×

Method and system for identifying network addresses associated with suspect network destinations

  • US 7,590,707 B2
  • Filed: 08/07/2006
  • Issued: 09/15/2009
  • Est. Priority Date: 08/07/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method for identifying a network address associated with a suspect network destination, the method comprising:

  • collecting a set of Uniform Resource Locators (URLs), each URL in the set of URLs being associated with a suspect network destination;

    segmenting each URL in the set of URLs into a set of component partsfor each URL in the set of URLs, classifying each component part in the set of component parts from that URL as one of a primary domain, a subdomain, and a page;

    for each URL in the set of URLs, hashing each component part in the set of component parts from that URL to produce a hash value for that component part;

    storing in a database the hash values of the component parts of the URLs in the set of URLs;

    receiving a target URL to be analyzed;

    segmenting the target URL into a set of component parts;

    classifying each component part in the set of component parts from the target URL as one of a primary domain, a subdomain, and a page;

    hashing each component part in the set of component parts from the target URL to produce a hash value for that component part;

    comparing the hash values of the set of component parts from the target URL with the hash values stored in the database;

    computing a score that indicates the extent to which the hash values of the set of component parts from the target URL match hash values stored in the database; and

    taking corrective action, when the score satisfies a predetermined criterion, and wherein the predetermined criterion is that the score exceed a predetermined threshold.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×