IP Reputation Service for Source-Level Threat Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for blocking malware, phishing, and spam attacks rely on URLs, which are difficult to track due to their variants and can be circumvented by minor changes, leading to inefficiencies in thwarting these threats.
Innovation Solution
An IP reputation service that identifies and blocks abuse-hosting services at their source by using the Internet Protocol (IP) address of attackers, hosting information on IP addresses known to serve malicious content, and integrating with existing URL-based solutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If URL-based blocking solutions are used, then threats can be blocked at the application layer, but the solutions are difficult to track due to URL variants and can be circumvented by minor changes
Solution Approach 1:
The patent transitions from tracking threats at the application layer (URLs) to the network layer (IP addresses). This dimensional shift from URL-based identification to IP-based identification resolves the issue of URL variants by operating at a lower, more stable network layer where the attacker's source IP address remains consistent across all malicious activities.
2Reliability
If hash-based or signature-based approaches are used, then identified domains can be blocked, but heuristics can be circumvented by slightly changing the binaries
Solution Approach 1:
The patent extracts the threat identification from the content level (URLs, binaries, hashes) and relocates it to the network source level (IP addresses). By taking out the dependency on content-based identification, the system eliminates the vulnerability to binary modifications and hash circumvention, as the IP address remains unchanged regardless of content variations.
3Productivity
If IP address tracking is implemented, then threats can be blocked at their source, but additional infrastructure and data management are required
Solution Approach 1:
The patent introduces an IP reputation service as an intermediary component that mediates between the DNS resolver and the client. This intermediary maintains the IP reputation database and provides reputation information to DNS resolvers, enabling efficient IP-based threat blocking without requiring complex infrastructure at every client device.
Data Source
AI summary
Various embodiments described above are directed to identifying abuse-hosting services at their source, rather than using such intermediaries as URLs and associated domains. In one or more embodiments, threats can be blocked by using the Internet protocol (IP) address of an identified attacker that is hosting content associated with abuse.


