IP Library Granted Patent US 12,395,527
Granted Patent B2
US 12,395,527 · App. 18/023,034 · Granted Aug 19, 2025

Determination device, determination method, and determination program

Inventors: Daiki Chiba (Musashino, JP); Mitsuaki Akiyama (Musashino, JP)
Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
H04L63/1483H04L61/3025H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,527
App. No.
18/023,034
Granted
Aug 19, 2025
Kind
B2
Abstract

A specifying device receives an input of time-series information indicating an operation form of a domain name up to a predetermined date and time in time series. Then, the specifying device specifies a pattern of a time-series change in operation form of a domain name on the basis of pattern information indicating patterns of time-series change in operation form of the domain name and time-series information of an input domain name. The specifying device specifies candidates for the operation form of the domain name since the predetermined date and time using a result of the specifying. Thereafter, the specifying device determines whether or not the domain name is a target of a re-determination as to whether or not the domain name is a malicious domain name on the basis of the specified candidates for the operation form of the domain name since the predetermined date and time.

Claims (33)

1. A determination device comprising:

a processing circuitry configured to

receive an input of time-series information indicating an operation form of a domain name up to a predetermined date and time in time series;

specify whether a time-series change in the operation form of the domain name corresponds to any of patterns shown in pattern information based on the time-series information of the domain name and the pattern information indicating patterns of time-series changes in the operation form of the domain name, and specify candidates for the operation form of the domain name after the predetermined date and time based on a specified pattern corresponding to the time-series change in the operation form of the domain name;

determine a possibility that the operation form of the domain name will change to malicious use based on the specified candidates for the operation form of the domain name after the predetermined date and time, the operation form of a domain name includes whether or not the domain name is used maliciously and whether or not the domain name is used for domain parking;

continuously update, in real time, a blacklist to include the domain name when the domain name is determined to be used maliciously; and

perform at least one of web filtering or domain name filtering based on the blacklist after being updated to include the domain name that is determined to be used maliciously.

2. The determination device according to claim 1 ,

wherein the time-series information of the domain name further includes

information indicating a period in which the domain name is re-registered after the domain name expires,

the pattern information further includes

information indicating a pattern of the operation form of the domain name in a period before and after the re-registration of the domain name, and

the processing circuitry, to specify whether the time-series change in operation form of the domain name corresponds to any of the patterns shown in the pattern information, is further configured to

specify whether or not a change in operation form in the period before and after the re-registration of the input domain name corresponds to any of patterns shown in the pattern information in response to determination that the domain name has been re-registered based on the time-series information of the domain name, and specify the candidates for the operation form of the domain name after the predetermined date and time based on the specified pattern.

3. The determination device according to claim 1 ,

wherein the time-series information of the domain name further includes

information indicating host names of one or more name servers used for the operation of the domain name in time series;

the pattern information further includes

information indicating a pattern of time-series changes in operation form in a case in which the domain name is operated at a same time or while switching between a plurality of name servers, and

the processing circuitry, to specify whether the time-series change in operation form of the input domain name corresponds to any of the patterns shown in the pattern information, is further configured to

specify whether or not a change in operation form in a period before and after re-registration of the domain name corresponds to a pattern shown in the pattern information based on the pattern information in response to determination that the domain name has been re-registered on the basis of the time-series information of the input domain name, and specify the candidates for the operation form of the domain name after the predetermined date and time based on the specified pattern.

4. A method executed by a determination device, the method comprising:

receiving an input of time-series information indicating an operation form of a domain name up to a predetermined date and time in time series;

specifying whether a time-series change in the operation form of the domain name corresponds to any of patterns shown in pattern information based on the time-series information of the domain name and the pattern information indicating patterns of time-series changes in the operation form of the domain name, and specifying candidates for the operation form of the domain name after the predetermined date and time based on a specified pattern corresponding to the time-series change in the operation form of the domain name;

determining is a possibility that the operation form of the domain name will change to malicious use based on the specified candidates for the operation form of the domain name after the predetermined date and time, the operation form of a domain name includes whether or not the domain name is used maliciously and whether or not the domain name is used for domain parking;

continuously updating, in real time, a blacklist to include the domain name when the domain name is determined to be used maliciously; and

performing at least one of web filtering or domain name filtering based on the blacklist after being updated to include the domain name that is determined to be used maliciously.

5. A non-transitory computer readable storage medium having stored therein a determination program for causing a computer to execute a process comprising:

receiving an input of time-series information indicating an operation form of a domain name up to a predetermined date and time in time series;

specifying whether a time-series change in the operation form of the domain name corresponds to any of patterns shown in pattern information based on the time-series information of the domain name and the pattern information indicating patterns of time-series changes in the operation form of the domain name, and specifying candidates for the operation form of the domain name after the predetermined date and time based on a specified pattern corresponding to the time-series change in the operation form of the domain name;

determining a possibility that the operation form of the domain name will change to malicious use based on the specified candidates for the operation form of the domain name after the predetermined date and time, the operation form of a domain name includes whether or not the domain name is used maliciously and whether or not the domain name is used for domain parking;

continuously updating, in real time, a blacklist to include the domain name when the domain name is determined to be used maliciously; and

performing at least one of web filtering or domain name filtering based on the blacklist after being updated to include the domain name that is determined to be used maliciously.

Assignments (2)
CHANGE OF NAME Recorded Aug 20, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072556/0180 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2023
From: CHIBA, DAIKI; AKIYAMA, MITSUAKI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 062793/0817 →
Continuity (1)
Related Publication 20230308478A1 · Sep 28, 2023
References Cited (24)
US 10728273B1 · Okubo · 2020 [cited by examiner]
US 10958668B1 · Wang · 2021 [cited by examiner]
US 20110283357A1 · Pandrangi · 2011 [cited by examiner]
US 20150106494A1 · Bhuiyan et al. · 2015 [cited by applicant]
US 20170208089A1 · Merza · 2017 [cited by examiner]
US 20170295187A1 · Havelka · 2017 [cited by examiner]
US 20180069883A1 · Meshi · 2018 [cited by examiner]
US 20180227321A1 · Freund · 2018 [cited by examiner]
US 20180270254A1 · Chiba et al. · 2018 [cited by applicant]
US 20190180032A1 · Shibahara · 2019 [cited by examiner]
US 20200007564A1 · Xie · 2020 [cited by examiner]
US 20200045077A1 · Chiba et al. · 2020 [cited by applicant]
US 20200349430A1 · Schmidtler · 2020 [cited by examiner]
US 20210014252A1 · Usher · 2021 [cited by examiner]
CN 110290116A · 2019 [cited by examiner]
EP 2860946A2 · 2015 [cited by applicant]
JP 201576892A · 2015 [cited by applicant]
JP 6196008B2 · 2017 [cited by applicant]
Chiba et al., , “Detecting Malicious Domain Names based on the Time series Analysis of Attackers Network Resources” (Year: 2015). [cited by examiner]
International Search Report and Written Opinion mailed on Nov. 24, 2020, received for PCT Application PCT/JP2020/032935, filed on Aug. 31, 2020, 10 pages including English Translation. [cited by applicant]
Chiba et al., “Detecting Malicious Domain Names Based on the Time-series Analysis of Attackers Network Resources”, IEICE Technical Report, vol. 115, No. 80, Jun. 4, 2015, pp. 51-56. (with English Abstract). [cited by applicant]
Hariu et al., “R&D of cyber attack countermeasure technology that supports NTT Group's security / business to confront escalating cyber attacks”, NTT Technical Journal, vol. 30, No. 2, Feb. 1, 2018, pp. 19-25 (12 pages … [cited by applicant]
Tomatsuri et al., “A Large-scale Analysis of Parked Domain Names”, Information Processing Society of Japan, Available Online at: https://ipsj.ixsq.nil.ac.jp/ej/?action=pages_view_main&active_action=repository_view_main_… [cited by applicant]
Daiki Chiba, et al., “DomainChroma: Building actionable threat intelligence from malicious domain names” 1 Computers & Security, Elsevier, vol. 77, Apr. 6, 2018, 24 pages, XP085485739. [cited by applicant]