Domain Name Abuse Detection via Character Replacement Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current spam and phish detection techniques fail to recognize domain name abuse when look-alike characters are used, allowing fraudulent websites to mimic legitimate ones and steal user information.

Innovation Solution

A method and system that processes domain names by applying rules to replace or modify characters that resemble legitimate domain names, using homographic, punctuation, foreign language, and character insertion rules to identify and block fraudulent domain names.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current spam and phish detection techniques are used, then detection of obvious fraudulent domain names is achieved, but detection of domain names using look-alike characters fails

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect homographic abuse
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary processing of domain names by applying multiple replacement rules (homographic, punctuation, foreign language, character insertion) to generate variant forms of the domain name before detection. This preliminary action transforms the detection problem from recognizing subtle visual differences to matching against known legitimate domain names, thereby resolving the contradiction between detection accuracy and adaptability to homographic abuse

Inventive Principle:
Principle #10Preliminary action

2Reliability

If domain names are processed with multiple replacement rules, then detection of spoofed domain names improves, but processing complexity increases

Engineering Contradiction:
Improvefraud detection reliabilityVSAvoidprocessing system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The processing system is segmented into distinct modular components, each responsible for a specific type of character replacement rule (homographic, punctuation, foreign language, character insertion). Each module independently processes the domain name and generates variants, which are then collectively evaluated. This segmentation maintains high detection reliability through comprehensive rule application while managing system complexity through modular design and clear separation of concerns

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8869269B1Method and apparatus for identifying domain name abuse
Publication Date: 2014.10.21 CA TECH INC
  • US8869269B1 patent drawing
  • US8869269B1 patent drawing
  • US8869269B1 patent drawing

AI summary

A method and apparatus for identifying domain name abuse in web-based content is described. In one embodiment, the method for identifying domain name abuse in web-based content to secure a computer comprising processing a first domain name and modifying the first domain name using a at least one rule for replacing characters. The modified first domain name indicates an imitation of a second domain name by the first domain name.