IP Library › Granted Patent US 12,126,639
Granted Patent B2
US 12,126,639 · App. 17/735,896 · Granted Oct 22, 2024

System and method for locating DGA compromised IP addresses

Inventors: Weihan Jiang (San Jose, CA); David Qianshan He (Cupertino, CA); Xuya Jiang (San Jose, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1425H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,126,639
App. No.
17/735,896
Granted
Oct 22, 2024
Kind
B2
Abstract

A system and method for locating DGA compromised IP addresses is provided. A domain name system (DNS) stream is received. The DNS stream is classified into DGA generated domains using a machine learning classifier to generate a classification output. User behavior profiling is performed to enhance the classification output. A verdict is generated based on the user behavior profiling of the classification output including identifying a compromised source IP address associated with a detected DGA malware attack.

Claims (43)

1. A system, comprising:

a processor configured to:

receive a domain name system (DNS) stream, wherein the DNS stream includes logs obtained from a plurality of network security devices;

classify the DNS stream into DGA generated domains using a machine learning classifier to generate a classification output;

perform user behavior profiling to enhance the classification output, comprising to:

determine that a DGA generated domain has a same source IP address as another DGA generated domain of a DGA domain cluster, wherein the DGA domain cluster includes one or more DGA generated domain; and

in response to a determination that the DGA generated domain has the same source IP address as the other DGA generated domain, add the DGA generated domain to the DGA domain cluster;

generate a verdict based on the user behavior profiling of the classification output including identifying a compromised source IP address associated with a detected DGA malware attack, comprising to:

compare a number of domains in the DGA domain cluster with a predefined threshold; and

in the event that the number of domains in the DGA domain cluster is equal to or exceeds the predefined threshold, determine that the source IP address associated with the DGA domain cluster is the compromised source IP address; and

perform an action on the compromised source IP address, wherein the action includes one or more of the following: block the compromised source IP address associated with the detected DGA malware attack, generate an alert including identification of the compromised source IP address, quarantine the compromised source IP address associated with the detected DGA malware attack, and/or generate a visualization and/or a report; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the DNS stream includes a plurality of events, wherein each event of the plurality of events comprises a DNS request and a source IP address.

3. The system of claim 1 , wherein the classifying of the DNS stream into the DGA generated domains comprises to:

classify the DNS stream into the DGA generated domains using a dictionary-based DGA.

4. The system of claim 1 , wherein the processor is further configured to block the compromised source IP address associated with the detected DGA malware attack.

5. The system of claim 1 , wherein the processor is further configured to generate an alert including the identification of the compromised source IP address.

6. The system of claim 1 , wherein the processor is further configured to quarantine the compromised source IP address associated with the detected DGA malware attack.

7. The system of claim 1 , wherein the generating of the verdict comprises to generate the verdict in near real-time.

8. The system of claim 1 , wherein the processor is further configured to generate visualizations, reports, and/or alerts based on the verdict.

9. A method, comprising:

receiving a domain name system (DNS) stream, wherein the DNS stream includes logs obtained from a plurality of network security devices;

classifying, using a processor, the DNS stream into DGA generated domains using a machine learning classifier to generate a classification output;

performing, using the processor, user behavior profiling to enhance the classification output, comprising:

determining that a DGA generated domain has a same source IP address as another DGA generated domain of a DGA domain cluster, wherein the DGA domain cluster includes one or more DGA generated domain; and

in response to a determination that the DGA generated domain has the same source IP address as the other DGA generated domain, adding the DGA generated domain to the DGA domain cluster;

generating, using the processor, a verdict based on the user behavior profiling of the classification output including identifying a compromised source IP address associated with a detected DGA malware attack, comprising:

comparing a number of domains in the DGA domain cluster with a predefined threshold; and

in the event that the number of domains in the DGA domain cluster is equal to or exceeds the predefined threshold, determining that a source IP address associated with the DGA domain cluster is the compromised source IP address; and

performing an action on the compromised source IP address, wherein the action includes one or more of the following: blocking the compromised source IP address associated with the detected DGA malware attack, generating an alert including identification of the compromised source IP address, quarantining the compromised source IP address associated with the detected DGA malware attack, and/or generating a visualization and/or a report.

10. The method of claim 9 , wherein the DNS stream includes a plurality of events, wherein each event of the plurality of events comprises a DNS request and a source IP address.

11. The method of claim 9 , wherein the classifying of the DNS stream into the DGA generated domains comprises:

classifying the DNS stream into the DGA generated domains using a dictionary-based DGA.

12. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving a domain name system (DNS) stream, wherein the DNS stream includes logs obtained from a plurality of network security devices;

classifying the DNS stream into DGA generated domains using a machine learning classifier to generate a classification output;

performing user behavior profiling to enhance the classification output, comprising:

determining that a DGA generated domain has a same source IP address as another DGA generated domain of a DGA domain cluster, wherein the DGA domain cluster includes one or more DGA generated domain; and

in response to a determination that the DGA generated domain has the same source IP address as the other DGA generated domain, adding the DGA generated domain to the DGA domain cluster;

generating a verdict based on the user behavior profiling of the classification output including identifying a compromised source IP address associated with a detected DGA malware attack, comprising:

comparing a number of domains in the DGA domain cluster with a predefined threshold; and

in the event that the number of domains in the DGA domain cluster is equal to or exceeds the predefined threshold, determining that a source IP address associated with the DGA domain cluster is the compromised source IP address; and

performing an action on the compromised source IP address, wherein the action includes one or more of the following: blocking the compromised source IP address associated with the detected DGA malware attack, generating an alert including identification of the compromised source IP address, quarantining the compromised source IP address associated with the detected DGA malware attack, and/or generating a visualization and/or a report.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2022
From: JIANG, WEIHAN; HE, DAVID QIANSHAN; JIANG, XUYA
To: PALO ALTO NETWORKS, INC.
Reel/Frame 060403/0426 →
Continuity (1)
Related Publication 20230362176A1 · Nov 9, 2023
Cited By (1)
US 12,348,546