Malicious Domain Detection via Multi-Profile Modeling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems fail to effectively detect malicious Command and Control (CnC) channels within computer networks, which are used by attackers to compromise data and execute malicious code, as they often rely on periodic and covert communications that are difficult to distinguish from legitimate traffic.
Innovation Solution
A method and system that collect data on transmissions between endpoints and Internet sites, generate access time and popularity profiles, and model malicious domain profiles to predict suspicious domains, using features like domain reputation, connection patterns, and referrers, to identify potential CnC channels and generate alerts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security systems use periodic and covert communications to detect malicious CnC channels, then detection capability is improved, but the ability to distinguish from legitimate traffic deteriorates
Solution Approach 1:
The patent segments the detection approach into multiple independent analysis components: access time profile analysis, popularity profile analysis, and maliciousness information integration. Each component analyzes a specific aspect of domain behavior separately, then combines results to achieve accurate detection while maintaining distinguishability from legitimate traffic through multi-dimensional characterization.
Solution Approach 2:
The patent introduces multiple new dimensions for analyzing domain behavior beyond simple periodic detection: access time patterns (temporal dimension), popularity metrics (frequency dimension), and maliciousness scores (threat dimension). This multi-dimensional approach enables differentiation of malicious CnC traffic from legitimate periodic communications by examining patterns across multiple simultaneous dimensions rather than a single metric.
2Measurement precision
If security systems monitor all domain transmissions in detail, then detection accuracy is improved, but system complexity and processing overhead worsen
Solution Approach 1:
The patent extracts only the most critical and discriminating features from the full set of transmission data: access time patterns, popularity metrics, and maliciousness information. Rather than analyzing all transmission details, the system selectively extracts key indicators that provide maximum detection value with minimum processing overhead, simplifying the system while maintaining high detection accuracy.
Solution Approach 2:
The patent transforms raw transmission data into standardized profile parameters with specific statistical characteristics: access time profiles use temporal patterns and intervals, popularity profiles use frequency and distribution metrics, and maliciousness profiles use scored assessments. This parameter transformation converts complex raw data into manageable, comparable formats that reduce processing complexity while preserving detection accuracy.
3Reliability
If security systems use multiple layers of security apparatus, then overall security coverage is improved, but false positive rates worsen
Solution Approach 1:
The patent implements feedback mechanisms where detection results from access time profiling, popularity analysis, and maliciousness assessment are continuously refined based on their combined outcomes. The system uses feedback loops to adjust thresholds and weighting factors, learning from false positives and negatives to improve the accuracy of subsequent detections across all security layers, thereby reducing false positive rates while maintaining comprehensive coverage.
Solution Approach 2:
The patent creates a composite detection approach that combines multiple independent detection methodologies (temporal analysis, popularity metrics, maliciousness information) into a unified assessment framework. Rather than relying on any single layer alone, the system integrates results from multiple security apparatus layers, using their combined strength to achieve accurate detection with reduced false positives through mutual validation and cross-verification.
Data Source
AI summary
A method, including collecting information on data transmitted at respective times between multiple endpoints and multiple Internet sites having respective domains, and acquiring, from one or more external or internal sources, maliciousness information for the domains. An access time profile is generated based on the times of the transmissions to the domains, and a popularity profile is generated based on the transmissions to the domains. A malicious domain profile is generated based on the acquired maliciousness information, and the collected information is modeled using the access time profile, the popularity profile and the malicious domain profile. Based on their respective modeled collected information, one or more of the domains is predicted to be suspicious, and an alert is generated for the one or more identified domains.


