Network Analysis System for Domain Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in managing digital cybersecurity risks, particularly in detecting domain threats and external threats beyond the firewall, due to the vast amount of information on the Internet, which makes it difficult to track and monitor Internet-facing assets and identify potential vulnerabilities or compromises in DNS infrastructure.

Innovation Solution

A network analysis system that includes a client system and a network analysis system, utilizing one or more computing devices to implement methods for monitoring network data, detecting threats, and identifying visually or conceptually similar domain names that may deceive users, by employing techniques such as string similarity algorithms and reputation scoring to prioritize potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprises manually monitor and track Internet-facing assets and domain names, then they can identify potential security threats, but the vast amount of information on the Internet makes this process nearly impossible and extremely time-consuming

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidtime to monitor and analyze domain information
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical monitoring processes with automated computational systems. The system uses algorithms to automatically crawl, collect, and analyze domain name information, replacing the impossible manual task of tracking thousands of domains with automated software agents that can process vast amounts of data efficiently.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates simplified representations (copies) of domain information through structured data models and profiles. Instead of analyzing raw vast amounts of domain data directly, the system creates organized copies of domain information including registration details, hosting information, and security metrics, making the data manageable and analyzable.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If enterprises expose more computer assets to the Internet to provide services, then they can improve business functionality, but tracking and identifying which assets are exposed becomes increasingly difficult

Engineering Contradiction:
Improvebusiness service capabilityVSAvoidasset tracking difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where the automated monitoring system continuously queries DNS infrastructure, WHOIS databases, and security feeds to update information about exposed assets. This feedback loop provides real-time or near-real-time information about which assets are internet-facing, their current security status, and any new threats, enabling enterprises to maintain accurate asset inventories despite dynamic changes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent creates a universal monitoring system that can track multiple types of internet-facing assets (domains, subdomains, IP addresses, services) through a single platform. The system performs multiple functions including asset discovery, threat detection, vulnerability assessment, and compliance monitoring, eliminating the need for separate tracking systems for different asset types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-generated harmful factors

If threat actors use identical or visually similar terms in domain names to deceive users, then they can successfully execute phishing attacks, but this creates challenges in automatically detecting and distinguishing malicious domains from legitimate ones

Engineering Contradiction:
Improvephishing attack effectivenessVSAvoiddomain threat detection accuracy
Core Design Contradiction:
Object-generated harmful factorsVSMeasurement precision

Solution Approach 1:

The patent applies metaphorical 'color changes' by assigning different security status indicators (risk scores, threat levels, security colors) to domains based on automated analysis. Legitimate domains receive green/low-risk indicators while suspicious domains with similar naming patterns receive yellow/red/high-risk indicators, making it visually and computationally easy to distinguish malicious domains from legitimate ones despite naming similarities.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent introduces intermediary analysis layers between the domain name surface and the threat detection decision. Instead of directly comparing domain names, the system uses intermediary data sources including WHOIS registration information, DNS hosting records, SSL certificate data, and security feed classifications to mediate the detection process, providing contextual evidence that distinguishes legitimate similar-named domains from malicious ones.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11343269B2Techniques for detecting domain threats
Publication Date: 2022.05.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11343269B2 patent drawing
  • US11343269B2 patent drawing
  • US11343269B2 patent drawing

AI summary

An inventory of Internet-facing assets related to a username within a social media site is generated using network data gathered from network data sources. Using data sources of known threats, such as malware, phishing attempts, scam pages, blacklisted sites, and so on, a network analytic system generates analytical information about components that are owned, managed, and/or controlled by a target entity. A measure of identity threat is generated based on a classification model using the analytical information.