IP Library › Granted Patent US 12,542,800
Granted Patent B2
US 12,542,800 · App. 18/360,421 · Granted Feb 3, 2026

Malicious domain monitoring and filtering using drift monitoring and contextual data

Inventor: Jerry McClurg (Savannah, TX)
Assignee: GOOGLE LLC
H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,800
App. No.
18/360,421
Granted
Feb 3, 2026
Kind
B2
Abstract

Example embodiments of the present disclosure provide for an example method including generating a baseline set of domains by comparing domains of interest to a group of existing registered domains. The domains of interest are generated using a permutation engine based on a first domain. The example method includes periodically generating a dynamic set of domains by comparing the domains of interest to an updated group of existing registered domains. The updated group is obtained in real-time. The example method includes determining a potentially malicious domain based on comparing the baseline set and dynamic set. The example method includes for each respective potentially malicious domain: obtaining an IP address associated with the potentially malicious domain and determining an IP address risk score. The example method includes determining a potentially malicious domain is a malicious domain based on the IP address risk score of the potentially malicious domain.

Claims (61)

1 . A computer-implemented method, comprising:

generating a baseline set of domains by comparing a plurality of domains of interest to a group of existing registered domains, wherein the domains of interest are generated using a permutation engine based on a first domain;

periodically generating a dynamic set of domains by comparing the plurality of domains of interest to an updated group of existing registered domains, wherein the updated group of existing registered domains is obtained in real-time;

determining at least one potentially malicious domain based on comparing the baseline set and dynamic set;

for each respective potentially malicious domain:

obtaining an internet protocol (IP) address associated with the potentially malicious domain;

determining a risk score for the respective potentially malicious domain by:

identifying one or more other different domains associated with the IP address by selecting a pre-defined number of domains associated with the IP address based on a domain registration date; and

determining an IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address; and

determining a first potentially malicious domain is a malicious domain based on the risk score of the first potentially malicious domain.

2 . The computer-implemented method of claim 1 , comprising:

automatically initiating a domain takedown action in response to determining the first potentially malicious domain is a malicious domain.

3 . The computer-implemented method of claim 1 , wherein identifying the one or more other different domains associated with the IP address comprises selecting a random subset of domains.

4 . The computer-implemented method of claim 1 , wherein identifying the one or more other different domains associated with the IP address comprises selecting a random subset of domains, wherein the random subset of domains comprises a pre-defined number of domains.

5 . The computer-implemented method of claim 1 , wherein determining the first potentially malicious domain is a malicious domain is based on the risk score of the first potentially malicious domain satisfying a criterion related to a threshold risk score.

6 . The computer-implemented method of claim 1 , wherein determining the IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address comprises:

obtaining a domain risk score for each respective domain of the one or more other different domains associated with the IP address; and

summing the obtained domain risk scores for each respective domain of the one or more other different domains.

7 . The computer-implemented method of claim 1 , wherein determining the IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address comprises:

obtaining a domain risk score for each respective domain of the one or more other different domains associated with the IP address; and

generating a weighted average of the domain risk scores for each respective domain of the one or more other different domains associated with the IP address.

8 . The computer-implemented method of claim 7 , wherein generating the weighted average of the domain risk scores for each respective domain of the one or more other different domains, comprises weighting more recently registered domain risk scores more heavily than earlier registered domain risk scores.

9 . A computing system, comprising:

one or more processors; and

one or more computer-readable media storing instructions that are executable to cause the one or more processors to perform operations, the operations comprising:

obtaining a first domain;

generating, using a permutation engine, a plurality of domains of interests;

generating a baseline set of domains by comparing the plurality of domains of interest to a group of registered domains, wherein the baseline set comprises at least a domain and an internet protocol (IP) address;

periodically, generating a dynamic set of domains by comparing the plurality of domains of interest to an updated group of existing registered domains, wherein the updated group of existing registered domains is obtained in real-time;

comparing, in response to generating the dynamic set of domains, the dynamic set to the baseline set to determine changes to at least one of the group of domains or an IP address for a domain being updated;

detecting, based on the comparison of the baseline set and the dynamic set, creation or deletion of one or more potentially malicious domains;

for each respective potentially malicious domain:

obtaining the IP address associated with the potentially malicious domain;

determining a risk score for the respective potentially malicious domain by:

identifying one or more other different domains associated with the IP address; and

determining an IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address by:

obtaining a domain risk score for each respective domain of the one or more other different domains associated with the IP address; and

generating a weighted average of the domain risk scores for each respective domain of the one or more other different domains associated with the IP address; and

determining a potentially malicious domain is a malicious domain based on the risk score.

10 . The computing system of claim 9 , wherein generating the dynamic set of domains occurs multiple times a day.

11 . The computing system of claim 9 , wherein determining the IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address comprises:

obtaining a domain risk score for each respective domain of the one or more other different domains associated with the IP address; and

generating a weighted average of the domain risk scores for each respective domain of the one or more other different domains associated with the IP address.

12 . The computing system of claim 11 , wherein generating the weighted average of the domain risk scores for each respective domain of the one or more other different domains, comprises weighting more recently registered domain risk scores more heavily than earlier registered domain risk scores.

13 . The computing system of claim 9 , wherein identifying one or more other different domains associated with the IP address comprises selecting a random subset of domains, wherein the random subset of domains comprises a pre-defined number of domains.

14 . The computing system of claim 9 , wherein identifying one or more other different domains associated with the IP address comprises selecting a pre-defined number of domains.

15 . The computing system of claim 14 , wherein the pre-defined number of domains are selected based on a domain registration date.

16 . The computing system of claim 9 , comprising:

automatically initiating a domain takedown action in response to determining the potentially malicious domain is a malicious domain.

17 . One or more non-transitory computer readable media storing instructions that are executable by one or more processors to perform operations comprising:

generating a baseline set of domains by comparing a plurality of domains of interest to a group of existing registered domains, wherein the domains of interest are generated using a permutation engine based on a first domain;

periodically generating a dynamic set of domains by comparing the plurality of domains of interest to an updated group of existing registered domains, wherein the updated group of existing registered domains is obtained in real-time;

determining at least one potentially malicious domain based on comparing the baseline set and dynamic set;

for each respective potentially malicious domain:

obtaining an IP address associated with the potentially malicious domain;

determining a risk score for the respective potentially malicious domain by:

identifying one or more other different domains associated with the IP address; and

determining an IP address risk score for the IP address based on data associated with the one or more other different domains associated with the IP address by:

obtaining a domain risk score for each respective domain of the one or more other different domains associated with the IP address; and

generating a weighted average of the domain risk scores for each respective domain of the one or more other different domains associated with the IP address; and

determining a first potentially malicious domain is a malicious domain based on the risk score of the first potentially malicious domain.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2023
From: MCCLURG, JERRY
To: GOOGLE LLC
Reel/Frame 064496/0990 →
Continuity (1)
Related Publication 20250039218A1 · Jan 30, 2025
References Cited (16)
US 8510411B2 · Coulson et al. · 2013 [cited by applicant]
US 8776224B2 · Krishnamurthy et al. · 2014 [cited by applicant]
US 9558497B2 · Carvalho · 2017 [cited by applicant]
US 10491614B2 · Grill · 2019 [cited by examiner]
US 10911477B1 · Kharraz · 2021 [cited by examiner]
US 11301560B2 · Prakash et al. · 2022 [cited by applicant]
US 11587080B2 · Wardman et al. · 2023 [cited by applicant]
US 11588826B1 · Lin · 2023 [cited by examiner]
US 20060068755A1 · Shraim · 2006 [cited by examiner]
US 20180351972A1 · Yu · 2018 [cited by examiner]
US 20200382533A1 · Nabeel · 2020 [cited by examiner]
US 20220124106A1 · Chiu · 2022 [cited by examiner]
US 20220279014A1 · Stokes, III · 2022 [cited by examiner]
US 20230123157A1 · Ramanan · 2023 [cited by examiner]
International Search Report and Written Opinion for Application No. PCT/US2024/039845, mailed Nov. 19, 2024, 14 pages. [cited by applicant]
BolsterAI, “Intuitive Methodology for Typosquatted Domains”, https://bolster.ai/solutions/typosquatting-protection, retrieved on Aug. 4, 2023, 8 pages. [cited by applicant]
Cited By (1)
US 12,726,516