IP Library Patent Application 18950923
Patent Application
App. No. 18/950,923

MACHINE LEARNING UNIFORM RESOURCE LOCATOR (URL) CLASSIFIER

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/950,923
Abstract

Aspects of the disclosure relate to URL classification. A computing platform may receive, from an enterprise user device, a request to evaluate a URL. The computing platform may execute one or more feature enrichment actions on the URL to identify one or more data points corresponding to the URL, which may include crawling the URL to extract metadata for the URL. The computing platform may input, into a URL classification model, the one or more data points corresponding to the URL, which may cause the URL classification model to output a maliciousness score indicative of a degree to which the URL is malicious. The computing platform may send, to the enterprise user device, a malicious score notification and one or more commands directing the enterprise user device to display the malicious score notification, which may cause the enterprise user device to display the malicious score notification.

Claims (53)

1 . A computing platform comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive, from an enterprise user device, a request to evaluate a uniform resource locator (URL);

crawl the URL to extract metadata for the URL and information corresponding to one or more redirects of the URL, wherein the information comprises a number of URLs accessed before the crawl reaches a final URL;

input the metadata and the information into a URL classification model to output a maliciousness score indicative of a degree to which the URL is malicious; and

cause a user device to display the maliciousness score.

2 . The computing platform of claim 1 , wherein extracting the information corresponding to the one or more redirects of the URL further comprises extracting one or more of: a number of redirects triggered, a type of redirection, or a number of hops.

3 . The computing platform of claim 2 , wherein outputting the maliciousness score by the URL classification model comprises:

comparing the number of hops to a hop threshold;

in response to identifying that the number of hops meets or exceeds the hop threshold, outputting a first maliciousness score indicating that the URL is malicious; and

in response to identifying that the number of hops is less than the hop threshold, outputting a second maliciousness score indicating that the URL is legitimate.

4 . The computing platform of claim 1 , wherein crawling the URL comprises executing one or more feature enrichment actions on the URL to identify one or more data points corresponding to the URL, and wherein the one or more data points are further input into the URL classification model.

5 . The computing platform of claim 4 , wherein executing the one or more feature enrichment actions comprises extracting information indicating whether or not a protocol of the URL requires a secure connection.

6 . The computing platform of claim 4 , wherein executing the one or more feature enrichment actions comprises:

extracting a domain age corresponding to the URL;

comparing the domain age to a threshold domain age;

if the domain age exceeds the threshold domain age, classifying the URL into a first category; and

if the domain age does not exceed the threshold domain age, classifying the URL into a second category.

7 . The computing platform of claim 4 , wherein executing the one or more feature enrichment actions comprises extracting block rate information corresponding to the URL, wherein the block rate information indicates a number of times the URL was blocked and a number of times the URL was unblocked.

8 . The computing platform of claim 4 , wherein executing the one or more feature enrichment actions comprises extracting manual classification information corresponding to the URL.

9 . The computing platform of claim 4 , wherein executing the one or more feature enrichment actions comprises extracting information indicating whether one or more of an IPv4 or an IPv6 network address is present in a redirect chain for the URL.

10 . The computing platform of claim 9 , wherein outputting the maliciousness score by the URL classification model comprises:

in response to identifying that one or more of the IPv4 or the IPv6 network address is present in the redirect chain for the URL, outputting a first maliciousness score indicating that the URL is malicious; and

in response to identifying that neither the IPv4 or the IPv6 network address are present in the redirect chain for the URL, outputting a second maliciousness score indicating that the URL is legitimate.

11 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

compare the maliciousness score to a predetermined maliciousness threshold; and

based on identifying that the maliciousness score exceeds the predetermined maliciousness threshold, send one or more commands to a network computing device directing the network computing device to perform one or more network security actions, wherein sending the one or more commands directing the network computing device to perform the one or more network security actions causes the network computing device to perform the one or more network security actions.

12 . The computing platform of claim 1 , wherein causing the user device to display the maliciousness score comprises sending a maliciousness score notification and one or more commands directing the user device to display the maliciousness score notification, wherein sending the maliciousness score notification and the one or more commands directing the user device to display the maliciousness score notification causes the user device to display the maliciousness score.

13 . A method comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

receiving, from an enterprise user device, a request to evaluate a uniform resource locator (URL);

crawl the URL to extract metadata for the URL and information corresponding to one or more redirects of the URL, wherein the information comprises a number of URLs accessed before the crawl reaches a final URL;

inputting the metadata and the information into a URL classification model to output a maliciousness score indicative of a degree to which the URL is malicious; and

causing a user device to display the maliciousness score.

14 . The method of claim 13 , wherein extracting the information corresponding to the one or more redirects of the URL further comprises extracting one or more of: a number of redirects triggered, a type of redirection, or a number of hops.

15 . The method of claim 13 , wherein crawling the URL comprises executing one or more feature enrichment actions on the URL to identify one or more data points corresponding to the URL, and wherein the one or more data points are further input into the URL classification model.

16 . The method of claim 15 , wherein executing the one or more feature enrichment actions comprises:

extracting a domain age corresponding to the URL;

comparing the domain age to a threshold domain age;

in response to identifying that the domain age exceeds the threshold domain age, classifying the URL into a first category; and

in response to identifying that the domain age does not exceed the threshold domain age, classifying the URL into a second category.

17 . The method of claim 15 , wherein executing the one or more feature enrichment actions comprises extracting manual classification information corresponding to the URL.

18 . The method of claim 15 , wherein executing the one or more feature enrichment actions comprises extracting information indicating whether one or more of an IPv4 or an IPv6 network address is present in a redirect chain for the URL.

19 . The method of claim 13 , further comprising:

comparing the maliciousness score to a predetermined maliciousness threshold; and

based on identifying that the maliciousness score exceeds the predetermined maliciousness threshold, sending one or more commands to a network computing device directing the network computing device to perform one or more network security actions, wherein sending the one or more commands directing the network computing device to perform the one or more network security actions causes the network computing device to perform the one or more network security actions.

20 . One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

receive, from an enterprise user device, a request to evaluate a uniform resource locator (URL);

crawl the URL to extract metadata for the URL and information corresponding to one or more redirects of the URL, wherein the information comprises a number of URLs accessed before the crawl reaches a final URL;

input the metadata and the information into a URL classification model to output a maliciousness score indicative of a degree to which the URL is malicious; and

cause a user device to display the maliciousness score.

Assignments (2)
INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Dec 9, 2025
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 073910/0027 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →