Malware Domain Sinkhole via Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware domain sinkhole technologies face scalability issues due to the inability to assign unique IP addresses to each domain, leading to complexity in maintenance and operational costs, which limits the effectiveness of identifying malware connections and patterns.

Innovation Solution

A computer-implemented method for creating malware domain sinkholes through domain clustering, where malware domains are grouped into clusters, and a single IP address is assigned to each cluster, using machine learning models like volumetric clustering and DGA clustering to identify and sort domains for sinkhole creation, allowing for efficient monitoring and re-clustering based on new domains and feedback.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If all DGA domains in a sinkhole resolve to the same IP address, then operational cost is reduced, but visibility into malware connections and patterns deteriorates

Engineering Contradiction:
Improveoperational costVSAvoidvisibility into malware connections
Core Design Contradiction:
Loss of energyVSLoss of information

Solution Approach 1:

The patent segments domains into clusters based on similarity metrics (lexical, volumetric, temporal), and assigns a unique IP address to each cluster rather than all domains. This segmentation maintains cost efficiency by limiting IP usage while improving visibility through cluster-level differentiation that reveals malware family patterns and connections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by differentiating IP assignment at the cluster level rather than uniformly across all domains. Each cluster receives a unique IP address based on its specific characteristics, providing localized visibility into different malware families while maintaining overall cost efficiency.

Inventive Principle:
Principle #3Local quality

2Loss of information

If a unique IP address is assigned to every domain in the sinkhole, then visibility into malware activities is improved, but device complexity and operational cost increase

Engineering Contradiction:
Improvevisibility into malware activitiesVSAvoidcomplexity in managing IP addresses
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges multiple domains into clusters based on similarity metrics, and assigns a single IP address to each cluster. This merging reduces the total number of IP addresses needed while maintaining visibility into malware activities at the cluster level, thereby reducing device complexity and management overhead.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates cluster representative domains that serve multiple functions: they represent entire clusters for IP assignment purposes, provide visibility into malware family patterns, and enable efficient sinkhole operations. This multi-functionality reduces the need for individual IP addresses for each domain.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If IPv6 addresses are used to assign unique IPs to every domain, then visibility is improved, but operational cost and maintenance complexity increase

Engineering Contradiction:
Improvevisibility into malware activitiesVSAvoidoperational cost
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The patent applies partial action by assigning unique IP addresses only to cluster representative domains rather than every individual domain. This partial differentiation provides sufficient visibility into malware activities while significantly reducing the total number of IP addresses needed compared to assigning unique IPs to all domains.

Inventive Principle:
Principle #16Partial or excessive action

4Loss of energy

If domains are carefully selected for registration, then operational cost is reduced, but scalability and comprehensiveness of malware detection deteriorate

Engineering Contradiction:
Improveoperational costVSAvoidscalability of malware detection
Core Design Contradiction:
Loss of energyVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary clustering and selection of representative domains before sinkhole operations begin. By pre-identifying cluster representatives based on similarity metrics, the system can scale to handle large numbers of domains efficiently while maintaining cost control and comprehensive malware detection coverage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11663331B2Creating a malware domain sinkhole by domain clustering
Publication Date: 2023.05.30 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11663331B2 patent drawing
  • US11663331B2 patent drawing
  • US11663331B2 patent drawing

AI summary

A computer-implemented method, a computer program product, and a computer system for creating malware domain sinkholes by domain clustering. The computer system clusters malware domains into domain clusters. The computer system collects domain metrics in the domain clusters. The computer system sorts clustered malware domains in the respective ones of the domain clusters, based on the domain metrics. The computer system selects, from the clustered malware domains in the respective ones of the domain clusters, a predetermined number of top domains as candidates of respective domain sinkholes, wherein the respective domain sinkholes are created for the respective ones of the domain clusters.