Domain Name Malicious Behavior Detection Using Attribute Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively detect and mitigate domain names registered for malicious activities, such as Denial-of-Service attacks, as they lack efficient methods to analyze and respond to suspicious domain data in real-time.

Innovation Solution

A system and method that collects and analyzes domain data, comparing attributes of a domain name to similar domain names to determine a likelihood of malicious behavior, using a combination of statistical values and weighted regression models to initiate remedial actions when the likelihood exceeds a threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If domain names are registered for legitimate purposes, then domain availability and service provision are improved, but malicious behavior detection capability deteriorates

Engineering Contradiction:
Improvedomain name usage flexibilityVSAvoidmalicious behavior detection accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The domain name is segmented into multiple attributes (registration patterns, traffic characteristics, reputation scores, etc.) that can be individually analyzed and weighted. This allows the system to distinguish between legitimate and malicious domains by examining specific attribute combinations rather than treating the domain as a single entity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameters used for domain evaluation by incorporating multiple dynamic attributes such as registration timing, traffic volume, and reputation metrics. These parameters are weighted and combined to produce a likelihood score, enabling the system to adapt to different domain types while maintaining detection accuracy.

Inventive Principle:
Principle #35Parameter changes

2Speed

If real-time domain analysis is performed, then malicious behavior detection speed is improved, but system complexity and processing resources deteriorate

Engineering Contradiction:
Improvedetection response timeVSAvoidanalysis system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system performs preliminary analysis by pre-establishing weightings for different attributes and pre-processing domain data into structured formats. This preparation allows for rapid evaluation of new domains without requiring complex real-time calculations, reducing both processing time and system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces complex mechanical analysis procedures with statistical models and weighted regression calculations. Instead of performing exhaustive manual analysis, the system uses mathematical models to quickly determine malicious likelihood, significantly reducing processing complexity while maintaining speed.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If comprehensive domain attribute analysis is conducted, then detection accuracy is improved, but processing time and computational resources deteriorate

Engineering Contradiction:
Improvemalicious behavior detection precisionVSAvoidanalysis processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies local quality by focusing analysis on specific critical attributes rather than treating all domain characteristics equally. Attributes such as registration patterns and traffic characteristics are weighted more heavily than less significant attributes, allowing the system to achieve high detection precision by concentrating computational resources on the most informative parameters.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses partial action by analyzing only the necessary subset of attributes required for accurate malicious behavior detection. Rather than comprehensively examining every possible domain characteristic, the system identifies and processes the key attributes that most strongly indicate malicious intent, reducing processing time while maintaining precision.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10728273B1Systems, devices, and methods for detecting and mitigating domain name registrations used for malicious behavior
Publication Date: 2020.07.28 VERISIGN INC
  • US10728273B1 patent drawing
  • US10728273B1 patent drawing
  • US10728273B1 patent drawing

AI summary

A method for detecting a domain name that is associated with malicious behavior includes receiving domain data for a plurality of domain names including a first domain name and a plurality of similar domain names. The domain data includes a first attribute and a second attribute of the first domain name and the similar domain names. The first attribute of the first domain name is compared to the first attributes of the similar domain names to produce a first value. The second attribute of the first domain name is compared to the second attributes of the similar domain names to produce a second value. The first value and the second value are combined to produce a combined value. A likelihood that the first domain name is associated with malicious behavior is determined based on the combined value.