Typosquatting Detection Using Passive IP Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting illegitimate typosquatting domains are inefficient and prone to false positives, as they often require visiting suspected domains, which can expose networks to threats and consume significant resources, and fail to distinguish between legitimate and illegitimate domains based on ownership.
Innovation Solution
The use of Internet Protocol (IP) information, such as IP addresses and Autonomous System Numbers, is employed to passively identify and categorize typosquatting domains, distinguishing between legitimate and illegitimate ones without visiting the domains, thereby reducing exposure to threats and improving computational efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If current methods visit suspected domains to detect typosquatting, then detection accuracy may improve, but network exposure to threats and resource consumption increase
Solution Approach 1:
The patent uses IP information (IP addresses and Autonomous System Numbers) as an intermediary to detect typosquatting domains without directly visiting them. By passively collecting and analyzing IP data from legitimate domains, the system can identify suspicious domains through IP mismatches while avoiding direct exposure to malicious content.
Solution Approach 2:
The patent replaces the mechanical action of visiting domains (HTTP requests, page rendering, content analysis) with a lighter mechanism based on IP information comparison. This substitution eliminates the need to actually connect to and process content from suspected domains, thereby reducing resource consumption and security risks.
2Measurement precision
If current methods visit suspected domains to detect typosquatting, then detection accuracy may improve, but resource consumption increases
Solution Approach 1:
The patent uses IP information as an intermediary that requires minimal computational resources to collect and analyze. Instead of downloading and processing full domain content, the system only needs to compare IP addresses and Autonomous System Numbers, dramatically reducing energy and computational resource consumption.
Solution Approach 2:
The patent employs lightweight, easily obtainable IP information data that requires minimal processing power. This approach uses inexpensive data (IP addresses and ASNs) that can be quickly collected and discarded after analysis, avoiding the heavy computational burden of full domain inspection.
3Quantity of substance
If domain monitoring is expanded to capture all variations, then detection coverage improves, but false positives increase due to inability to distinguish legitimate from illegitimate domains
Solution Approach 1:
The patent implements a feedback mechanism where IP information from legitimate domains is continuously collected and used to update the detection model. This feedback loop allows the system to learn which IP associations are legitimate, thereby reducing false positives while maintaining broad domain coverage for detection.
Solution Approach 2:
The patent uses IP information as an intermediary verification layer that helps distinguish legitimate from illegitimate domains. By checking whether the IP address and Autonomous System Number match expected values for known legitimate domains, the system can filter out false positives while maintaining comprehensive monitoring coverage.
Data Source
AI summary
Detecting illegitimate typosquatting with Internet Protocol (IP) information includes, at a computing device having connectivity to a network, obtaining a list of domains and filtering the list to generate a list of monitored domain strings. IP information is passively determined for domains associated with each of the monitored domain strings. A domain requested in network traffic for the network is identified as a candidate typosquatting domain and the candidate typosquatting domain is determined to be an illegitimate typosquatting domain based at least on the IP information. An action is initiated related to the illegitimate typosquatting domain.


