Cloud Domain Squatting Detection Using Distance Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security filters fail to identify targeted attacks using domain squatting, where malicious domains impersonate legitimate ones through subtle URL mistakes, relying on known bad domains or IP addresses, which are increasingly evaded by cybercriminals.

Innovation Solution

A cloud-based system that receives valid domains, compares unidentified domains using distance calculations such as Levenshtein Distance, Sørensen-Dice Coefficient, and Jaccard index, and dynamically adjusts weights to detect cybersquatting attempts, notifying operators and blocking malicious domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security filters relying on known bad domains or IP addresses are used, then the system is simple to operate and has low device complexity, but it fails to identify new malicious domains using domain squatting techniques

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system pre-calculates and stores distance metrics between domain names before security evaluation. By maintaining a database of pre-computed distances between legitimate domains and potential squatting variants, the system can quickly identify malicious domains without performing complex real-time analysis, thus improving detection accuracy while keeping operational complexity manageable

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces distance metrics (such as Levenshtein distance, Sørensen-Dice coefficient, and Jaccard index) as intermediary measures to quantify the similarity between domain names. These metrics serve as mediators that translate the complex problem of domain squatting detection into measurable numerical values, enabling reliable identification of malicious domains through mathematical comparison rather than simple pattern matching

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple distance computations with dynamic weight adjustment are implemented, then the measurement precision of cybersquatting detection is improved, but the device complexity and computational requirements increase

Engineering Contradiction:
Improvedomain similarity detection precisionVSAvoidcomputation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system computes multiple distance metrics (Levenshtein distance, Sørensen-Dice coefficient, Jaccard index) between domain names to achieve high precision in detecting cybersquatting attempts. By applying several computational methods simultaneously rather than relying on a single metric, the system ensures accurate identification of malicious domains even when they use subtle variations, thus prioritizing detection precision over computational efficiency

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements dynamic weight adjustment for different distance metrics based on the specific characteristics of the domains being compared. The system adaptively modifies the importance assigned to each distance computation (e.g., giving more weight to character-based metrics for certain domain types and structure-based metrics for others), allowing the detection system to optimize its precision for different cybersquatting techniques while managing computational complexity through adaptive rather than static processing

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10419477B2Systems and methods for blocking targeted attacks using domain squatting
Publication Date: 2019.09.17 ZSCALER INC
  • US10419477B2 patent drawing
  • US10419477B2 patent drawing
  • US10419477B2 patent drawing

AI summary

Systems and methods for identifying and addressing domains suspected as malicious domains used for targeted attacks in a cloud-based system include receiving valid domains; receiving an unidentified domain; comparing the unidentified domain to the valid domains to derive a distance calculation of the unidentified domain to each of the valid domains; determining whether the unidentified domain is a cybersquatting attempt of one of the valid domains based on the comparing; and, responsive to the determining the unidentified domain is a cybersquatting attempt, one of notifying an operator/user and blocking the unidentified domain in the cloud-based system.