Domain Name Impersonation Detection via Tokenization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Domain Name System (DNS) is vulnerable to domain name impersonation, where nefarious parties register domain names that resemble well-known brands, leading to malicious activities such as phishing and malware distribution, which can dilute brand value and compromise user trust.

Innovation Solution

A system that generates candidate tokens from DNS names, preprocesses them to remove extraneous characters, and applies literal, phonetic, and homoglyph algorithms to detect potential impersonations in real-time, using DNS sensor nodes to monitor and alert subscribers of potential brand impersonation attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If domain names are registered freely through domain name registrar services, then the DNS system maintains openness and accessibility, but the system becomes vulnerable to domain name impersonation and malicious activities

Engineering Contradiction:
Improveopenness of DNS registrationVSAvoiddomain name impersonation
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of domain names during the registration process by comparing them against a database of known brand names and previously registered domains. This proactive approach identifies potential impersonation attempts before they can be fully deployed, preventing malicious activities while maintaining open registration policies

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A centralized DNS monitoring and analysis system acts as an intermediary between domain name registrars and the broader DNS infrastructure. This intermediary layer analyzes incoming domain registrations for potential impersonation risks and can flag or block suspicious registrations, thereby protecting the system without restricting overall accessibility

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the DNS translates all domain names to IP addresses, then users can access any website, but users may be redirected to malicious sites through impersonated domain names

Engineering Contradiction:
Improvedomain name translationVSAvoidtrustworthiness of translation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements a feedback mechanism where DNS translators continuously monitor translation requests and compare them against updated databases of malicious and impersonated domains. When potential impersonation is detected, the system provides feedback to block or alert users, maintaining ease of access while ensuring translation reliability through continuous verification

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple domain names are registered to protect brand impersonation, then brand protection improves, but the complexity of domain name management increases

Engineering Contradiction:
Improvebrand protectionVSAvoiddomain name management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a universal domain name management platform that performs multiple functions: monitoring new registrations, analyzing potential impersonation risks, comparing against brand databases, and providing alerting services. This multi-functional system consolidates what would otherwise require multiple separate tools and manual processes into a single automated platform

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables automated self-service capabilities where brand owners can register their trademarks and domain patterns once, and the system automatically monitors and protects against impersonation using these inputs. This eliminates the need for manual registration of numerous defensive domain names while maintaining comprehensive brand protection

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9882933B1Tokenization of domain names for domain name impersonation detection using matching
Publication Date: 2018.01.30 FARSIGHT SECURITY INC
  • US9882933B1 patent drawing
  • US9882933B1 patent drawing
  • US9882933B1 patent drawing

AI summary

Systems and methods are described for detecting domain name impersonation in the domain name system (DNS). A nefarious party may register a domain name in the DNS that impersonates a domain name associated with a company in an attempt to lure users to malicious destination network addresses based on their trust of that company. This may lead to the dilution of the company's online presence as its domains come to be associated with malicious activity. In embodiments, a system is described which receives inputs from a subscriber including the domain names the subscriber wishes to protect, ignore, or give special scrutiny to. The system receives instances of domain names registered in the DNS and performs methods to determine if the domain name is attempting to impersonate the domain names of the subscriber. Alerts are generated so that the subscriber may take corrective action.