Malicious domain name identification method, identification apparatus and electronic equipment

TWI935992BActive Publication Date: 2026-08-11INVENTEC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
TW114138646
Authority / Receiving Office
TW · TW
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-10-07
Publication Date
2026-08-11
Estimated Expiration
2045-10-06

Smart Images

  • Figure TWG2TB001905931_001
    Figure TWG2TB001905931_001
  • Figure TWG2TB001905931_002
    Figure TWG2TB001905931_002
  • Figure TWG2TB001905931_003
    Figure TWG2TB001905931_003
Patent Text Reader

Abstract

The malicious domain name identification method includes: generating a device domain name relationship diagram based on the domain name to be detected corresponding to the object to be protected and the domain name association information corresponding to each domain name to be detected; determining the first type of risk factor value corresponding to each domain name to be detected based on the device domain name relationship diagram; determining the second type of risk factor value corresponding to each domain name to be detected based on the frequency of occurrence of each character in each domain name to be detected in the corresponding domain name; determining the risk score corresponding to each domain name to be detected based on the first type of risk factor value and the second type of risk factor value; and determining whether each domain name to be detected is a malicious domain name based on the risk score of each domain name to be detected.
Need to check novelty before this filing date? Find Prior Art

Claims

1. A method for identifying malicious domain names, comprising: Upon receiving a domain name to be detected corresponding to the object to be protected, the system obtains domain name association information corresponding to each domain name to be detected. Based on the domain name to be detected and its association information, a device domain name relationship graph is generated. The domain name association information includes a network device corresponding to the domain name to be detected, and the IP address and access time of the network device when initiating or responding to the domain name request. Based on the device domain name relationship graph, a first type of risk factor value corresponding to each domain name to be detected is determined. Based on the frequency of occurrence of each character in the domain name to be detected in the corresponding domain name, a second type of risk factor value corresponding to each domain name to be detected is determined. Based on the first type of risk factor value and the second type of risk factor value corresponding to each domain name to be detected, a risk score is determined. Based on the risk score of each domain name to be detected, it is determined whether each domain name to be detected is a malicious domain name.

2. The malicious domain name identification method as described in claim 1, wherein determining the first type of risk factor value corresponding to each of the domain names to be detected based on the device's domain name relationship diagram includes: By using a pre-constructed relationship graph analysis model, the relationship graph of the device's domain names is analyzed to obtain a graph feature vector, an anomaly identification result, and an access behavior classification result corresponding to the relationship graph of the device's domain names; and based on the graph feature vector, the anomaly identification result, and the access behavior classification result, the first type of risk factor value corresponding to each of the domain names to be detected is calculated.

3. The malicious domain name identification method as described in claim 2, wherein the domain name relationship graph of the device is analyzed by a pre-constructed relationship graph analysis model to obtain the graph feature vector corresponding to the domain name relationship graph of the device, the anomaly identification result, and the access behavior classification result, including: Feature extraction is performed on the domain name relationship graph of the device to obtain a graph feature set corresponding to the domain name relationship graph of the device. The graph feature set includes single domain name access frequency features, multi-domain name access synchronization features, and cross-access structure features between domain names. Based on the graph feature set, the graph feature vector, the anomaly identification result, and the access behavior classification result corresponding to the domain name relationship graph of the device are determined by the pre-constructed relationship graph analysis model.

4. The malicious domain name identification method as described in request item 2 or 3, wherein the access behavior classification result is the result of classifying the access behavior of the domain name to be detected, and the anomaly identification result includes an abnormal access probability value, an abnormal access type, and an abnormal time series distribution.

5. The malicious domain name identification method as described in claim 1, wherein the first type of risk factor value includes at least one of the following: domain name isolation detection score, domain name duplicate behavior score, domain name communication instruction structure anomaly score, domain name cloning behavior similarity score, domain name lifecycle anomaly score, and domain name spoofing score.

6. The malicious domain name identification method as described in claim 1, wherein determining the second type of risk factor value corresponding to each of the domain names to be detected based on the frequency of occurrence of each character in the corresponding domain name, including: Based on the domain name length and the number of times each character in the domain name appears in the domain name, a frequency of occurrence of each character in the domain name is determined; based on a predefined weight relationship table, a target weight coefficient corresponding to each character in the domain name is determined; and based on the frequency of occurrence of each character in the domain name and the target weight coefficient, the value of the second type of risk factor corresponding to the domain name is determined.

7. The malicious domain name identification method as described in claim 6, wherein determining the target weight coefficient corresponding to each character in the domain name to be detected according to the predefined weight relationship table includes: Based on the character type of each character in the domain name to be detected, the predefined weight relationship table is queried to obtain a first sub-weight coefficient corresponding to each character in the domain name to be detected; based on the arrangement of each character in the domain name to be detected, the predefined weight relationship table is queried to obtain a second sub-weight coefficient corresponding to each character in the domain name to be detected; based on the multi-letter combinations corresponding to each character in the domain name to be detected, the predefined weight relationship table is queried to obtain a third sub-weight coefficient for each character that makes up the multi-letter combinations; based on the binary letter combinations formed by each character in the domain name to be detected and its adjacent characters, the predefined weight relationship table is queried to obtain a fourth sub-weight coefficient for each character that makes up the binary letter combinations; and based on the first, second, third, and fourth sub-weight coefficients corresponding to each character in the domain name to be detected, the target weight coefficient corresponding to each character in the domain name to be detected is determined.

8. The malicious domain name identification method as described in claim 1, wherein determining the risk score corresponding to each of the domain names to be detected based on the first type of risk factor value and the second type of risk factor value corresponding to each of the domain names to be detected, includes: The first type of risk factor value and the second type of risk factor value corresponding to each of the network domain names to be tested are weighted and summed to obtain the risk score corresponding to each of the network domain names to be tested.

9. A malicious domain name identification device, comprising: A relationship graph generation module is used to obtain a domain name association information corresponding to each domain name to be detected when a domain name to be detected corresponding to the object to be protected is received, and to generate a device domain name relationship graph based on the domain name to be detected and the corresponding domain name association information. The domain name association information includes a network device corresponding to the domain name to be detected, and the IP address and access time of the network device when it initiates or responds to the domain name request. A risk factor value determination module is used to determine a first type of risk factor value corresponding to each of the domain names to be detected based on the domain name relationship diagram of the device, and to determine a second type of risk factor value corresponding to each of the domain names to be detected based on the frequency of occurrence of each character in the corresponding domain name; and a malicious domain name identification module is used to determine a risk score corresponding to each of the domain names to be detected based on the first type of risk factor value and the second type of risk factor value, and to determine whether each of the domain names to be detected is a malicious domain name based on the risk score.

10. An electronic device, comprising: At least one processor; And a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to execute any one of the malicious domain name identification methods in requests 1-8.

Citation Information

Patent Citations

  • System and method for detecting suspicious domain name according to semi-passive network domain name server judging whether an unknown network domain is suspicious or not by a suspicious domain name judgment module according to the classification rule

    TW201822505A

  • Electronic device and method of detecting malicious domain name

    TW202327319A

  • Domain feature classification and autonomous system vulnerability scanning

    US10440042B1

  • Dynamic DNS policy enforcement based on endpoint security posture

    US11050792B2