Malicious Domain Detection via Multi-Profile Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems fail to effectively detect malicious Command and Control (CnC) channels within computer networks, which are used by attackers to compromise data and execute malicious code, as they often rely on periodic and covert communications that are difficult to distinguish from legitimate traffic.

Innovation Solution

A method and system that collect data on transmissions between endpoints and Internet sites, generate access time and popularity profiles, and model malicious domain profiles to predict suspicious domains, using features like domain reputation, connection patterns, and referrers, to identify potential CnC channels and generate alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security systems use periodic and covert communications to detect malicious CnC channels, then detection capability is improved, but the ability to distinguish from legitimate traffic deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoiddistinction from legitimate traffic
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the detection approach into multiple independent analysis components: access time profile analysis, popularity profile analysis, and maliciousness information integration. Each component analyzes a specific aspect of domain behavior separately, then combines results to achieve accurate detection while maintaining distinguishability from legitimate traffic through multi-dimensional characterization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces multiple new dimensions for analyzing domain behavior beyond simple periodic detection: access time patterns (temporal dimension), popularity metrics (frequency dimension), and maliciousness scores (threat dimension). This multi-dimensional approach enables differentiation of malicious CnC traffic from legitimate periodic communications by examining patterns across multiple simultaneous dimensions rather than a single metric.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If security systems monitor all domain transmissions in detail, then detection accuracy is improved, but system complexity and processing overhead worsen

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the most critical and discriminating features from the full set of transmission data: access time patterns, popularity metrics, and maliciousness information. Rather than analyzing all transmission details, the system selectively extracts key indicators that provide maximum detection value with minimum processing overhead, simplifying the system while maintaining high detection accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms raw transmission data into standardized profile parameters with specific statistical characteristics: access time profiles use temporal patterns and intervals, popularity profiles use frequency and distribution metrics, and maliciousness profiles use scored assessments. This parameter transformation converts complex raw data into manageable, comparable formats that reduce processing complexity while preserving detection accuracy.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security systems use multiple layers of security apparatus, then overall security coverage is improved, but false positive rates worsen

Engineering Contradiction:
Improvesecurity coverageVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where detection results from access time profiling, popularity analysis, and maliciousness assessment are continuously refined based on their combined outcomes. The system uses feedback loops to adjust thresholds and weighting factors, learning from false positives and negatives to improve the accuracy of subsequent detections across all security layers, thereby reducing false positive rates while maintaining comprehensive coverage.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent creates a composite detection approach that combines multiple independent detection methodologies (temporal analysis, popularity metrics, maliciousness information) into a unified assessment framework. Rather than relying on any single layer alone, the system integrates results from multiple security apparatus layers, using their combined strength to achieve accurate detection with reduced false positives through mutual validation and cross-verification.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS10574681B2Detection of known and unknown malicious domains
Publication Date: 2020.02.25 PALO ALTO NETWORKS INC
  • US10574681B2 patent drawing
  • US10574681B2 patent drawing
  • US10574681B2 patent drawing

AI summary

A method, including collecting information on data transmitted at respective times between multiple endpoints and multiple Internet sites having respective domains, and acquiring, from one or more external or internal sources, maliciousness information for the domains. An access time profile is generated based on the times of the transmissions to the domains, and a popularity profile is generated based on the transmissions to the domains. A malicious domain profile is generated based on the acquired maliciousness information, and the collected information is modeled using the access time profile, the popularity profile and the malicious domain profile. Based on their respective modeled collected information, one or more of the domains is predicted to be suspicious, and an alert is generated for the one or more identified domains.