Domain Scanning System for Malicious Registry Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face difficulties in monitoring and preventing competitors from exploiting their names in web domains, especially with the increasing number of top-level domain registrations, which can lead to reputational damage and malicious activities.
Innovation Solution
A computer-implemented data processing method that scans and analyzes web domains to identify potential threats by determining associated terms, performing registry lookups, analyzing webpage content, and assessing risk levels, with automated actions taken when risks exceed a threshold.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual monitoring of web domains is performed, then detection accuracy can be maintained, but the system cannot scale to handle increasing numbers of domain registrations
Solution Approach 1:
The system segments the domain monitoring task into distinct functional modules: domain scanning component, registry lookup component, risk analysis component, and automated response component. Each module handles a specific aspect of the monitoring process, enabling the system to scale efficiently while maintaining detection accuracy through specialized processing at each stage.
Solution Approach 2:
The patent introduces automated intermediaries including domain scanning bots that systematically probe for malicious domains, registry lookup services that automatically verify domain ownership, and risk analysis algorithms that automatically assess threats. These intermediaries enable high-volume monitoring without requiring manual intervention for each domain.
2Measurement precision
If comprehensive registry lookups are performed for all identified domains, then accurate risk assessment is achieved, but processing time and computational resources increase significantly
Solution Approach 1:
The system performs preliminary filtering by scanning for domains containing entity terms before conducting comprehensive registry lookups. This preliminary action identifies only the most relevant domains for detailed analysis, reducing the total number of registry queries needed while maintaining accurate risk assessment for high-priority targets.
Solution Approach 2:
The patent applies different levels of analysis depth to different domains based on their risk characteristics. High-risk domains identified through initial scanning receive comprehensive registry lookups and detailed web page analysis, while lower-risk domains receive streamlined processing. This local quality approach optimizes resource allocation while maintaining precision where most needed.
3Speed
If automated actions are taken immediately upon detecting risk, then response speed is improved, but false positives may cause unnecessary disruptions
Solution Approach 1:
The system incorporates feedback loops where automated actions are triggered by risk thresholds, then monitored for effectiveness. The system learns from the outcomes of automated responses and adjusts its risk assessment parameters accordingly, improving both response speed and accuracy over time by refining what constitutes a true positive versus false positive.
Solution Approach 2:
The patent implements cushioning mechanisms in the form of configurable risk thresholds and approval workflows that prevent immediate automated actions for borderline cases. This cushioning allows the system to maintain fast response times for clear-cut threats while providing additional verification layers for ambiguous cases, reducing false positives while preserving rapid response capability.
Data Source
AI summary
A domain scanning and website analysis system may be utilized to determine whether an entity is registering one or more websites maliciously in the name of a particular organization (e.g., or using a particular brand name, trademark, or other protected name of the organization). The system may be configured to: (1) scan a plurality of web domains to identify a particular name or variation thereof; (2) perform a registry lookup for any identified web domains that include the particular name; (3) determine based on registration information determined from the registry lookup, whether the identified domain or sub-domain is registered to a potentially malicious entity; (4) scan one or more webpages in the identified domain to determine content; and (5) determine, based on the determined content and whether the web domain is registered to a potentially malicious entity, whether to take action against the identified domain or sub-domain.


