IP Library Granted Patent US 10,313,369
Granted Patent B2
US 10,313,369 · App. 15/716,909 · Granted Jun 4, 2019

Blocking malicious internet content at an appropriate hierarchical level

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,313,369
App. No.
15/716,909
Granted
Jun 4, 2019
Kind
B2
Abstract

Blocking malicious Internet content at an appropriate hierarchical level. In one embodiment, a method may include identifying evidence of security risks in hierarchical levels of an Internet hierarchy. The method may also include generating security risk scores for the hierarchical levels of the Internet hierarchy based on the evidence of security risks. The method may further include identifying a security risk threshold. The method may also include identifying, as an appropriate blocking level, the highest hierarchical level of the Internet hierarchy having a security risk score at or above the security risk threshold. The method may further include blocking a network device from accessing Internet content in the Internet hierarchy at or below the appropriate blocking level.

Claims (42)

1. A computer-implemented method for blocking malicious Internet content at an appropriate hierarchical level, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

identifying evidence of security risks in hierarchical levels of an Internet hierarchy;

generating security risk scores for the hierarchical levels of the Internet hierarchy based on the evidence of security risks;

identifying a security risk threshold;

identifying, as an appropriate blocking level, the highest hierarchical level of the Internet hierarchy having a security risk score at or above the security risk threshold; and

blocking a network device from accessing Internet content in the Internet hierarchy at or below the appropriate blocking level.

2. The method of claim 1 , wherein the hierarchical levels of the Internet hierarchy comprise Top Level Domain (TLD), Autonomous System Number (ASN), Classless Inter-Domain Routing (CIDR) Range, Internet Protocol (IP) address, Domain, Host, Path, and File.

3. The method of claim 1 , wherein the generating of the security risk scores for the hierarchical levels of the Internet hierarchy based on the evidence of security risks is accomplished using machine learning.

4. The method of claim 1 , wherein the evidence of security risks comprises direct evidence.

5. The method of claim 4 , wherein the evidence of security risks further comprises indirect evidence.

6. The method of claim 5 , further comprising:

weighting the indirect evidence of security risks based on the hierarchical level to which the indirect evidence corresponds.

7. The method of claim 6 , wherein the indirect evidence corresponding to higher hierarchical levels of the Internet hierarchy are weighted lower than the indirect evidence corresponding to lower hierarchical levels of the Internet hierarchy.

8. A computer-implemented method for blocking malicious Internet content at an appropriate hierarchical level, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

identifying a base hierarchical level of an Internet hierarchy that has a potential security risk;

identifying direct evidence of security risks in the base hierarchical level and other hierarchical levels of the Internet hierarchy that are higher than and/or lower than the base hierarchical level;

generating indirect evidence of security risks in the base hierarchical level and other hierarchical levels;

combining the direct and indirect evidence of security risks in the base hierarchical level and other hierarchical levels into combined evidence of security risks;

generating security risk scores for the hierarchical levels of the Internet hierarchy based on the combined evidence of security risks;

identifying a security risk threshold;

identifying, as an appropriate blocking level, the highest hierarchical level of the Internet hierarchy having a security risk score at or above the security risk threshold; and

blocking a network device from accessing Internet content in the Internet hierarchy at or below the appropriate blocking level.

9. The method of claim 8 , wherein the hierarchical levels of the Internet hierarchy comprise Top Level Domain (TLD), Autonomous System Number (ASN), Classless Inter-Domain Routing (CIDR) Range, Internet Protocol (IP) address, Domain, Host, Path, and File.

10. The method of claim 8 , wherein the generating of the security risk scores for the hierarchical levels of the Internet hierarchy based on the combined evidence of security risks is accomplished using machine learning.

11. The method of claim 8 , further comprising:

weighting the indirect evidence of security risks based on the hierarchical level to which the indirect evidence corresponds.

12. The method of claim 11 , wherein the indirect evidence corresponding to higher hierarchical levels of the Internet hierarchy are weighted lower than the indirect evidence corresponding to lower hierarchical levels of the Internet hierarchy.

13. The method of claim 11 , wherein the weighting of the indirect evidence of security risks is accomplished using machine learning.

14. The method of claim 8 , wherein the identifying of the direct evidence of security risks comprises identifying the direct evidence of security risks in one or more of telemetry data, traffic log data, and historical tracking data.

15. One or more non-transitory computer-readable media comprising one or more computer-readable instructions that, when executed by one or more processors of one or more computing devices, cause the one or more computing devices to perform a method for blocking malicious Internet content at an appropriate hierarchical level, the method comprising:

identifying evidence of security risks in hierarchical levels of an Internet hierarchy;

generating security risk scores for the hierarchical levels of the Internet hierarchy based on the evidence of security risks;

identifying a security risk threshold;

identifying, as an appropriate blocking level, the highest hierarchical level of the Internet hierarchy having a security risk score at or above the security risk threshold; and

blocking a network device from accessing Internet content in the Internet hierarchy at or below the appropriate blocking level.

16. The one or more non-transitory computer-readable media of claim 15 , wherein the hierarchical levels of the Internet hierarchy comprise Top Level Domain (TLD), Autonomous System Number (ASN), Classless Inter-Domain Routing (CIDR) Range, Internet Protocol (IP) address, Domain, Host, Path, and File.

17. The one or more non-transitory computer-readable media of claim 15 , wherein the generating of the security risk scores for the hierarchical levels of the Internet hierarchy based on the evidence of security risks is accomplished using machine learning.

18. The one or more non-transitory computer-readable media of claim 15 , wherein the evidence of security risks comprises direct evidence.

19. The one or more non-transitory computer-readable media of claim 18 , wherein the evidence of security risks further comprises indirect evidence.

20. The one or more non-transitory computer-readable media of claim 19 , wherein:

the method further comprises weighting the indirect evidence of security risks based on the hierarchical level to which the indirect evidence corresponds; and

the indirect evidence corresponding to higher hierarchical levels of the Internet hierarchy are weighted lower than the indirect evidence corresponding to lower hierarchical levels of the Internet hierarchy.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2017
From: DINERSTEIN, JONATHAN J.
To: SYMANTEC CORPORATION
Reel/Frame 043714/0072 →