IP Library › Granted Patent US 9,173,801
Granted Patent B2
US 9,173,801 · App. 14/445,018 · Granted Nov 3, 2015

Graphic display of security threats based on indications of access to newly registered domains

Inventor: Munawar Monzy Merza (Albuquerque, NM)
Assignee: Splunk, Inc.
A61G17/0073A61G17/04H04L63/1416H04L63/1441A61G2017/041A61G2017/042A61G2017/044H04L61/1511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,173,801
App. No.
14/445,018
Granted
Nov 3, 2015
Kind
B2
Abstract

Domain names are determined for each computational event in a set, each event detailing requests or posts of webpages. A number of events or accesses associated with each domain name within a time period is determined. A registrar is further queried to determine when the domain name was registered. An object is generated that includes a representation of the access count and an age since registration for each domain names. A client can interact with the object to explore representations of domain names associated with high access counts and recent registrations. Upon determining that a given domain name is suspicious, a rule can be generated to block access to the domain name.

Claims (50)

1. A method, comprising:

retrieving data from one or more events in a data store having time stamps that fall within an identified time period, each of the one or more events including information relating to an access to a domain name;

displaying a visual representation of the retrieved data in a scatter plot for the identified time period that includes selectable points, each selectable point representing a domain name, each selectable point in the scatter plot is positioned to reflect (i) an age since a registration time with a registrar for the domain name represented by that selectable point, and (ii) an access count indicating how many times the domain name was accessed;

determining one or more domain names represented by a selectable point in the scatter plot that is a potential security threat based at least in part on both (i) a number of accesses to each of the domain names determined from the one or more events, and (ii) how recently each of the domain names was registered with a registrar;

wherein the method is performed by one or more computing devices.

2. The method of claim 1 , wherein the one or more events include unstructured data.

3. The method of claim 1 , wherein the one or more events include machine data.

4. The method of claim 1 , wherein the one or more events include structured data.

5. The method of claim 1 , wherein the one or more events consists of a single event.

6. The method of claim 1 , wherein the one or more events are indexed based on associated timestamps.

7. The method of claim 1 , further comprising:

determining a total number of accesses in the one or more events for each domain name represented by a selectable point in the scatter plot.

8. The method of claim 1 , further comprising:

determining an age since a registration time with a registrar for each domain name represented by a selectable point in the scatter plot.

9. The method of claim 1 , wherein each domain name represented by a selectable point in the scatter plot is a domain name not previously detected prior to the identified time period.

10. The method of claim 1 , wherein each domain name represented by a selectable point in the scatter plot was identified in a number of the one or more events that exceeds a specified threshold.

11. The method of claim 1 , further comprising:

identifying one or more domain names represented by a selectable point in the scatter plot that is a potential security threat.

12. The method of claim 1 , further comprising:

determining one or more domain names represented by a selectable point in the scatter plot that is a potential security threat by identifying domain names with a number of accesses in the one or more events that are above a threshold count.

13. The method of claim 1 , further comprising:

determining one or more domain names represented by a selectable point in the scatter plot that is a potential security threat based at least in part on a number of accesses to each of the domain names determined from the one or more events.

14. The method of claim 1 , further comprising:

determining one or more domain names represented by a selectable point in the scatter plot that is a potential security threat based at least in part on how recently each of the domain names was registered with a registrar.

15. The method of claim 1 , further comprising:

in response to receiving user input indicating a selection of a selectable point in the scatter plot, displaying details pertaining to events in the one or more events that include information relating to a domain name represented by the selected selectable point.

16. The method of claim 1 , further comprising:

in response to receiving user input indicating a selection of a selectable point in the scatter plot, ignoring future occurrences of events where a domain name represented by the selected selectable point is found.

17. The method of claim 1 , further comprising:

in response to receiving user input indicating a selection of a selectable point in the scatter plot, causing denial of future accesses to a domain name represented by the selected selectable point.

18. The method of claim 1 , wherein retrieving data from the one or more events in the data store further comprises:

in response to receipt of user input to retrieve the data from the one or more events, applying a late binding schema to the one or more events to impose structure on data contained in the one or more events.

19. The method of claim 1 , wherein retrieving data from the one or more events in the data store further comprises:

determining the domain name to which each of the one or more events relates by extracting the domain name from each of the one or more events using a late binding schema.

20. An apparatus, comprising:

a subsystem, implemented at least partially in hardware, that retrieves data from one or more events in a data store having time stamps that fall within an identified time period, each of the one or more events including information relating to an access to a domain name;

a subsystem, implemented at least partially in hardware, that displays a visual representation of the retrieved data in a scatter plot for the identified time period that includes selectable points, each selectable point representing a domain name, each selectable point in the scatter plot is positioned to reflect (i) an age since a registration time with a registrar for the domain name represented by that selectable point, and (ii) an access count indicating how many times the domain name was accessed;

a subsystem, implemented at least partially in hardware, that determines one or more domain names represented by a selectable point in the scatter plot that is a potential security threat based at least in part on both (i) a number of accesses to each of the domain names determined from the one or more events, and (ii) how recently each of the domain names was registered with a registrar.

21. The apparatus of claim 20 , wherein the one or more events include at least one of: unstructured data, machine data, or structured data.

22. The apparatus of claim 20 , further comprising:

a subsystem, implemented at least partially in hardware, that identifies one or more domain names represented by a selectable point in the scatter plot that is a potential security threat.

23. The apparatus of claim 20 , further comprising:

a subsystem, implemented at least partially in hardware, that, in response to receiving user input indicating a selection of a selectable point in the scatter plot, displays details pertaining to events in the one or more events that include information relating to a domain name represented by the selected selectable point.

24. A non-transitory computer-readable medium storing one or more sequences of instructions, wherein execution of the one or more sequences of instructions by one or more processors causes the one or more processors to perform:

retrieving data from one or more events in a data store having time stamps that fall within an identified time period, each of the one or more events including information relating to an access to a domain name;

displaying a visual representation of the retrieved data in a scatter plot for the identified time period that includes selectable points, each selectable point representing a domain name, each selectable point in the scatter plot is positioned to reflect (i) an age since a registration time with a registrar for the domain name represented by that selectable point, and (ii) an access count indicating how many times the domain name was accessed;

determining one or more domain names represented by a selectable point in the scatter plot that is a potential security threat based at least in part on both (i) a number of accesses to each of the domain names determined from the one or more events, and (ii) how recently each of the domain names was registered with a registrar.

25. The non-transitory computer-readable medium of claim 24 , wherein the one or more events include at least one of: unstructured data, machine data, or structured data.

26. The non-transitory computer-readable medium of claim 24 , further comprising:

identifying one or more domain names represented by a selectable point in the scatter plot that is a potential security threat.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2015
From: MERZA, MUNAWAR MONZY
To: SPLUNK INC.
Reel/Frame 037071/0193 →
Continuity (3)
Continuation 13956262 · Jul 31, 2013
Provisional Application 61858506 · Jul 25, 2013
Related Publication 20150033332A1 · Jan 29, 2015