263264A1 · Klein et al. · 2013 [cited by applicant]
US 20130297619A1 · Chandrasekaran et al. · 2013 [cited by applicant]
US 20130340080A1 · Gostev et al. · 2013 [cited by applicant]
US 20140033307A1 · Schmidtler · 2014 [cited by applicant]
US 20140058854A1 · Ranganath et al. · 2014 [cited by applicant]
US 20140082730A1 · Vashist et al. · 2014 [cited by applicant]
US 20140173287A1 · Mizunuma · 2014 [cited by applicant]
US 20140181975A1 · Spernow et al. · 2014 [cited by applicant]
US 20140310811A1 · Hentunen · 2014 [cited by applicant]
US 20150007250A1 · Dicato, Jr. et al. · 2015 [cited by applicant]
US 20150049547A1 · Kim · 2015 [cited by applicant]
US 20150067839A1 · Wardman et al. · 2015 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20150170312A1 · Mehta et al. · 2015 [cited by applicant]
US 20150200963A1 · Geng et al. · 2015 [cited by applicant]
US 20150220735A1 · Paithane et al. · 2015 [cited by applicant]
US 20150295945A1 · Canzanese et al. · 2015 [cited by applicant]
US 20150363791A1 · Raz et al. · 2015 [cited by applicant]
US 20150381654A1 · Wang et al. · 2015 [cited by applicant]
US 20160036837A1 · Jain et al. · 2016 [cited by applicant]
US 20160036838A1 · Jain et al. · 2016 [cited by applicant]
US 20160044054A1 · Stiansen et al. · 2016 [cited by applicant]
US 20160055490A1 · Keren et al. · 2016 [cited by applicant]
US 20160065595A1 · Kim et al. · 2016 [cited by applicant]
US 20160112445A1 · Abramowitz · 2016 [cited by applicant]
US 20160127907A1 · Baxley et al. · 2016 [cited by applicant]
US 20160149943A1 · Kaloroumakis et al. · 2016 [cited by applicant]
US 20160191243A1 · Manning · 2016 [cited by applicant]
US 20160205122A1 · Bassett · 2016 [cited by applicant]
US 20160205123A1 · Almurayh et al. · 2016 [cited by applicant]
US 20160226894A1 · Lee et al. · 2016 [cited by applicant]
US 20160253679A1 · Venkatraman et al. · 2016 [cited by applicant]
US 20160261628A1 · Doron et al. · 2016 [cited by applicant]
US 20160267179A1 · Mei et al. · 2016 [cited by applicant]
US 20160285907A1 · Nguyen et al. · 2016 [cited by applicant]
US 20160294862A1 · Tao · 2016 [cited by applicant]
US 20160306974A1 · Turgeman et al. · 2016 [cited by applicant]
US 20160352772A1 · O'Connor · 2016 [cited by applicant]
US 20160359679A1 · Parandehgheibi et al. · 2016 [cited by applicant]
US 20170034211A1 · Buergi et al. · 2017 [cited by applicant]
US 20170111377A1 · Park et al. · 2017 [cited by applicant]
US 20170134401A1 · Medvedovsky et al. · 2017 [cited by applicant]
US 20170142144A1 · Weinberger et al. · 2017 [cited by applicant]
US 20170149813A1 · Wright et al. · 2017 [cited by applicant]
US 20170200457A1 · Chai et al. · 2017 [cited by applicant]
US 20170230401A1 · Ahmed et al. · 2017 [cited by applicant]
US 20170244735A1 · Visbal et al. · 2017 [cited by applicant]
US 20170250972A1 · Ronda et al. · 2017 [cited by applicant]
US 20170257391A9 · Emigh · 2017 [cited by examiner]
US 20170272471A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170279818A1 · Milazzo et al. · 2017 [cited by applicant]
US 20170279846A1 · Osterweil · 2017 [cited by examiner]
US 20170286544A1 · Hunt et al. · 2017 [cited by applicant]
US 20170289187A1 · Noel et al. · 2017 [cited by applicant]
US 20170295157A1 · Chavez et al. · 2017 [cited by applicant]
US 20170295187A1 · Havelka et al. · 2017 [cited by applicant]
US 20170324738A1 · Hari et al. · 2017 [cited by applicant]
US 20170346839A1 · Peppe et al. · 2017 [cited by applicant]
US 20180007070A1 · Kulkarni et al. · 2018 [cited by applicant]
US 20180012021A1 · Volkov · 2018 [cited by applicant]
US 20180012144A1 · Ding et al. · 2018 [cited by applicant]
US 20180034779A1 · Ahuja et al. · 2018 [cited by applicant]
US 20180063190A1 · Wright et al. · 2018 [cited by applicant]
US 20180096153A1 · Dewitte et al. · 2018 [cited by applicant]
US 20180115573A1 · Kuo et al. · 2018 [cited by applicant]
US 20180137150A1 · Osesina et al. · 2018 [cited by applicant]
US 20180227324A1 · Chambers · 2018 [cited by examiner]
US 20180268464A1 · Li · 2018 [cited by examiner]
US 20180307832A1 · Ijiro · 2018 [cited by examiner]
US 20180309787A1 · Evron · 2018 [cited by examiner]
US 20190089737A1 · Shayevitz · 2019 [cited by examiner]
US 20190207973A1 · Peng · 2019 [cited by applicant]
US 20190222589A1 · Kislitsin · 2019 [cited by examiner]
US 20190373005A1 · Bassett · 2019 [cited by applicant]
US 20200007502A1 · Everton · 2020 [cited by examiner]
US 20200092326A1 · Prakash · 2020 [cited by examiner]
US 20200106809A1 · Raj · 2020 [cited by examiner]
US 20200134702A1 · Li · 2020 [cited by applicant]
US 20200145435A1 · Chiu · 2020 [cited by examiner]
US 20200169570A1 · Kleymenov · 2020 [cited by examiner]
US 20200349430A1 · Schmidtler · 2020 [cited by examiner]
US 20200351244A1 · Moore · 2020 [cited by examiner]
US 20210126901A1 · Rodriguez · 2021 [cited by examiner]
US 20210174199A1 · Manadhata · 2021 [cited by examiner]
US 20210194879A1 · Meaburn · 2021 [cited by examiner]
US 20210400080A1 · Kaidi · 2021 [cited by examiner]
US 20220058483A1 · Liu · 2022 [cited by examiner]
CN 103491205A · 2014 [cited by applicant]
CN 104504307A · 2015 [cited by applicant]
CN 105429956A · 2016 [cited by applicant]
CN 105897714A · 2016 [cited by applicant]
CN 106131016A · 2016 [cited by applicant]
CN 106506435A · 2017 [cited by applicant]
CN 106713312A · 2017 [cited by applicant]
CN 107392456A · 2017 [cited by applicant]
EP 1160646A2 · 2001 [cited by applicant]
EP 2410452B1 · 2016 [cited by applicant]
GB 2493514A · 2013 [cited by applicant]
KR 1020070049514A · 2007 [cited by applicant]
KR 101514984B1 · 2015 [cited by applicant]
RU 2382400C2 · 2010 [cited by applicant]
RU 107616U1 · 2011 [cited by applicant]
RU 2446459C1 · 2012 [cited by applicant]
RU 129279U1 · 2013 [cited by applicant]
RU 2487406C1 · 2013 [cited by applicant]
RU 2488880C1 · 2013 [cited by applicant]
RU 2495486C1 · 2013 [cited by applicant]
RU 2522019C1 · 2014 [cited by applicant]
RU 2523114C2 · 2014 [cited by applicant]
RU 2530210C2 · 2014 [cited by applicant]
RU 2536664C2 · 2014 [cited by applicant]
RU 2538292C1 · 2015 [cited by applicant]
RU 2543564C1 · 2015 [cited by applicant]
RU 2566329C2 · 2015 [cited by applicant]
RU 2571594C2 · 2015 [cited by applicant]
RU 2589310C2 · 2016 [cited by applicant]
RU 164629U1 · 2016 [cited by applicant]
RU 2607231C2 · 2017 [cited by applicant]
RU 2610586C2 · 2017 [cited by applicant]
RU 2613535C1 · 2017 [cited by applicant]
RU 2622870C2 · 2017 [cited by applicant]
RU 2625050C1 · 2017 [cited by applicant]
RU 2628192C2 · 2017 [cited by applicant]
RU 2636702C1 · 2017 [cited by applicant]
RU 2668710C1 · 2018 [cited by applicant]
RU 2670906C9 · 2018 [cited by applicant]
RU 2681699C1 · 2019 [cited by applicant]
WO 0245380A2 · 2002 [cited by applicant]
WO 2009026564A1 · 2009 [cited by applicant]
WO 2011045424A1 · 2011 [cited by applicant]
WO 2012015171A2 · 2012 [cited by applicant]
WO 2019010182A1 · 2019 [cited by applicant]
English Translation of CN106713312, @Questel—FAMPAT, Jul. 17, 2019. [cited by applicant]
English Translation of CN105897714, @Questel—FAMPAT, Jul. 17, 2019. [cited by applicant]
English Translation of CN106506435, @Questel—FAMPAT, Jul. 26, 2019. [cited by applicant]
English Translation of CN107392456, @Questel—FAMPAT, Jul. 29, 2019. [cited by applicant]
English Translation of CN103491205, @Questel—FAMPAT, Jul. 29, 2019. [cited by applicant]
English Translation of CN106131016, @Questel—FAMPAT, Jul. 17, 2019. [cited by applicant]
Invitation to Respond to Written Opinion received Aug. 5, 2019 with regard to the counterpart SG Patent Application No. 10201900339Q. [cited by applicant]
Invitation to Respond to Written Opinion received Aug. 5, 2019 with regard to the counterpart SG Patent Application No. 10201901079U. [cited by applicant]
Invitation to Respond to Written Opinion received Jul. 31, 2019 with regard to the counterpart SG Patent Application No. 10201900335P. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018144708 completed Aug. 16, 2019. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018147431 completed Aug. 15, 2019. [cited by applicant]
English Translation of KR10-2007-0049514 (Description, Claims) retrieved on Espacenet on Oct. 16, 2019. [cited by applicant]
English Abstract of KR10-1514984 retrieved on Espacenet on Oct. 15, 2019. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 15/707,641 mailed Apr. 25, 2019. [cited by applicant]
European Search Report with regard to the counterpart EP Patent Application No. EP17210904 completed May 16, 2018. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 16/261,854 mailed Oct. 21, 2019. [cited by applicant]
Notice of Allowance with regard to the counterpart U.S. Appl. No. 15/707,641 mailed Oct. 30, 2019. [cited by applicant]
Whyte, “DNS-based Detection of Scanning Worms in an Enterprise Network”, Aug. 2004, NOSS, pp. 1-17 (Year: 2005)—cited in the Notice of Allowance with regard to the counterpart U.S. Appl. No. 15/707,641. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 15/858,013 mailed Nov. 22, 2019. [cited by applicant]
Search Report with regard to the counterpart SG Patent Application No. 10201900062S mailed Dec. 5, 2019. [cited by applicant]
Search Report with regard to the counterpart SG Patent Application No. 10201900060Y mailed Dec. 5, 2019. [cited by applicant]
English Abstract for CN105429956 retrieved on Espacenet on Jan. 7, 2020. [cited by applicant]
English Abstract for CN104504307 retrieved on Espacenet on Jan. 7, 2020. [cited by applicant]
Office Action received with regard to the counterpart U.S. Appl. No. 15/858,032 mailed Apr. 6, 2020. [cited by applicant]
Notice of Allowance with regard to the counterpart U.S. Appl. No. 15/858,013 mailed May 8, 2020. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 16/270,341 mailed May 27, 2020. [cited by applicant]
Notice of Allowance with regard to the counterpart U.S. Appl. No. 15/858,013 mailed Jun. 10, 2020. [cited by applicant]
Notice of Allowance with regard to the counterpart U.S. Appl. No. 15/858,032 mailed Jul. 30, 2020. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 16/659,697 mailed May 12, 2021. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 16/247,870 mailed Jun. 29, 2021. [cited by applicant]
Office Action with regard to the counterpart U.S. Appl. No. 16/659,687 mailed Mar. 16, 2022. [cited by applicant]
Notice of Allowance with regard to the counterpart U.S. Appl. No. 16/659,687 mailed Jun. 24, 2022. [cited by applicant]
Search Report with regard to the NL Patent Application No. 2031253 completed Jan. 2, 2023. [cited by applicant]
English Abstract of RU107616 retrieved on Espacenet on Jul. 3, 2017. [cited by applicant]
European Search Report with regard to EP17180099 completed on Nov. 28, 2017. [cited by applicant]
European Search Report with regard to EP17191900 completed on Jan. 11, 2018. [cited by applicant]
Yoshioka et al., “Sandbox Analysis with Controlled Internet Connection for Observing Temporal Changes of Malware Behavior”, https://www.researchgate.net/publication/254198606, 15 pages. [cited by applicant]
Yoshioka et al., “Multi-Pass Malware Sandbox Analysis with Controlled Internet Connection”, IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences, Engineering Sciences Society, Tokyo, 2… [cited by applicant]
Wikipedia, “Blockchain”, https://en.wikipedia.org/wiki/Blockchain, pdf document, 18 pages. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018101764 completed Jun. 29, 2018. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018101761 completed Jun. 20, 2018. [cited by applicant]
International Search Report with regard to the counterpart Patent Application No. PCT/RU2016/000526 mailed Jun. 1, 2017. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018101760 completed Jun. 22, 2018. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018101759 completed Sep. 7, 2018. [cited by applicant]
English Abstract of RU129279 retrieved on Espacenet on Sep. 11, 2017. [cited by applicant]
English Abstract of RU164629 retrieved on Espacenet on Sep. 11, 2017. [cited by applicant]
English Abstract of RU2538292 retrieved on Espacenet on Sep. 18, 2017. [cited by applicant]
Prakash et al., “PhishNet: Predictive Blacklisting to Detect Phishing Attacks”, INFOCOM, 2010 Proceedings IEEE, USA, 2010, ISBN: 978-1-4244-5836-3, doc. 22 pages. [cited by applicant]
Search Report with regard to the counterpart Patent Application No. RU2018105377 completed Oct. 15, 2018. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2018101763 completed Jan. 11, 2019. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2016137336 completed Jun. 6, 2017. [cited by applicant]
English Abstract of RU2522019 retrieved on Espacenet on Jan. 25, 2019. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2017140501 completed Jul. 11, 2018. [cited by applicant]
European Search Report with regard to the counterpart EP Patent Application No. EP17211131 completed Apr. 12, 2018. [cited by applicant]