Malware Domain Sinkhole via Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware domain sinkhole technologies face scalability issues due to the inability to assign unique IP addresses to each domain, leading to complexity in maintenance and operational costs, which limits the effectiveness of identifying malware connections and patterns.
Innovation Solution
A computer-implemented method for creating malware domain sinkholes through domain clustering, where malware domains are grouped into clusters, and a single IP address is assigned to each cluster, using machine learning models like volumetric clustering and DGA clustering to identify and sort domains for sinkhole creation, allowing for efficient monitoring and re-clustering based on new domains and feedback.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If all DGA domains in a sinkhole resolve to the same IP address, then operational cost is reduced, but visibility into malware connections and patterns deteriorates
Solution Approach 1:
The patent segments domains into clusters based on similarity metrics (lexical, volumetric, temporal), and assigns a unique IP address to each cluster rather than all domains. This segmentation maintains cost efficiency by limiting IP usage while improving visibility through cluster-level differentiation that reveals malware family patterns and connections.
Solution Approach 2:
The patent applies local quality by differentiating IP assignment at the cluster level rather than uniformly across all domains. Each cluster receives a unique IP address based on its specific characteristics, providing localized visibility into different malware families while maintaining overall cost efficiency.
2Loss of information
If a unique IP address is assigned to every domain in the sinkhole, then visibility into malware activities is improved, but device complexity and operational cost increase
Solution Approach 1:
The patent merges multiple domains into clusters based on similarity metrics, and assigns a single IP address to each cluster. This merging reduces the total number of IP addresses needed while maintaining visibility into malware activities at the cluster level, thereby reducing device complexity and management overhead.
Solution Approach 2:
The patent creates cluster representative domains that serve multiple functions: they represent entire clusters for IP assignment purposes, provide visibility into malware family patterns, and enable efficient sinkhole operations. This multi-functionality reduces the need for individual IP addresses for each domain.
3Loss of information
If IPv6 addresses are used to assign unique IPs to every domain, then visibility is improved, but operational cost and maintenance complexity increase
Solution Approach 1:
The patent applies partial action by assigning unique IP addresses only to cluster representative domains rather than every individual domain. This partial differentiation provides sufficient visibility into malware activities while significantly reducing the total number of IP addresses needed compared to assigning unique IPs to all domains.
4Loss of energy
If domains are carefully selected for registration, then operational cost is reduced, but scalability and comprehensiveness of malware detection deteriorate
Solution Approach 1:
The patent performs preliminary clustering and selection of representative domains before sinkhole operations begin. By pre-identifying cluster representatives based on similarity metrics, the system can scale to handle large numbers of domains efficiently while maintaining cost control and comprehensive malware detection coverage.
Data Source
AI summary
A computer-implemented method, a computer program product, and a computer system for creating malware domain sinkholes by domain clustering. The computer system clusters malware domains into domain clusters. The computer system collects domain metrics in the domain clusters. The computer system sorts clustered malware domains in the respective ones of the domain clusters, based on the domain metrics. The computer system selects, from the clustered malware domains in the respective ones of the domain clusters, a predetermined number of top domains as candidates of respective domain sinkholes, wherein the respective domain sinkholes are created for the respective ones of the domain clusters.


