IP Library › Granted Patent US 12,255,918
Granted Patent B2
US 12,255,918 · App. 17/353,641 · Granted Mar 18, 2025

Techniques for determining threat intelligence for network infrastructure analysis

Inventors: Adam Hunt (El Cerrito, CA); Jonas Edgeworth (San Francisco, CA); Chris Kiernan (San Francisco, CA); Elias Manousos (San Francisco, CA); David Pon (Sunnyvale, CA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/1483G06F21/51G06F21/562H04L41/22H04L63/08H04L63/1425H04L43/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,255,918
App. No.
17/353,641
Filed
Jun 21, 2021
Granted
Mar 18, 2025
Kind
B2
Examiner
KORSAK, OLEG
Art Unit
2492
USPC
726/22
Abstract

Embodiments of the present disclosure are directed to a network analytic system for tracking and analysis of network infrastructure for network-based digital assets. The network analytic system can detect and track a relationship between assets based on one or more attributes related or shared between any given assets. The network analytic system can analyze network-based digital assets to determine information about a website (e.g., information about electronic documents, such as web pages) that has be used to detect phishing and other abuse of the website. The network analytic system can analyze data about network-based assets to determine whether any are being used or connected to use of unauthorized or malicious activity or known network-based assets. Based on the relationship identified, the network analytic system can associate or link assets together. The network analytic system may provide an interface to view data sets generated by the network analytic system.

Claims (52)

1. A computer-implemented method comprising, at a computer system:

accepting a crawl configuration, which specifies a sequence of internet-facing assets to be monitored, based on verification that the crawl configuration is free of errors;

selecting a proxy server via which to access an internet-facing asset, which is included in the sequence of internet-facing assets, based on the crawl configuration, the proxy server enabling a bot to anonymously interact with the internet-facing asset;

selecting the bot, which obtains data from the internet-facing asset by accessing the internet-facing asset anonymously via the proxy server, based on the crawl configuration;

monitoring the internet-facing asset according to the crawl configuration, wherein the monitoring comprises identifying an event that is indicated by the data, which is obtained by the bot, by analyzing the data;

based on the event being identified, causing data related to the event to be displayed on a display device;

analyzing network data associated with the event; and

causing information related to the network data to be displayed on the display device.

2. The computer-implemented method of claim 1 , wherein accepting the crawl configuration comprises:

accepting the crawl configuration based on verification that the crawl configuration includes requisite username and password information.

3. The computer-implemented method of claim 1 , wherein the crawl configuration indicates an order in which the internet-facing assets are to be monitored, the order based on how close links to the internet-facing assets are to a root directory of a web page.

4. The computer-implemented method of claim 1 , wherein the proxy server simulates access of the internet-facing asset by devices from different geographic locations.

5. The computer-implemented method of claim 1 , wherein the proxy server simulates access of the internet-facing asset by different types of web browsers.

6. The computer-implemented method of claim 1 , wherein selecting the proxy server comprises:

selecting the proxy server from a plurality of proxy servers based on the crawl configuration, which specifies the sequence of the internet-facing assets to be monitored.

7. The computer-implemented method of claim 1 , wherein selecting the bot comprises:

selecting the bot from a plurality of bots based on the crawl configuration, which specifies the sequence of the internet-facing assets to be monitored.

8. The computer-implemented method of claim 1 , wherein monitoring the internet-facing asset comprises:

monitoring the internet-facing asset according to a rule that is defined based on a user-specified keyword.

9. The computer-implemented method of claim 1 , wherein analyzing the network data comprises:

analyzing the network data, which indicates Internet activity associated with the event.

10. A system comprising:

memory; and

a processing system coupled to the memory, the processing system configured to:

select a proxy server via which to access an internet-facing asset based on a crawl configuration that indicates an order in which a plurality of internet-facing assets, which includes the internet-facing asset, are to be monitored, the order based on how close a plurality of respective links to the plurality of internet-facing assets are to a root directory of a web page, the proxy server enabling a bot to anonymously interact with the internet-facing asset;

based on the crawl configuration, select the bot, which obtains data from the internet-facing asset by accessing the internet-facing asset anonymously via the proxy server;

monitor the internet-facing asset according to the crawl configuration, wherein the monitoring comprises identifying an event that is indicated by the data, which is obtained by the bot, by analyzing the data;

based on the event being identified, cause data related to the event to be displayed on a display device;

analyze network data associated with the event; and

cause information related to the network data to be displayed on the display device.

11. The system of claim 10 , wherein the processing system is further configured to: accept the crawl configuration based on verification that the crawl configuration is free of errors.

12. The system of claim 11 , wherein the processing system is configured to:

accept the crawl configuration based on verification that the crawl configuration includes requisite username and password information.

13. The system of claim 10 , wherein the proxy server simulates access of the internet-facing asset by devices from different geographic locations.

14. The system of claim 10 , wherein the proxy server simulates access of the internet-facing asset by different types of web browsers.

15. The system of claim 10 , wherein the processing system is configured to:

select the proxy server from a plurality of proxy servers based on the crawl configuration, which indicates the order in which the plurality of internet-facing assets are to be monitored.

16. The system of claim 10 , wherein the processing system is configured to:

select the bot from a plurality of bots based on the crawl configuration, which indicates the order in which the plurality of internet-facing assets are to be monitored.

17. The system of claim 10 , wherein the processing system is configured to:

monitor the internet-facing asset according to a rule that is defined based on a user-specified keyword.

18. The system of claim 10 , wherein the processing system is configured to:

analyze the network data, which indicates Internet activity associated with the event.

19. A non-transitory computer-readable storage medium storing instructions that, when executed, cause a processor-based system to perform operations, the operations comprising:

accept a crawl configuration, which specifies a sequence of internet-facing assets to be monitored, based on verification that the crawl configuration is free of errors;

select a proxy server via which to access an internet-facing asset, which is included in the sequence of internet-facing assets, based on the crawl configuration, the proxy server enabling a bot to anonymously interact with the internet-facing asset;

select the bot, which is configured to obtain data from the internet-facing asset by accessing the internet-facing asset anonymously via the proxy server, based on the crawl configuration;

monitor the internet-facing asset according to the crawl configuration, wherein the monitoring comprises identifying an event that is indicated by the data, which is obtained by the bot, by analyzing the data;

based on the event being identified, cause data related to the event to be displayed on a display device;

analyze network data associated with the event; and

cause information related to the network data to be displayed on the display device.

20. The non-transitory computer-readable storage medium of claim 19 , wherein the crawl configuration indicates an order in which the internet-facing assets are to be monitored, the order based on how close links to the internet-facing assets are to a root directory of a web page.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2021
From: RISKIQ, INC.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 057621/0212 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2021
From: HUNT, ADAM; EDGEWORTH, JONAS; KIERNAN, CHRIS; MANOUSOS, ELIAS; PON, DAVID
To: RISKIQ, INC.
Reel/Frame 056746/0700 →
Continuity (3)
Continuation 15677956 · Aug 15, 2017
Provisional Application 62375068 · Aug 15, 2016
Related Publication 20210314354A1 · Oct 7, 2021
References Cited (95)
US 7035842B2 · Kauffman et al. · 2006 [cited by applicant]
US 7080073B1 · Jiang · 2006 [cited by examiner]
US 7296222B1 · Sakairi · 2007 [cited by applicant]
US 7831611B2 · Roberts et al. · 2010 [cited by applicant]
US 8291500B1 · Bojaxhi et al. · 2012 [cited by applicant]
US 8407791B2 · Granstedt et al. · 2013 [cited by applicant]
US 8499032B2 · Matkowsky · 2013 [cited by applicant]
US 8516377B2 · Dixon et al. · 2013 [cited by applicant]
US 8583612B2 · Bennett · 2013 [cited by applicant]
US 8701185B2 · Krishnamurthy et al. · 2014 [cited by applicant]
US 8881283B2 · Tuvell et al. · 2014 [cited by applicant]
US 8954573B2 · Hugard, IV et al. · 2015 [cited by applicant]
US 9021260B1 · Falk et al. · 2015 [cited by applicant]
US 9049207B2 · Hugard, IV et al. · 2015 [cited by applicant]
US 9070110B2 · Shih et al. · 2015 [cited by applicant]
US 9172611B2 · Guruswamy · 2015 [cited by applicant]
US 9438615B2 · Gladstone et al. · 2016 [cited by applicant]
US 9438616B2 · Singla et al. · 2016 [cited by applicant]
US 9569471B2 · Sharan et al. · 2017 [cited by applicant]
US 9591027B2 · Molloy et al. · 2017 [cited by applicant]
US 10210255B2 · Crabtree · 2019 [cited by examiner]
US 10860962B2 · Crabtree · 2020 [cited by examiner]
US 20030188194A1 · Currie et al. · 2003 [cited by applicant]
US 20040093408A1 · Hirani et al. · 2004 [cited by applicant]
US 20050289084A1 · Thayer et al. · 2005 [cited by applicant]
US 20060015722A1 · Rowan et al. · 2006 [cited by applicant]
US 20060059557A1 · Markham et al. · 2006 [cited by applicant]
US 20060068755A1 · Shraim · 2006 [cited by examiner]
US 20060069697A1 · Shraim · 2006 [cited by examiner]
US 20060095586A1 · Adelman et al. · 2006 [cited by applicant]
US 20060161644A1 · Adelman et al. · 2006 [cited by applicant]
US 20070011168A1 · Keohane et al. · 2007 [cited by applicant]
US 20070094500A1 · Shannon et al. · 2007 [cited by applicant]
US 20070107053A1 · Shraim · 2007 [cited by examiner]
US 20070192853A1 · Shraim · 2007 [cited by examiner]
US 20070217371A1 · Sinha · 2007 [cited by applicant]
US 20070255821A1 · Ge · 2007 [cited by examiner]
US 20070294352A1 · Shraim · 2007 [cited by examiner]
US 20070294762A1 · Shraim · 2007 [cited by examiner]
US 20070299777A1 · Shraim · 2007 [cited by examiner]
US 20070299915A1 · Shraim · 2007 [cited by examiner]
US 20090327849A1 · Kavanagh et al. · 2009 [cited by applicant]
US 20100042622A1 · Matkowsky · 2010 [cited by applicant]
US 20110225142A1 · McDonald · 2011 [cited by applicant]
US 20110276716A1 · Coulson et al. · 2011 [cited by applicant]
US 20120023153A1 · Karasaridis · 2012 [cited by applicant]
US 20120042381A1 · Antonakakis et al. · 2012 [cited by applicant]
US 20120054869A1 · Yen et al. · 2012 [cited by applicant]
US 20120259833A1 · Paduroiu · 2012 [cited by examiner]
US 20130227141A1 · Schmidt et al. · 2013 [cited by applicant]
US 20130246605A1 · Vinay et al. · 2013 [cited by applicant]
US 20130247184A1 · Mahadik et al. · 2013 [cited by applicant]
US 20140033307A1 · Schmidtler · 2014 [cited by applicant]
US 20140096251A1 · Doctor et al. · 2014 [cited by applicant]
US 20140090058A1 · Ward et al. · 2014 [cited by applicant]
US 20140173739A1 · Ahuja et al. · 2014 [cited by applicant]
US 20140189864A1 · Wang et al. · 2014 [cited by applicant]
US 20140380482A1 · Thomas et al. · 2014 [cited by applicant]
US 20150106357A1 · Sun · 2015 [cited by examiner]
US 20150207809A1 · Macaulay · 2015 [cited by applicant]
US 20160044054A1 · Stiansen · 2016 [cited by examiner]
US 20160112284A1 · Pon et al. · 2016 [cited by applicant]
US 20170006054A1 · Stiansen · 2017 [cited by applicant]
US 20180048673A1 · Hunt et al. · 2018 [cited by applicant]
WO 2013044748A1 · 2013 [cited by applicant]
Long et al. (Google Hacking for Penetration Testers, Syngress Publishing, 2005, 529 pages) (Year: 2005). [cited by examiner]
“PassiveTotal (Introducing PassiveTotal (Nutmeg) and Enterprise Services”, Jun. 2, 2015, 3 Pages. [cited by applicant]
Khoury et al., “An Efficient Web Page Change Detection System Based on an Optimized Hungarian Algorithm”, IEEE 2007, pp. 599-613. [cited by applicant]
Pan et al., “Anomaly Based Web Phishing Page Detection,” IEEE 2006, 10 Pages. [cited by applicant]
U.S. Appl. No. 15/677,956, Advisory Action dated Jan. 7, 2021. [cited by applicant]
U.S. Appl. No. 15/677,956, Final Office Action dated Jan. 30, 2018. [cited by applicant]
U.S. Appl. No. 15/677,956, Final Office Action dated Dec. 27, 2018. [cited by applicant]
U.S. Appl. No. 15/677,956, Final Office Action dated Nov. 4, 2019. [cited by applicant]
U.S. Appl. No. 15/677,956, Final Office Action dated Jul. 30, 2020. [cited by applicant]
U.S. Appl. No. 15/677,956, Non-Final Office Action dated Aug. 15, 2017. [cited by applicant]
U.S. Appl. No. 15/677,956, Non-Final Office Action dated Jun. 20, 2018. [cited by applicant]
U.S. Appl. No. 15/677,956, Non-Final Office Action dated May 24, 2019. [cited by applicant]
U.S. Appl. No. 15/677,956, Non-Final Office Action dated Apr. 13, 2020. [cited by applicant]
U.S. Appl. No. 15/677,956, Notice of Allowance dated Feb. 17, 2021. [cited by applicant]
World Intellectual Property Organization, Application No. PCT/US17/47017, International Search Report dated Nov. 7, 2017. [cited by applicant]
Notice of Allowance Issued in U.S. Appl. No. 17/103,916, Mailed Date: Dec. 29, 2021, 10 Pages. [cited by applicant]
“Domain Name System Security Extensions”, Retrieved From: https://en.wikipedia.org/wiki/ Domain_Name_System_Security_Extensions, Jan. 25, 2016, 19 Pages. [cited by applicant]
“Server Fault; How can I find all of the domain names owned by a company?”, Retrieved from <http://serverfault.com/questions/231432/how-can-i-find-all-of-the-domain-names-owned-bya- company>, Retrieved on Oct. 21, 2014,… [cited by applicant]
Final Office Action mailed on Apr. 16, 2020, in U.S. Appl. No. 16/237,734 (MS#800533-US02-CON), 8 pages. [cited by applicant]
Final Office Action mailed on Feb. 22, 2018, in U.S. Appl. No. 14/520,029 (MS#800533-US01), 23 pages. [cited by applicant]
Final Office Action mailed on Sep. 9, 2016, in U.S. Appl. No. 14/520,029 (MS#800533-US01), 22 pages. [cited by applicant]
Google Answers: Domains Owned Search, Retrieved from http://answers.google.com/answers/threadview? id=566090>, Retrieved on Oct. 21, 2014, Posted on Sep. 9, 2005, 6 pages. [cited by applicant]
Laurie, et al., “DNS Security (DNSSEC) Hashed Authenticated Denial of Existence (RFC 5155 section 1.1)”, Retrieved From: https://datatracker.ietf.org/doc/html/rfc5155#section-1.1, 2008, 53 Pages. [cited by applicant]
Non-Final Office Action mailed on Aug. 8, 2019, in U.S. Appl. No. 16/237,734 (MS#800533-US02-CON), 10 pages. [cited by applicant]
Non-Final Office Action mailed on Feb. 1, 2016, in U.S. Appl. No. 14/520,029 (MS#800533-US01), 19 pages. [cited by applicant]
Non-Final Office Action mailed on Feb. 13, 2015, in U.S. Appl. No. 14/520,029 (MS#800533-US01), 13 pages. [cited by applicant]
Non-Final Office Action mailed on Jun. 30, 2017, in U.S. Appl. No. 14/520,029 (MS#800533-US01), 23 pages. [cited by applicant]
Notice of Allowance mailed on Aug. 27, 2018, in U.S. Appl. No. 14/520,029 (MS#800533-US01), 9 pages. [cited by applicant]
Notice of Allowance mailed on Jul. 15, 2020, in U.S. Appl. No. 16/237,734 (MS#800533-US02-CON), 9 pages. [cited by applicant]
Notice of Allowance mailed on Sep. 2, 2015, in U.S. Appl. No. 14/520,029 (MS#800533-US01), 8 pages. [cited by applicant]