IP Library › Granted Patent US 11,159,943
Granted Patent B2
US 11,159,943 · App. 16/268,824 · Granted Oct 26, 2021

Security monitoring for wireless communication devices

Inventors: Anand J. Shah (Parsippany, NJ); Hans Raj Nahata (New Providence, NJ)
Assignee: Verizon Patent and Licensing Inc.
H04W12/121G06F16/9566H04L63/1416G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,159,943
App. No.
16/268,824
Granted
Oct 26, 2021
Kind
B2
Abstract

A computer device may include a memory configured to store instructions and a processor configured to execute the instructions to receive a request from a user equipment (UE) device to resolve a Domain Name System (DNS) query for a Uniform Resource Locator (URL) and determine that the URL corresponds to a malicious URL. The processor may be further configured to select to not resolve the DNS query in response to determining that the URL corresponds to a malicious URL and send an indication to the UE device that the URL corresponds to a malicious URL.

Claims (74)

1. A method comprising:

receiving, by a computer device, a request from a user equipment (UE) device to resolve a Domain Name System (DNS) query for a Uniform Resource Locator (URL);

determining, by the computer device, that the URL corresponds to a malicious URL;

selecting, by the computer device, to not resolve the DNS query in response to determining that the URL corresponds to a malicious URL;

sending, by the computer device, an indication to the UE device that the URL corresponds to a malicious URL;

receiving, by the computer device, a request from the UE device to resolve another DNS query for another URL;

determining, by the computer device, that the UE device has selected an advertisement blocking setting;

determining, by the computer device, that the other URL is associated with an advertisement; and

selecting, by the computer device, to not resolve the other DNS query in response to determining that the other URL is associated with an advertisement and that the UE device has selected the advertisement blocking setting.

2. The method of claim 1 , further comprising:

receiving a request from the UE device to proceed with resolving the DNS query;

resolving the DNS query to identify an Internet Protocol (IP) address associated with URL, in response to receiving the request from the UE device to proceed with resolving the DNS query; and

providing the identified IP address to the UE device.

3. The method of claim 1 , wherein determining that the URL corresponds to a malicious URL includes:

accessing a malicious URL database that stores a list of identified malicious URLs.

4. The method of claim 3 , wherein determining that the URL corresponds to a malicious URL includes:

receiving an indication from another UE device identifying the URL as a malicious URL; and

adding the URL to the malicious URL database, in response to receiving the indication from the other UE device.

5. The method of claim 1 , wherein determining that the URL corresponds to a malicious URL includes:

providing the URL as an input to a machine learning model trained to identify malicious URLs.

6. The method of claim 5 , further comprising:

generating an input feature vector from the URL based on one or more of lexical features associated with the URL, location features associated with the URL, and UE device use features associated with the URL.

7. The method of claim 1 , wherein determining that the URL is associated with an advertisement includes:

accessing an advertisement URL database that stores a list of identified advertisement URLs.

8. The method of claim 1 , wherein determining that the URL is associated with an advertisement includes:

providing the URL as an input to a machine learning model trained to identify advertisement URLs.

9. A computer device comprising:

a memory configured to store instructions; and

a processor configured to execute the instructions to:

receive a request from a user equipment (UE) device to resolve a Domain Name System (DNS) query for a Uniform Resource Locator (URL);

determine that the URL corresponds to a malicious URL;

select to not resolve the DNS query in response to determining that the URL corresponds to a malicious URL;

send an indication to the UE device that the URL corresponds to a malicious URL;

receive a request from the UE device to resolve another DNS query for another URL;

determine that the UE device has selected an advertisement blocking setting;

determine that the other URL is associated with an advertisement; and

select to not resolve the other DNS query in response to determining that the other URL is associated with an advertisement and that the UE device has selected the advertisement blocking setting.

10. The computer device of claim 9 , wherein the processor is further configured to:

receive a request from the UE device to proceed with resolving the DNS query;

resolve the DNS query to identify an Internet Protocol (IP) address associated with URL, in response to receiving the request from the UE device to proceed with resolving the DNS query; and

provide the identified IP address to the UE device.

11. The computer device of claim 9 , wherein, when determining that the URL corresponds to a malicious URL, the processor is further configured to:

access a malicious URL database that stores a list of identified malicious URLs.

12. The computer device of claim 9 , wherein, when determining that the URL corresponds to a malicious URL, the processor is further configured to:

receive an indication from another UE device identifying the URL as a malicious URL; and

add the URL to the malicious URL database, in response to receiving the indication from the other UE device.

13. The computer device of claim 9 , wherein, when determining that the URL corresponds to a malicious URL, the processor is further configured to:

provide the URL as an input to a machine learning model trained to identify malicious URLs.

14. The computer device of claim 13 , wherein the processor is further configured to:

generate an input feature vector from the URL based on one or more of lexical features associated with the URL, location features associated with the URL, and UE device use features associated with the URL.

15. The computer device of claim 9 , wherein, when determining that the URL is associated with an advertisement, the computer device is further configured to at least one of:

access an advertisement URL database that stores a list of identified advertisement URLs, or

provide the URL as an input to a machine learning model trained to identify advertisement URLs.

16. A computer device comprising:

a memory configured to store instructions; and

a processor configured to execute the instructions to:

intercept a request to resolve a Domain Name System (DNS) query for a Uniform Resource Locator (URL);

send a DNS query request to a DNS server managed by a provider that manages the computer device or that provides wireless communication service to the computer device;

receive, from the DNS server, an indication to the computer device that the URL corresponds to a malicious URL;

generate a warning, to be displayed in a user interface, indicating that the URL corresponds to a malicious URL;

intercept another request for another DNS query for another URL;

provide an advertisement blocking setting associated with the computer device, to the DNS server; and

receive, from the DNS server, an indication that the other DNS query has not been resolved based on the provided advertisement blocking setting.

17. The computer device of claim 16 , wherein the processor is further configured to:

generate a security score for a user associated with the computer device, wherein the security score is based on demographic information associated with the user and a browsing history associated with the user.

18. The computer device of claim 16 , wherein the computer device includes a gateway device, wherein the gateway device is configured to:

receive the request to resolve the DNS query for the URL from a user equipment (UE) device;

determine that the UE device is subscribed to a DNS monitoring service; and

send the DNS query request to the DNS server managed by the provider that manages the computer device or that provides wireless communication service to the computer device in response to determining that the UE device is subscribed to the DNS monitoring service.

19. The computer device of claim 16 , wherein the processor is further configured to:

obtain security news; and

provide information relating to the obtained security news to a user equipment (UE) device associated with the computer device.

20. The computer device of claim 16 , wherein the processor is further configured to:

monitor one or more applications installed on a user equipment (UE) device, associated with the computer device, for security violations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2019
From: SHAH, ANAND J.; NAHATA, HANS RAJ
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 048253/0084 →
Continuity (1)
Related Publication 20200252803A1 · Aug 6, 2020
Cited By (3)
US 12,200,011 US 12,602,485 US 12,712,912