Domain Age Registration Alert for Security Risk Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security monitoring systems in networked environments face challenges in detecting unauthorized access attempts, tracing account usage across multiple assets, and updating policies, as they rely on manual analysis and do not effectively leverage domain characteristics associated with security risks.
Innovation Solution
A system and method that utilize account lateral movement mapping, domain age analysis, and pseudo-accounts to detect security risks, generate alerts, and enforce network policies, incorporating a central monitoring console to manage virtual appliances and correlate account information across network assets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual analysis of activity logs is used to detect unauthorized access attempts, then security professionals can identify potential threats, but the process is time-consuming and provides limited information about the source and nature of attempts
Solution Approach 1:
The system pre-processes and correlates authentication events across multiple assets before security professionals need to analyze them. Event correlation services continuously gather data from various assets, correlate accounts across assets, and prepare enriched event information in advance, so when analysis is needed, the work has already been performed or is in progress automatically.
Solution Approach 2:
The patent introduces an event correlation service as an intermediary between raw authentication events and security professional analysis. This service acts as a mediator that automatically correlates events, enriches data with account mapping information, and presents processed results, reducing the manual effort required while improving detection reliability.
2Reliability
If honeypot virtual appliances are deployed to monitor network assets, then access attempts by unauthorized users can be detected, but the setup and configuration process is cumbersome and time-consuming
Solution Approach 1:
The honeypot virtual appliance is designed to perform multiple functions: it monitors authentication attempts, detects unauthorized access, collects security events, and integrates with the event correlation service. This multi-functionality reduces the number of separate tools needed and simplifies deployment while maintaining comprehensive threat detection capabilities.
Solution Approach 2:
The honeypot appliance is configured to automatically perform monitoring and detection functions without requiring extensive manual setup. It self-manages its operation and integrates automatically with the existing event correlation infrastructure, reducing the burden on administrators while maintaining reliable threat detection.
3Reliability
If domain registration information is not considered in security risk assessment, then existing security systems can operate with simpler criteria, but they fail to detect risks associated with recently registered domains
Solution Approach 1:
The patent merges domain registration information with existing authentication event monitoring. The event correlation service combines data from authentication logs with domain age information from external sources, creating a unified risk assessment that considers both authentication patterns and domain characteristics without requiring separate systems.
Solution Approach 2:
The event correlation service is enhanced to perform multiple functions: it continues to correlate authentication events across assets while also evaluating domain registration information for security risks. This multi-functionality allows the system to detect both traditional authentication-based threats and domain-based threats through a single integrated service.
Data Source
AI summary
Systems and methods of identifying a security risk by monitoring and generating alerts based on attempts to access web domains that have been registered within a short period of time and are therefore identified as “high-risk,” including identifying an attempt to access a domain; receiving a registration date of the domain; and detecting a security risk based on the registration date of the domain.


