Watering Hole Attack Detection via Domain Sequence Mining

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods are inadequate for detecting watering hole attacks efficiently, as they struggle to process large amounts of data quickly and accurately identify low support, high confidence domain sequences indicative of such attacks.

Innovation Solution

A process involving the generation of domain sequences from proxy logs, identification of low support and high confidence sequences using sequential pattern mining, and flagging potential infected domains or exploit kit hosts for further investigation and security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional security detection methods are used to detect watering hole attacks, then detection capability is maintained, but processing speed and efficiency deteriorate when handling large amounts of data

Engineering Contradiction:
Improvedata processing speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent extracts and focuses analysis on specific domain sequences that exhibit low support and high confidence characteristics, rather than processing all domain data uniformly. This extraction approach enables the system to quickly identify suspicious patterns indicative of watering hole attacks while maintaining detection accuracy through targeted analysis of the most promising candidates.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameters for domain sequence evaluation by establishing specific thresholds for support (frequency) and confidence (predictiveness) levels. By adjusting these parameters, the system optimizes its ability to distinguish between legitimate domain usage and malicious watering hole attacks, achieving both speed and accuracy through parameter optimization rather than brute-force processing.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive domain sequence analysis is performed to identify all potential attacks, then detection completeness is improved, but processing time increases significantly

Engineering Contradiction:
Improvedetection completenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by analyzing only domain sequences that meet specific criteria (low support and high confidence) rather than exhaustively analyzing all possible domain sequences. This selective approach maintains detection completeness for actual attacks while significantly reducing processing time by excluding obviously legitimate or irrelevant domain patterns from analysis.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary filtering and classification of domain sequences before full analysis, using support and confidence metrics to pre-sort potential targets. This preliminary action identifies the most suspicious sequences in advance, allowing the system to allocate processing resources efficiently and maintain completeness for attack detection while avoiding time-consuming analysis of benign domains.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If the system focuses only on high confidence sequences, then false positive rate is reduced, but detection sensitivity to rare attacks decreases

Engineering Contradiction:
Improvefalse positive rateVSAvoiddetection sensitivity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent employs dynamic thresholding for support and confidence parameters, allowing the system to adapt its sensitivity based on the analysis context. By dynamically adjusting these thresholds, the system maintains low false positive rates for common patterns while preserving sensitivity to detect rare and evolving watering hole attacks, achieving both precision and sensitivity through adaptive parameter adjustment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different quality thresholds and analysis depths to different domain sequences based on their local characteristics. High confidence sequences receive stricter validation to minimize false positives, while low support sequences are analyzed with appropriate flexibility to capture rare attack patterns. This localized quality assessment enables the system to maintain both precision for common cases and sensitivity for rare cases simultaneously.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10313390B1Discovering domain associations for watering hole attack detection
Publication Date: 2019.06.04 EMC IP HLDG CO LLC
  • US10313390B1 patent drawing
  • US10313390B1 patent drawing
  • US10313390B1 patent drawing

AI summary

One or more proxy logs are processed in order to generate a plurality of domain sequences. One or more domain sequences which have low support and high confidence within the plurality of domain sequences are identified. The identified domain sequences are flagged as including one or more of the following: an infected watering hole domain or an exploit kit host.