IP Library Granted Patent US 12,335,305
Granted Patent B2
US 12,335,305 · App. 18/236,625 · Granted Jun 17, 2025

Systems and methods for detecting domain impersonation

Inventors: Simon Paul Tyler (Wiltshire, GB); Jackie Anne Maylor (Wiltshire, GB); Paul Sowden (London, GB); Meni Farjon (Ramat Gan, IL)
Assignee: Mimecast Services Ltd.
H04L63/1483G06F16/907G06F21/44G06F21/51G06F21/606H04L63/1416G06F2221/2119H04L61/4511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,305
App. No.
18/236,625
Granted
Jun 17, 2025
Kind
B2
Abstract

The invention is a security system providing domain name authentication for intrusion and malware prevention. The system is configured to analyze domain names, specifically analyze network metadata associated with said domain names, and further identify domain names attempting to impersonate or spoof domain names associated with a trusted entity or party.

Claims (47)

1. A system for domain name authentication, the system comprising:

at least one processor coupled to at least one memory containing instructions executable by the at least one processor to cause the system to:

maintain a database with a plurality of trusted domains;

analyze a domain, wherein analysis of the domain comprises comparing the domain with one or more of the plurality of trusted domains;

determine that the domain is similar but not identical to at least one of the trusted domains based on the comparison of the domain with one or more of the plurality of trusted domains;

determine a set of nameservers associated with the domain;

determine a set of nameservers associated with the at least one trusted domain that is similar but not identical to the domain;

determine if there is a match between the set of nameservers associated with the domain and the set of nameservers associated with the at least one trusted domain, wherein determining if there is a match between the set of nameservers associated with the domain and the set of nameservers associated with the at least one trusted domain comprises determining if the domain and the at least one trusted domain share a common set of nameservers; and

flag the domain as being legitimate or flag the domain as being illegitimate based on whether there is a match between the set of nameservers associated with the domain and the set of nameservers associated with the at least one trusted domain.

2. The system of claim 1 , wherein the domain is associated with an undelivered message intended to be delivered to a recipient.

3. The system of claim 1 , wherein the domain is associated with a received email message, and wherein the system flags the domain name as being legitimate and the email message as safe or flags the domain name as being illegitimate and the email message as potentially harmful based on whether there is a match between the set of nameservers associated with the domain and the set of nameservers associated with the at least one trusted domain.

4. The system of claim 3 , wherein the domain is associated with a sender of the email message.

5. The system of claim 1 , wherein determining that the domain is similar but not identical to at least one of the trusted domains based on the comparison of the domain with one or more of the plurality of trusted domains comprises:

determining that there is a positive level of resemblance between the domain and the one or more similar but not identical trusted domains of the plurality of trusted domains.

6. The system of claim 1 , wherein the domain is an unrecognized domain associated with a website, and wherein the system flags the domain as being legitimate and the website as safe or flags the domain as being illegitimate and the website as potentially dangerous based on whether there is a match between the set of nameservers associated with the domain and the set of nameservers associated with the at least one trusted domain.

7. The system of claim 1 , wherein the instructions further cause the system to:

determine an identity of a registrar for the domain and an identity of a registrar for the at least one of the trusted domains that are similar but not identical to the domain from the at least one domain registration system;

compare the identity of the registrar for the domain with the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain; and

flag the domain as being legitimate or flag the domain as being illegitimate based on whether the identity of the registrar for the domain is the same as or different than the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain.

8. The system of claim 1 , wherein the instructions further cause the system to:

determine an identity of a host for the domain and an identity of a host for the at least one of the trusted domains that are similar but not identical to the domain from the at least one domain registration system;

compare the identity of the host for the domain with the identity of the host for the at least one of the trusted domains that are similar but not identical to the domain; and

flag the domain as being legitimate or flag the domain as being illegitimate based on whether the identity of the host for the domain is the same as or different than the identity of the host for the at least one of the trusted domains that are similar but not identical to the domain.

9. The system of claim 1 , wherein at least one nameserver is a cloud nameserver.

10. A method for domain name authentication, the method implemented by a computer security system and comprising:

maintaining a database with a plurality of trusted domains;

analyzing a domain, wherein analysis of the domain comprises comparing the domain with one or more of the plurality of trusted domains;

determining that the domain is similar but not identical to at least one of the trusted domains based on the comparison of the domain with one or more of the plurality of trusted domains;

determine a set of nameservers associated with the domain;

determine a set of nameservers associated with the at least one trusted domain that is similar but not identical to the domain;

determine if there is a match between the set of nameservers associated with the domain and the set of nameservers associated with the at least one trusted domain, wherein determining if there is a match between the set of nameservers associated with the domain and the set of nameservers associated with the at least one trusted domain comprises determining if the domain and the at least one trusted domain share a common set of nameservers; and

flagging the domain as being legitimate or flag the domain as being illegitimate based on whether there is a match between the set of nameservers associated with the domain and the set of nameservers associated with the at least one trusted domain.

11. The method of claim 10 , wherein the domain is associated with an undelivered message intended to be delivered to a recipient.

12. The method of claim 10 , wherein the domain is associated with a received email message, and wherein the method flags the domain name as being legitimate and the email message as safe or flags the domain name as being illegitimate and the email message as potentially harmful based on whether there is a match between the set of nameservers associated with the domain and the set of nameservers associated with the at least one trusted domain.

13. The method of claim 12 , wherein the domain is associated with a sender of the email message.

14. The method of claim 10 , wherein determining that the domain is similar but not identical to at least one of the trusted domains based on the comparison of the domain with one or more of the plurality of trusted domains comprises:

determining that there is a positive level of resemblance between the domain and the one or more similar but not identical trusted domains of the plurality of trusted domains.

15. The method of claim 10 , wherein the domain is an unrecognized domain associated with a website, and wherein the method flags the domain as being legitimate and the website as safe or flags the domain as being illegitimate and the website as potentially dangerous based on whether there is a match between the set of nameservers associated with the domain and the set of nameservers associated with the at least one trusted domain.

16. The method of claim 10 , further comprising:

determining an identity of a registrar for the domain and an identity of a registrar for the at least one of the trusted domains that are similar but not identical to the domain from the at least one domain registration system;

comparing the identity of the registrar for the domain with the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain; and

flagging the domain as being legitimate or flag the domain as being illegitimate based on whether the identity of the registrar for the domain is the same as or different than the identity of the registrar for the at least one of the trusted domains that are similar but not identical to the domain.

17. The method of claim 10 , further comprising:

determining an identity of a host for the domain and an identity of a host for the at least one of the trusted domains that are similar but not identical to the domain from the at least one domain registration system;

comparing the identity of the host for the domain with the identity of the host for the at least one of the trusted domains that are similar but not identical to the domain; and

flagging the domain as being legitimate or flag the domain as being illegitimate based on whether the identity of the host for the domain is the same as or different than the identity of the host for the at least one of the trusted domains that are similar but not identical to the domain.

18. The method of claim 10 , wherein at least one nameserver is a cloud nameserver.

Continuity (3)
Continuation 16134317 · Sep 18, 2018
Provisional Application 62581860 · Nov 6, 2017
Related Publication 20240064171A1 · Feb 22, 2024
References Cited (47)
US 7559085B1 · Wahl · 2009 [cited by examiner]
US 8990933B1 · Magdalin · 2015 [cited by applicant]
US 9332022B1 · Ashley · 2016 [cited by examiner]
US 9762612B1 · Schiffman · 2017 [cited by examiner]
US 9774626B1 · Himler · 2017 [cited by examiner]
US 10721195B2 · Jakobsson · 2020 [cited by examiner]
US 10904286B1 · Liu · 2021 [cited by applicant]
US 11089055B1 · Sadovyi et al. · 2021 [cited by applicant]
US 11146576B1 · Mushtaq · 2021 [cited by applicant]
US 11496510B1 · Orhan · 2022 [cited by applicant]
US 20060047958A1 · Morais · 2006 [cited by applicant]
US 20070208940A1 · Adelman · 2007 [cited by examiner]
US 20080010538A1 · Satish et al. · 2008 [cited by applicant]
US 20080022013A1 · Adelman · 2008 [cited by examiner]
US 20080034211A1 · Shull · 2008 [cited by examiner]
US 20080307049A1 · Curran · 2008 [cited by examiner]
US 20090119402A1 · Shull et al. · 2009 [cited by applicant]
US 20090187992A1 · Poston · 2009 [cited by applicant]
US 20090300768A1 · Krishnamurthy · 2009 [cited by examiner]
US 20100235913A1 · Craioveanu et al. · 2010 [cited by applicant]
US 20100313266A1 · Feng · 2010 [cited by examiner]
US 20120167233A1 · Gillum · 2012 [cited by examiner]
US 20130086677A1 · Ma · 2013 [cited by examiner]
US 20140082726A1 · Dreller · 2014 [cited by examiner]
US 20140201844A1 · Buck · 2014 [cited by applicant]
US 20140259158A1 · Brown · 2014 [cited by examiner]
US 20140298460A1 · Xue · 2014 [cited by examiner]
US 20150213131A1 · Styler · 2015 [cited by examiner]
US 20160055490A1 · Keren · 2016 [cited by examiner]
US 20160315969A1 · Goldstein · 2016 [cited by examiner]
US 20160352772A1 · O'Connor · 2016 [cited by examiner]
US 20170034100A1 · Zink · 2017 [cited by examiner]
US 20170078321A1 · Maylor · 2017 [cited by examiner]
US 20170099314A1 · Klatt · 2017 [cited by examiner]
US 20170126730A1 · Oberheide · 2017 [cited by examiner]
US 20170230323A1 · Jakobsson · 2017 [cited by examiner]
US 20180027013A1 · Wright · 2018 [cited by examiner]
US 20180091478A1 · Jakobsson · 2018 [cited by examiner]
US 20190373002A1 · Mushtaq · 2019 [cited by applicant]
US 20200036751A1 · Kohavi · 2020 [cited by applicant]
US 20200067861A1 · Leddy · 2020 [cited by examiner]
US 20200358819A1 · Bowditch et al. · 2020 [cited by applicant]
US 20210026977A1 · Shivakumar et al. · 2021 [cited by applicant]
US 20210037006A1 · Belenko · 2021 [cited by applicant]
US 20210149957A1 · Grossman et al. · 2021 [cited by applicant]
US 20210320946A1 · Boshmaf et al. · 2021 [cited by applicant]
US 20220174092A1 · Farjon et al. · 2022 [cited by applicant]