IP Library › Granted Patent US 12,309,116
Granted Patent B2
US 12,309,116 · App. 17/878,665 · Granted May 20, 2025

Detecting shadowed domains

Inventors: Janos Szurdi (Santa Clara, CA); Rebekah Houser (Sunnyvale, CA); Daiping Liu (Sunnyvale, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/0236H04L41/16H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,116
App. No.
17/878,665
Filed
Aug 1, 2022
Granted
May 20, 2025
Kind
B2
Art Unit
2437
USPC
726/11
Abstract

A method and system for detecting shadowed domains is provided. New hostnames are collected for a predetermined period of time. Candidate shadowed domains are selected from the new hostnames. Classification of the candidate shadowed domains is performed based on a plurality of features relating to the candidate shadowed domains to output a set of identified shadowed domains. An action is performed based on the set of identified shadowed domains.

Claims (81)

1. A system, comprising:

a processor configured to:

collect new hostnames for a predetermined period of time;

select candidate shadowed domains from the new hostnames;

perform classification of the candidate shadowed domains based on a plurality of features relating to the candidate shadowed domains to output a set of identified shadowed domains;

perform post-processing on the set of identified shadowed domains, comprising to:

compare a subnetwork of an IP address of an identified shadowed domain with a subnetwork of an IP address of a root domain associated with the identified shadowed domain, wherein the subnetwork corresponds to the first 24 bits of the IP address of the identified shadowed domain; and

in response to a determination that the subnetwork of an IP address of the identified shadowed domain matches the subnetwork of an IP address of the root domain associated with the identified shadowed domain, determine that the identified shadowed domain is likely benign; and

perform an action based on the set of identified shadowed domains, comprising to: add the set of identified shadowed domains to a blacklist of a network security device for blocking access to shadowed domains; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the collecting of the new hostnames for the predetermined period of time comprises to:

determine whether a newly observed hostname (NOH) from a new hostnames dataset is found in an allowlist; and

in the event that the NOH is found in the allowlist, determine that the NOH is not shadowed.

3. The system of claim 1 , wherein the performing of the classification of the candidate shadowed domains comprises to:

extract the plurality of features relating to the candidate shadowed domains; and

perform the classification of the candidate shadowed domains using a model or a set of rules.

4. The system of claim 3 , wherein the model is a machine learning model.

5. The system of claim 3 , wherein the model is a machine learning model, the machine learning model being a neural network.

6. The system of claim 1 , wherein the processor is further configured to:

perform post-processing on the set of identified shadowed domains, comprising to:

compare a time since creation of an identified shadowed domain with a predefined threshold; and

in response to a determination that the time since creation of the identified shadowed domain is equal to or exceeds the predefined threshold, determine that the identified shadowed domain is not shadowed.

7. The system of claim 1 , wherein the processor is further configured to:

perform post-processing on the set of identified shadowed domains, comprising to:

compare a time since the root domain of an identified shadowed domain was registered with a predefined threshold; and

in response to a determination that the time since the root domain of the identified shadowed domain was registered is less than or equal to the predefined threshold, determine that the identified shadowed domain is not shadowed.

8. A system, comprising:

a processor configured to:

collect new hostnames for a predetermined period of time;

select candidate shadowed domains from the new hostnames;

perform classification of the candidate shadowed domains based on a plurality of features relating to the candidate shadowed domains to output a set of identified shadowed domains;

perform post-processing on the set of identified shadowed domains, comprising to:

compare a subnetwork of an IP address of an identified shadowed domain with a subnetwork of an IP address of a root domain associated with the identified shadowed domain, wherein the comparing of the subnetwork of an IP address of the identified shadowed domain with the subnetwork of an IP address of the root domain associated with the identified shadowed domain comprises to:

compare the subnetwork of an IP address of the identified shadowed domain with the subnetwork of an IP address of the root domain associated with the identified shadowed domain based on an active DNS dataset and a passive DNS dataset; and

in response to a determination that the subnetwork of an IP address of the identified shadowed domain matches the subnetwork of an IP address of the root domain associated with the identified shadowed domain, determine that the identified shadowed domain is likely benign; and

perform an action based on the set of identified shadowed domains, comprising to: add the set of identified shadowed domains to a blacklist of a network security device for blocking access to shadowed domains; and

a memory coupled to the processor and configured to provide the processor with instructions.

9. A method, comprising:

collecting, using a processor, new hostnames for a predetermined period of time;

selecting, using the processor, candidate shadowed domains from the new hostnames;

performing, using the processor, classification of the candidate shadowed domains based on a plurality of features relating to the candidate shadowed domains to output a set of identified shadowed domains;

performing post-processing on the set of identified shadowed domains, comprising:

comparing a subnetwork of an IP address of the identified shadowed domain with a subnetwork of an IP address of a root domain associated with the identified shadowed domain, wherein the subnetwork corresponds to the first 24 bits of the IP address of the identified shadowed domain; and

in response to a determination that the subnetwork of an IP address of an identified shadowed domain matches the subnetwork of an IP address of the root domain associated with the identified shadowed domain, determining that the identified shadowed domain is benign; and

performing, using the processor, an action based on the set of identified shadowed domains, comprising: adding the set of identified shadowed domains to a blacklist of a network security device for blocking access to shadowed domains.

10. The method of claim 9 , wherein the performing of the classification of the candidate shadowed domains comprises:

extracting the plurality of features relating to the candidate shadowed domains; and

performing the classification of the candidate shadowed domains using a model or a set of rules.

11. The method of claim 9 , wherein the model is a machine learning model.

12. The method of claim 9 , wherein the model is a machine learning model, the machine learning model being a neural network.

13. The method of claim 9 , further comprising:

before the performing of the action, performing post-processing on the set of identified shadowed domains, comprising:

comparing a time since creation of the identified shadowed domain with a predefined threshold; and

in response to a determination that the time since creation of an identified shadowed domain is equal to or exceeds the predefined threshold, determining that the identified shadowed domain is not shadowed.

14. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

collecting new hostnames for a predetermined period of time;

selecting candidate shadowed domains from the new hostnames;

performing classification of the candidate shadowed domains based on a plurality of features relating to the candidate shadowed domains to output a set of identified shadowed domains;

performing post-processing on the set of identified shadowed domains, comprising:

comparing a subnetwork of an IP address of the identified shadowed domain with a subnetwork of an IP address of a root domain associated with the identified shadowed domain, wherein the subnetwork corresponds to the first 24 bits of the IP address of the identified shadowed domain; and

in response to a determination that the subnetwork of an IP address of an identified shadowed domain matches the subnetwork of an IP address of the root domain associated with the identified shadowed domain, determining that the identified shadowed domain is benign; and

performing an action based on the set of identified shadowed domains, comprising: adding the set of identified shadowed domains to a blacklist of a network security device for blocking access to shadowed domains.

15. A method, comprising:

collecting, using a processor, new hostnames for a predetermined period of time;

selecting, using the processor, candidate shadowed domains from the new hostnames;

performing, using the processor, classification of the candidate shadowed domains based on a plurality of features relating to the candidate shadowed domains to output a set of identified shadowed domains;

performing post-processing on the set of identified shadowed domains, comprising:

comparing a subnetwork of an IP address of the identified shadowed domain with a subnetwork of an IP address of a root domain associated with the identified shadowed domain, wherein the comparing of the subnetwork of an IP address of the identified shadowed domain with the subnetwork of an IP address of the root domain associated with the identified shadowed domain comprises:

comparing the subnetwork of an IP address of the identified shadowed domain with the subnetwork of an IP address of the root domain associated with the identified shadowed domain based on an active DNS dataset and a passive DNS dataset; and

in response to a determination that the subnetwork of an IP address of an identified shadowed domain matches the subnetwork of an IP address of the root domain associated with the identified shadowed domain, determining that the identified shadowed domain is benign; and

performing, using the processor, an action based on the set of identified shadowed domains, comprising: adding the set of identified shadowed domains to a blacklist of a network security device for blocking access to shadowed domains.

16. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

collecting new hostnames for a predetermined period of time;

selecting candidate shadowed domains from the new hostnames;

performing classification of the candidate shadowed domains based on a plurality of features relating to the candidate shadowed domains to output a set of identified shadowed domains;

performing post-processing on the set of identified shadowed domains, comprising:

comparing a subnetwork of an IP address of the identified shadowed domain with a subnetwork of an IP address of a root domain associated with the identified shadowed domain, wherein the subnetwork corresponds to the first 24 bits of the IP address of the identified shadowed domain, wherein the comparing of the subnetwork of an IP address of the identified shadowed domain with the subnetwork of an IP address of the root domain associated with the identified shadowed domain comprises:

comparing the subnetwork of an IP address of the identified shadowed domain with the subnetwork of an IP address of the root domain associated with the identified shadowed domain based on an active DNS dataset and a passive DNS dataset; and

in response to a determination that the subnetwork of an IP address of an identified shadowed domain matches the subnetwork of an IP address of the root domain associated with the identified shadowed domain, determining that the identified shadowed domain is benign; and

performing an action based on the set of identified shadowed domains, comprising:

adding the set of identified shadowed domains to a blacklist of a network security device for blocking access to shadowed domains.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2022
From: SZURDI, JANOS; HOUSER, REBEKAH; LIU, DAIPING
To: PALO ALTO NETWORKS, INC.
Reel/Frame 061411/0326 →
Continuity (1)
Related Publication 20240039890A1 · Feb 1, 2024
References Cited (15)
US 9300623B1 · Earl · 2016 [cited by examiner]
US 10027688B2 · Perdisci · 2018 [cited by examiner]
US 10264017B2 · Stemm · 2019 [cited by examiner]
US 20160226819A1 · Manadhata · 2016 [cited by examiner]
US 20160269362A1 · Rolette · 2016 [cited by examiner]
US 20220337624A1 · Young · 2022 [cited by examiner]
US 20220394060A1 · Berger · 2022 [cited by examiner]
Author Unknown, Domain Shadowing: When Good Domains Go Bad, RiskIQ.com, Jun. 22, 2016, https://www.riskiq.com/blog/external-threat-management/domain-shadowing-good-domains-go-bad/. [cited by applicant]
Florian Weimer, Passive DNS Replication, Apr. 2005, https://www.enyo.de/fw/software/dnslogger/first2005-paper.pdf. [cited by applicant]
Hamilton et al., Abstract of An Efficient Multi-Stage Approach for Identifying Domain Shadowing, ICC 2020-2020 EEE International Conference on Communications (ICC), Jun. 2020. [cited by applicant]
Hamilton et al., Abstract of Cluster Analysis of Passive DNS Features for Identifying Domain Shadowing Infrastructure, 2020 International Symposium on Networks, Computers and Communications (ISNCC), Oct. 2020. [cited by applicant]
Hamilton et al., An Efficient Multi-Stage Approach for Identifying Domain Shadowing, ICC 2020-2020 IEEE International Conference on Communications (ICC), Jun. 2020. [cited by applicant]
Hamilton et al., Cluster Analysis of Passive DNS Features for Identifying Domain Shadowing Infrastructure, 2020 International Symposium on Networks, Computers and Communications (ISNCC), Oct. 2020. [cited by applicant]
Liu et al., Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed Domains, CCS' 17, 2017. [cited by applicant]
P. Mockapetris, 3.6 Resource Record, Nov. 1987, pp. 11-15, https://www.rfc-editor.org/rfc/rfc1034#section-3.6. [cited by applicant]