DOMAIN MALWARE FAMILY CLASSIFICATION
A method for classifying domains to malware families includes identifying a corpus of malicious domains, identifying one or more suspicious domains, extracting a timeframe corresponding to the one or more suspicious domains, calculating a rank coefficient between the one or more suspicious domains a...
Gespeichert in:
Hauptverfasser: | , , , , |
---|---|
Format: | Patent |
Sprache: | eng |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
container_end_page | |
---|---|
container_issue | |
container_start_page | |
container_title | |
container_volume | |
creator | BARTIK, AVISHAY Cohen, Yakov Shay-El Lazar, David RON, AVIV FREUND, ALON |
description | A method for classifying domains to malware families includes identifying a corpus of malicious domains, identifying one or more suspicious domains, extracting a timeframe corresponding to the one or more suspicious domains, calculating a rank coefficient between the one or more suspicious domains and a current seed domain of the corpus of malicious domains, determining whether the rank correlation coefficient exceeds a rank threshold for the one or more suspicious domains, comparing a number of suspicious domains whose correlation coefficients exceed the rank threshold to a relation threshold, and responsive to determining the number of suspicious domains whose correlation coefficients exceed the rank threshold exceeds the relation threshold, applying a tag to the suspicious domains indicating that the one or more suspicious domains correspond to a same malware family as the current seed domain. |
format | Patent |
fullrecord | <record><control><sourceid>epo_EVB</sourceid><recordid>TN_cdi_epo_espacenet_US2023114721A1</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>US2023114721A1</sourcerecordid><originalsourceid>FETCH-epo_espacenet_US2023114721A13</originalsourceid><addsrcrecordid>eNrjZFBx8fd19PRT8HX0CXcMclVwc_T19IlUcPZxDA72dPN0dgzx9PfjYWBNS8wpTuWF0twMym6uIc4euqkF-fGpxQWJyal5qSXxocFGBkbGhoYm5kaGjobGxKkCAAS4I9w</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>DOMAIN MALWARE FAMILY CLASSIFICATION</title><source>esp@cenet</source><creator>BARTIK, AVISHAY ; Cohen, Yakov Shay-El ; Lazar, David ; RON, AVIV ; FREUND, ALON</creator><creatorcontrib>BARTIK, AVISHAY ; Cohen, Yakov Shay-El ; Lazar, David ; RON, AVIV ; FREUND, ALON</creatorcontrib><description>A method for classifying domains to malware families includes identifying a corpus of malicious domains, identifying one or more suspicious domains, extracting a timeframe corresponding to the one or more suspicious domains, calculating a rank coefficient between the one or more suspicious domains and a current seed domain of the corpus of malicious domains, determining whether the rank correlation coefficient exceeds a rank threshold for the one or more suspicious domains, comparing a number of suspicious domains whose correlation coefficients exceed the rank threshold to a relation threshold, and responsive to determining the number of suspicious domains whose correlation coefficients exceed the rank threshold exceeds the relation threshold, applying a tag to the suspicious domains indicating that the one or more suspicious domains correspond to a same malware family as the current seed domain.</description><language>eng</language><creationdate>2023</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&date=20230413&DB=EPODOC&CC=US&NR=2023114721A1$$EHTML$$P50$$Gepo$$Hfree_for_read</linktohtml><link.rule.ids>230,308,776,881,25542,76290</link.rule.ids><linktorsrc>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&date=20230413&DB=EPODOC&CC=US&NR=2023114721A1$$EView_record_in_European_Patent_Office$$FView_record_in_$$GEuropean_Patent_Office$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>BARTIK, AVISHAY</creatorcontrib><creatorcontrib>Cohen, Yakov Shay-El</creatorcontrib><creatorcontrib>Lazar, David</creatorcontrib><creatorcontrib>RON, AVIV</creatorcontrib><creatorcontrib>FREUND, ALON</creatorcontrib><title>DOMAIN MALWARE FAMILY CLASSIFICATION</title><description>A method for classifying domains to malware families includes identifying a corpus of malicious domains, identifying one or more suspicious domains, extracting a timeframe corresponding to the one or more suspicious domains, calculating a rank coefficient between the one or more suspicious domains and a current seed domain of the corpus of malicious domains, determining whether the rank correlation coefficient exceeds a rank threshold for the one or more suspicious domains, comparing a number of suspicious domains whose correlation coefficients exceed the rank threshold to a relation threshold, and responsive to determining the number of suspicious domains whose correlation coefficients exceed the rank threshold exceeds the relation threshold, applying a tag to the suspicious domains indicating that the one or more suspicious domains correspond to a same malware family as the current seed domain.</description><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2023</creationdate><recordtype>patent</recordtype><sourceid>EVB</sourceid><recordid>eNrjZFBx8fd19PRT8HX0CXcMclVwc_T19IlUcPZxDA72dPN0dgzx9PfjYWBNS8wpTuWF0twMym6uIc4euqkF-fGpxQWJyal5qSXxocFGBkbGhoYm5kaGjobGxKkCAAS4I9w</recordid><startdate>20230413</startdate><enddate>20230413</enddate><creator>BARTIK, AVISHAY</creator><creator>Cohen, Yakov Shay-El</creator><creator>Lazar, David</creator><creator>RON, AVIV</creator><creator>FREUND, ALON</creator><scope>EVB</scope></search><sort><creationdate>20230413</creationdate><title>DOMAIN MALWARE FAMILY CLASSIFICATION</title><author>BARTIK, AVISHAY ; Cohen, Yakov Shay-El ; Lazar, David ; RON, AVIV ; FREUND, ALON</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-epo_espacenet_US2023114721A13</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>eng</language><creationdate>2023</creationdate><toplevel>online_resources</toplevel><creatorcontrib>BARTIK, AVISHAY</creatorcontrib><creatorcontrib>Cohen, Yakov Shay-El</creatorcontrib><creatorcontrib>Lazar, David</creatorcontrib><creatorcontrib>RON, AVIV</creatorcontrib><creatorcontrib>FREUND, ALON</creatorcontrib><collection>esp@cenet</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>BARTIK, AVISHAY</au><au>Cohen, Yakov Shay-El</au><au>Lazar, David</au><au>RON, AVIV</au><au>FREUND, ALON</au><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>DOMAIN MALWARE FAMILY CLASSIFICATION</title><date>2023-04-13</date><risdate>2023</risdate><abstract>A method for classifying domains to malware families includes identifying a corpus of malicious domains, identifying one or more suspicious domains, extracting a timeframe corresponding to the one or more suspicious domains, calculating a rank coefficient between the one or more suspicious domains and a current seed domain of the corpus of malicious domains, determining whether the rank correlation coefficient exceeds a rank threshold for the one or more suspicious domains, comparing a number of suspicious domains whose correlation coefficients exceed the rank threshold to a relation threshold, and responsive to determining the number of suspicious domains whose correlation coefficients exceed the rank threshold exceeds the relation threshold, applying a tag to the suspicious domains indicating that the one or more suspicious domains correspond to a same malware family as the current seed domain.</abstract><oa>free_for_read</oa></addata></record> |
fulltext | fulltext_linktorsrc |
identifier | |
ispartof | |
issn | |
language | eng |
recordid | cdi_epo_espacenet_US2023114721A1 |
source | esp@cenet |
title | DOMAIN MALWARE FAMILY CLASSIFICATION |
url | https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-02-02T23%3A12%3A34IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-epo_EVB&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=BARTIK,%20AVISHAY&rft.date=2023-04-13&rft_id=info:doi/&rft_dat=%3Cepo_EVB%3EUS2023114721A1%3C/epo_EVB%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true |