Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1702 results about "Domain name" patented technology

Domain name information processing and displaying method based on multi-modal data fusion

The invention discloses a domain name information processing and displaying method based on multi-modal data fusion, and the method comprises the following steps: S1, collecting and preprocessing domain name multi-modal original data, and generating a preprocessed data sample set; s2, performing feature extraction on the preprocessed data sample set, and constructing a multi-modal fusion feature vector sequence; s3, constructing an initial Tab Net model, and outputting an initial domain name risk prediction result; s4, constructing a model performance evaluation objective function; s5, introducing a dragonfly optimization algorithm, and searching to obtain an optimal Tab Net parameter combination; and S6, based on the optimal Tab Net parameter combination, obtaining an optimized Tab Net model, and outputting a final domain name risk prediction result. And S7, based on the final domain name risk prediction result, constructing a domain name knowledge graph display structure, and generating an interactive graph display result. According to the method, a multi-modal feature extraction mechanism, a Tab Net depth model and a dragonfly optimization algorithm are fused, and intelligent prediction of domain name risks and interactive knowledge graph display optimization are realized.
Owner:HEFEI XUNYUN NETWORK TECH CO LTD

Live chat client application for connecting with available agents of any website and application

The method and systems for automatically identified currently viewing website domain name or a uniform resource locator (URL), receiving, by the server, said automatically identified website domain name or the uniform resource locator (URL), a request or an invitation for initiating a communication including live chat, puts the request for initiating a communication including live chat from the first user and the second user in a communication including live chat queue of the website or the uniform resource locator (URL) associated account, for available or identified or relevant agents to pick up, routing request or invitation for initiating a communication including live chat from the first user and the second user according to a pre-set rules and start a communication including live chat by available agent by selecting particular request for initiating a communication including live chat from the queued communication including live chats.
Owner:RATHOD YOH

Methods and Systems for Identity on Blockchain Clusters

To solve the problems of fractured identity across multiple blockchains, these methods and systems allow for a single unified identity to be managed and resolved across multiple chains within an interop network. By leveraging message passing, identity records can exist securely across different chains. The system incorporates counterfactual blockchains, enabling trust-minimized name registration that reduces costs while maintaining decentralization and security. ENS name resolution is supported across both onchain and offchain environments, with verifiable proofs ensuring efficient resolution. By structuring message passing and utilizing decentralized indexers, these methods and systems provide a scalable and reliable framework for cross-chain identity.
Owner:MAKEIG PREM

Continuously Assessing External Risk for Internet-Facing Assets

The concepts and technologies disclosed herein are directed to continuous external risk assessment for Internet-facing assets. In one or more implementations, a system can execute a web crawl using a plurality of seed uniform resource locators. The system can execute a domain name service subdomain scan and a subdomain scan. The system can obtain asset data associated with one or more client assets. The system can determine, based upon the asset data and results of the web crawl, the domain name service subdomain scan, and the subdomain scan, whether each domain of a plurality of domains is known.
Owner:ABRICTO SECURITY LLC

Hypertext markup language (HTML) content analysis using machine learning

HyperText Markup Language (HTML) content analysis (HCA) using machine learning is described. A feature vector schema may be generated based on domain names corresponding to HTML webpages and corresponding indications of a status of the HTML webpage. The schema may map each position in a feature vector of a given HTML webpage to a resource identifier. Information may be processed using the schema to generate respective feature vectors. The feature vectors may be used to train a model to generate risk indicators for HTML webpages. A potentially parked domain webpage or a potentially malicious domain webpage may be received. A feature vector for the webpage may be generated and inputted to the model. The model may generate a risk indicator for the webpage. The risk indicator may be output and may cause responsive actions. The model may be updated based on a determination indicating whether the webpage was a parked domain webpage or a malicious domain webpage.
Owner:CENTRIPETAL NETWORKS INC

Route selection method and apparatus for edge application server, communication device and storage medium

A route selection method for an Edge Application Server (EAS) is provided, the method is performed by a terminal, and includes: receiving a Domain Name System (DNS) information indication sent by a first network function; executing a DNS policy decision based on the DNS information indication; and sending a DNS query request to a second network function based on the decision, where the DNS query request is used to request the second network function to select an EAS.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Distributed node unified identity authentication method and system based on QUIC protocol

The invention relates to a QUIC protocol-based distributed node unified identity authentication method and system, belongs to the technical field of network security, is applied to a client, and comprises the following steps: registering a client domain name identity through a certificate authority, obtaining a client certificate, and pre-storing a server certificate chain; generating a QUIC initial data packet according to the target server domain name identifier and the client certificate, and sending the QUIC initial data packet to the server; receiving a QUIC handshake data packet returned by the server; verifying the legality of the server certificate based on the server certificate chain, and if the server certificate is legal, calculating a pre-master key according to the client DH private key and the server DH public key; deriving a 1-RTT session key based on the pre-master key; generating a signature verification message, and sending the client certificate and the signature verification message to a server; and synchronously using the 1-RTT session key to encrypt the application layer data with the server, and transmitting the data to the server in the 1-RTT encryption space of the QUIC protocol. According to the invention, the reliability of node identities and the confidentiality of data are ensured.
Owner:BEIJING LIUJINSUIYUE TECH CO LTD

Visual deep learning for inline phishing detection

Techniques for visual deep learning for inline phishing detection are disclosed. In some embodiments, a system / process / computer program product for visual deep learning for inline phishing detection includes extracting a logo from a screenshot of a web page; detecting phishing based on a match to at least one of a plurality of reference logos using a visual deep learning model and that a domain associated with the web page is not associated with an entity that matches the logo extracted from the web page; and performing a remedial action in response to determining that the web page is associated with phishing.
Owner:PALO ALTO NETWORKS INC

Fraud website identification early warning method, device and equipment and storage medium thereof

The invention relates to a fraud website identification early warning method, device and equipment and a storage medium thereof. The method comprises the following steps: firstly, acquiring network address information, then extracting feature data from dimensions such as structure, semantics, behavior and vision, accelerating similarity detection by applying a graphics processor parallel computing technology, and generating a composite feature vector containing a domain name similarity score and a registration feature; constructing fraud features in combination with the composite feature vector, mining a data association relationship through a graph neural network, and forming multi-dimensional risk feature data; and finally, processing the risk feature data by using a deep learning model, generating a risk probability, and when the risk probability exceeds a preset threshold, determining that the network address is a high-risk network address and generating an early warning report. By adopting the method, the comprehensiveness and accuracy of fraud website identification can be improved, complex fraud means such as domain name variation and semantic camouflage can be effectively dealt with, the real-time early warning capability for potential risks is enhanced, and efficient technical support is provided for network security protection.
Owner:CHONGQING JIAOTONG UNIV

DNS anomaly detection and domain name hijacking early warning method based on multi-source NLP

The invention discloses a DNS anomaly detection and domain name hijacking early warning method based on a multi-source NLP, and belongs to the technical field of network security. According to the method, firstly, multi-source information collection and NLP semantic analysis are carried out, malicious entities are identified from collected external information, and an attack mode is reasoned; performing association scoring on the identified malicious entity and an abnormal mode detected in a preset time window, if the score exceeds a threshold value, judging that a domain name hijacking behavior or a DNS poisoning behavior exists, executing a domain name hijacking early warning process, and storing an abnormal event log; and updating a multi-source information acquisition and NLP semantic analysis module and a DNS anomaly detection model according to feedback of a system alarm result, a log and sample data output by information association analysis and hijacking judgment. According to the invention, domain name hijacking and DNS abnormity can be quickly found, accurately positioned and timely warned, and false alarm and missing alarm are reduced.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Multi-modal attack identification method fusing BMama and difference to guide trans-attention

The invention discloses a multi-modal attack identification method fusing BMama and difference to guide trans-attention, which comprises the following steps: simulating a false data injection attack, a denial of service attack, an address resolution protocol spoofing attack and a domain name system spoofing attack, collecting physical layer sensor data and network layer flow data, and preprocessing multi-modal data; bMama is constructed to perform dynamic time modeling on multi-modal data, a graph neural network is combined to adversariate a variational auto-encoder, features of a power grid system topology and a communication topology structure are fused, and robustness of potential representation is enhanced through adversarial training; the method comprises the following steps of: guiding feature complementary fusion by using modal difference through a difference guide iteration cross-attention fusion mechanism, improving the capability of distinguishing complex attacks, finally carrying out attack detection and classification on fused modals, and executing end-to-end optimization according to a weighted combination of loss of each part. The method can effectively detect and classify the multi-modal attack in the smart power grid, and enhances the safety and reliability of a complex system.
Owner:SOUTHEAST UNIV

Method and system for dynamically routing back-end address by API (Application Program Interface) gateway

The invention relates to the technical field of computers, and discloses a method and system for dynamically routing a back-end address by an API gateway, and the method comprises the steps: receiving an HTTP request, and analyzing a URL and a request header; extracting a tenant identifier, and supporting multi-mode identification of a request header, a sub-domain name or a path segment; loading an exclusive routing rule set based on the tenant identifier; sorting according to local priorities in the tenants, executing longest path prefix matching through a prefix tree, and determining an optimal back-end address; and finally forwarding the request. The system comprises a request analysis module, a tenant identification module, a rule loading module, a local sorting module, a longest matching module and a request forwarding module, and supports routing rule hot update and conflict detection. According to the method, cross-tenant interference is effectively eliminated through tenant context awareness and a two-stage matching mechanism, and the routing accuracy and the system isolation are improved.
Owner:SHANGHAI GANGLIAN E COMMERCE

DNS configuration provisioning

Method and apparatus for improvement of DNS configuration for applications are disclosed. A method performed at a server comprises generating Domain Name System (DNS) information; deciding whether to transmit the DNS information to a User Equipment (UE) or to a network or to both the UE and the network; and transmitting the DNS information for use with at least one application associated with the UE according to the decision.
Owner:LENOVO (BEIJING) LTD

Detection of malicious domains

Disclosed are systems and methods that monitor for malicious and unauthorized behaviors, determine categories for detected malicious behaviors, determine why a domain is determined to be malicious, and provide information to users that identifies the categories and reasons as to why a domain is determined to be malicious. In some implementations, the disclosed systems and methods may be utilized to provide monitoring security to customers of a cloud service. For example, customers of a cloud service may maintain an account with the cloud service and the disclosed implementations may be utilized to protect those accounts from malicious attacks and cybercrimes such as, but not limited to, spam, phishing, malware, botnets, etc.
Owner:AMAZON TECH INC

Data processing method and device, equipment and medium

The invention discloses a data processing method and device, equipment and a medium. The method comprises the steps that a detection threshold value is determined based on a first access traffic log; determining an access behavior for the service domain name based on the number of domain name requests determined by the access traffic indicated by the second access traffic log and a detection threshold; when the access behavior aiming at the service domain name belongs to the abnormal access behavior, taking a behavior determination time point corresponding to the abnormal access behavior as a critical time point, and taking a third access traffic log obtained based on the critical time point as an abnormal access traffic log; when a normal traffic feature determined based on the first access traffic log is obtained, determining an abnormal traffic feature of the service domain name based on the abnormal access traffic log, and performing feature comparison on the abnormal traffic feature and the normal traffic feature to obtain an attack feature of the service domain name; a protection policy for the service domain name is determined based on the attack feature. According to the invention, the security and stability of the business server can be maintained.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

RAG-based multi-dimensional network penetration test vulnerability mining method

The invention provides an efficient multi-dimensional network penetration testing method based on RAG, which comprises the following steps: firstly, identifying sub-domain names possibly existing in a target website, and sequentially expanding attack surfaces of penetration testing to obtain vulnerability information pairs; secondly, a design model generated based on retrieval enhancement is adopted, vulnerability information pairs are extracted from the queue to be utilized, knowledge items related to local knowledge base retrieval and network intelligent search retrieval are utilized, and finally, a large model generates vulnerability utilization information according to the knowledge items; acquiring target machine permission for the previously acquired vulnerability information pair construction command injector, and further scanning other hosts of the intranet accessed by the target skipping machine; finally, combining vulnerability information obtained by penetration testing, utilizing a large model to sort vulnerabilities existing in different assets, and outputting penetration testing reports for different assets. According to the method and the system, comprehensive penetration testing of cross-network and cross-system is realized, security experts are helped to quickly identify, verify and repair vulnerabilities in a complex and changeable network environment, and high-efficiency and low-cost network security maintenance is realized.
Owner:SOUTHEAST UNIV

Webpage parsing code generation method, device and equipment based on large language model

The invention provides a webpage analysis code generation method, device and equipment based on a large language model, and relates to the technical field of natural language processing, webpage analysis and the like. The method comprises the following steps: determining a key information field according to a demand text of a webpage analysis task through a first large language model, and filling the key information field into a structured analysis prompt template to obtain an analysis prompt text; the key information field comprises at least one of the following items: a domain name of a target website, a target webpage type, a target webpage structure and a target data field; and through a second large language model, generating an analysis code of the webpage analysis task according to the analysis prompt text.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Resource access method and device, zero-trust platform and storage medium

The invention provides a resource access method and device, a zero-trust platform and a storage medium, and the method comprises the steps: receiving an internal resource access request of a zero-trust client, the access request carrying an access address of a target resource, user information of the zero-trust client, and temporary authentication information; the access address comprises a zero-trust platform domain name and a target resource identifier, the zero-trust platform domain name points to a public network address of the zero-trust platform, and the target resource identifier is used for uniquely identifying a target resource; the temporary authentication information is used for authenticating that the zero-trust client has the qualification of initiating the access request; based on the user information and the temporary authentication information, verifying the user identity and the access authority of the zero-trust client; after the verification is successful, determining a real address of the target intranet server based on a pre-configured mapping relationship between the real address of the intranet server and the internal resource identifier; and forwarding the access request to the target intranet server according to the real address of the target intranet server.
Owner:HANGZHOU DPTECH TECH

DNS Validation to Avoid Inadvertent Subzone Creation

Methods, systems, and apparatuses are described herein for management of a Domain Name System (DNS) system. The system comprises numerous improvements, many related to CNAME records of the DNS. A computing device may manage authentication for a DNS using shared authentication credentials of a first authentication framework. In this manner, a wide variety of users might authenticate themselves using a first framework and use authentication credentials for a second framework to access a DNS. The computing device may further protect DNS servers from Denial of Service (DoS) attacks by bifurcating read and write requests to a DNS to different servers, such that attacks on read requests do not affect all of the DNS. The computing device may further validate DNS requests using, for example, natural language processing to avoid typographical errors inadvertently creating DNS zones.
Owner:CAPITAL ONE SERVICES LLC

Domain name resource record TTL tampering traceability positioning method based on analytic chain reasoning

The invention discloses a domain name resource record TTL tampering traceability positioning method based on analytic chain reasoning, and belongs to the technical field of Internet security monitoring. The method comprises the following steps: deploying a system which comprises a special server for managing a domain name, a plurality of repeaters and a plurality of recursive resolvers located at the upstream of the repeaters, and setting a TTL reference value stored in the special server; selecting a target transponder, and initiating a plurality of DNS query requests with time intervals to the target transponder by a user; and determining a cache mode of the target transponder based on the TTL value in the response corresponding to each DNS query request, and determining an object tampering the TTL reference value based on the cache mode of the target transponder and the TTL value in the response corresponding to each DNS query request. The method is used for realizing hierarchical positioning of TTL tampering responsibilities.
Owner:NAT UNIV OF DEFENSE TECH +1

DNS (Domain Name Server) hierarchical cache analysis acceleration method and system based on prefetching mechanism

The invention relates to the technical field of network communication, in particular to a DNS (Domain Name Server) hierarchical cache resolution acceleration method and system based on a prefetching mechanism, which comprises the following steps: by constructing a hierarchical cache model comprising a client layer, a local DNS server layer and an upstream DNS server layer, caching a resolved domain name and a corresponding resolution result into each layer of cache; a DNS request of a terminal user is received, whether the request hits the cache or not is judged, and corresponding operation is adopted; historical query logs are collected, a next DNS request is predicted in combination with a prefetching mechanism of real-time network topology perception, and an analysis result of the domain name is cached to a local DNS server layer in advance; a cross-layer collaborative cache updating mechanism is adopted to ensure synchronous updating of cache data of different levels; and a symmetric encryption algorithm and a TLS protocol are introduced, so that the security of the data in the storage and transmission process is ensured. According to the method, the response of DNS analysis is accelerated through a prefetching mechanism and layered caching.
Owner:贵州中融信通科技有限公司 +1

Systems and methods for counter-reconnaissance in cloud infrastructure to disrupt adversarial targeting

The present invention relates to a cybersecurity system for preventing adversarial reconnaissance in cloud, hybrid, and multi-cloud environments by dynamically modifying user authentication identifiers, hostnames and fully qualified domain names. The system updates login usernames in real time using randomized, non-repeating values generated from a configurable dictionary. Updates occur at scheduled, random, coordinated, or event-triggered intervals to disrupt profiling and targeting attempts. When identifiers are changed, associated sessions and tokens are invalidated to prevent reuse. The system monitors expired credential usage to detect potential reconnaissance, generating alerts with intelligence such as IP addresses, timestamps, and affected resources. By eliminating predictable identity patterns, the system defends against reconnaissance-based attacks, unauthorized access attempts, and other credential-driven threats, thereby improving organizational security across cloud platforms.
Owner:FRENETIK LLC

Methods and apparatus to decrease domain name system (DNS) lookup time for airborne clients

Methods and apparatus to decrease DNS lookup times for mobile clients are disclosed. An example DNS cache peering system includes a mobile DNS cache; a mobile DNS server configured to, when an IP address for a URL is not found in the DNS cache, send a DNS lookup request for the URL; a ground-based DNS server to receive the DNS lookup request from the mobile DNS server, and send, in response, a DNS lookup response including the IP address for the URL to the mobile DNS server; and a ground-based DNS peer engine server configured to capture the DNS lookup response, and multicast DNS information from the DNS lookup response to a plurality of mobile DNS peer engine clients, wherein the plurality of mobile DNS peer engine clients are configured to store the DNS information in respective ones of a plurality of mobile DNS caches.
Owner:GOGO BUSINESS AVIATION LLC

Public network-oriented global threat perception method and system

The invention provides a public network-oriented global threat perception method and system, and relates to the technical field of advanced persistent attack threat detection, and the specific technical scheme is as follows: setting a network trip line and a domain name trip line of a public network to establish honey point equipment, and establishing honey court equipment based on an IP address reputation mechanism; building a honey hole device based on a camouflage traceability technology and a reverse chain technology, and building a sub-honey array based on a honey point device, a honey court device and the honey hole device; generating a honey point template based on the sub-honey array to deploy honey point equipment, obtaining public network traffic based on a honey yard equipment preposition and combining with the honey point equipment, and detecting the public network traffic to obtain a detection result; and making a countering strategy of the honey hole device based on the behavior of the attacker in the detection result, obtaining threat intelligence of the attacker, and updating IP address resources of the honey point device and the honey court device based on the threat intelligence. According to the invention, a low-intrusive threat probing mechanism and a high-universality global threat sensing system are established through four-honey equipment.
Owner:GUANGZHOU UNIVERSITY

Provisioning applications with mobile network provided DNS settings

The present disclosure relates to Edge Computing enhancements by provisioning applications with mobile network provided Domain Name System (DNS) settings. In one embodiment, a method performed by a User Equipment (UE), which supports an Edge Application Server (EAS) discovery procedure with an Edge Application Server Discovery Function (EASDF), includes receiving a DNS setting provided by a mobile network, and storing a first copy of the DNS setting provided by the mobile network as a first DNS setting and a second copy of the DNS setting provided by the mobile network. Herein, the stored first DNS setting is not impacted by any changes made to the second copy of the DNS setting provided by the mobile network.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Methods and systems for prevention of attacks associated with the domain name system

The attack vectors for some denial-of-service cyber attacks on the Internet's Domain Name System (DNS) are bad, bogus, or unregistered domain name DNS requests to resolve domain names that are not registered in the DNS. Some other cyber attacks steal sensitive data by encoding the data in bogus domain names, or domain names otherwise not registered in the DNS, that are transferred across networks in bogus DNS requests. A DNS gatekeeper may filter in-transit packets containing DNS requests and may efficiently determine if a request's domain name is registered in the DNS. When the domain name is not registered in the DNS, the DNS gatekeeper may take one of a plurality of protective actions. The DNS gatekeeper drops requests determined not to be legitimate, which may prevent an attack.
Owner:CENTRIPETAL NETWORKS INC

Methods and systems for blockchain name identifiers

A computer-implemented method includes: receiving a first request from a registrant to associate a domain name with a blockchain address; transmitting the first request to a registry, wherein the registry is configured to digitally sign the first request; submitting the digitally signed data from the first request or transformation of the data from first request to a first blockchain contract, wherein the first blockchain contract is configured to store the associated domain name as a first blockchain identifier; determining a deployment of a second blockchain contract by the registrant; transmitting a second request to the registrant to associate a subdomain of the associated domain name as a second blockchain identifier for the second blockchain contract; receiving, from the registrant, an indication to use the subdomain as the second blockchain identifier for the second blockchain contract; transmitting the second request to a registry, wherein the registry is configured to digitally sign the second request; submitting the digitally signed data from the second request or transformation of the data from second request to a second blockchain contract, wherein the second blockchain contract is configured to store the associated domain name as a second blockchain identifier.
Owner:VERISIGN INC

Systems and methods for managing network identifiers in distributed computing systems

At least one aspect of the technical solutions described herein relate to a system. The system can include one or more processors coupled with memory. The system can receive a message can include an identifier of a browser extension executing on the client device and a user identifier of a software-as-a-service (SaaS) application. The system can bind a subdomain identifier with the identifier of the browser extension. The system can transmit a uniform resource identifier (URI) including the subdomain identifier to the client device. The domain name service (DNS) request can include a host identifier of the client device. The system can access a DNS log of the DNS system to identify the host identifier using the subdomain identifier. The system can bind the identifier of the browser extension and the user identifier with the host identifier of the client device.
Owner:OBSIDIAN SECURITY INC

Domain Name Detection Method, Device, and Storage Medium

Embodiments of the present disclosure provide a domain name detection method, device, and storage medium. By matching a domain name to be detected with a preset domain name set, where the preset domain name set includes multiple trusted domain names; if the domain name to be detected is not in the preset domain name set, the edit distance between each level of domain name in the domain name to be detected and a preset domain name keyword in a domain name keyword set is calculated; if the edit distance between any target level domain name and any target preset domain name keyword is less than a preset distance threshold, the character pairs where the target level domain name and the target preset domain name keyword are different are obtained, and the character pairs are matched with a set of similar character pairs; if it is determined that the character pairs are in the set of similar character pairs, it is determined that the domain name to be detected has a security risk. Embodiments of the present disclosure can effectively detect counterfeit domain names, improve accuracy, reduce false alarms, and have a simple algorithm, small implementation difficulty, and small complexity and performance overhead.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Domain recommendation system and method with ambiguity resolution

Aspects of the invention provide a method, system, and computer program product for retrieval augmented generation. In one aspect, the method includes receiving a query. The method further includes classifying the query to a first domain within a plurality of domains. The method additionally includes determining an ambiguity associated with classifying the query. The method also includes retrieving an index of domain-specific vector embeddings corresponding to the domains when the ambiguity does not exceed a threshold for ambiguity. The method further includes prompting a large language model with the query and the domain-specific vector embeddings. The method also includes receiving a query response from the large language model as grounded with the most relevant index results. The method further includes forwarding the query response.
Owner:INTUIT INC