IP Reputation Service for Source-Level Threat Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for blocking malware, phishing, and spam attacks rely on URLs, which are difficult to track due to their variants and can be circumvented by minor changes, leading to inefficiencies in thwarting these threats.

Innovation Solution

An IP reputation service that identifies and blocks abuse-hosting services at their source by using the Internet Protocol (IP) address of attackers, hosting information on IP addresses known to serve malicious content, and integrating with existing URL-based solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If URL-based blocking solutions are used, then threats can be blocked at the application layer, but the solutions are difficult to track due to URL variants and can be circumvented by minor changes

Engineering Contradiction:
Improvethreat blocking reliabilityVSAvoidURL variant adaptation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from tracking threats at the application layer (URLs) to the network layer (IP addresses). This dimensional shift from URL-based identification to IP-based identification resolves the issue of URL variants by operating at a lower, more stable network layer where the attacker's source IP address remains consistent across all malicious activities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If hash-based or signature-based approaches are used, then identified domains can be blocked, but heuristics can be circumvented by slightly changing the binaries

Engineering Contradiction:
Improvemalware detection reliabilityVSAvoidbinary modification evasion
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts the threat identification from the content level (URLs, binaries, hashes) and relocates it to the network source level (IP addresses). By taking out the dependency on content-based identification, the system eliminates the vulnerability to binary modifications and hash circumvention, as the IP address remains unchanged regardless of content variations.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If IP address tracking is implemented, then threats can be blocked at their source, but additional infrastructure and data management are required

Engineering Contradiction:
Improvethreat blocking efficiencyVSAvoidIP reputation service infrastructure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an IP reputation service as an intermediary component that mediates between the DNS resolver and the client. This intermediary maintains the IP reputation database and provides reputation information to DNS resolvers, enabling efficient IP-based threat blocking without requiring complex infrastructure at every client device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8695092B2Host IP reputation
Publication Date: 2014.04.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8695092B2 patent drawing
  • US8695092B2 patent drawing
  • US8695092B2 patent drawing

AI summary

Various embodiments described above are directed to identifying abuse-hosting services at their source, rather than using such intermediaries as URLs and associated domains. In one or more embodiments, threats can be blocked by using the Internet protocol (IP) address of an identified attacker that is hosting content associated with abuse.