×

Filter-based identification of malicious websites

  • US 8,850,570 B1
  • Filed: 06/30/2008
  • Issued: 09/30/2014
  • Est. Priority Date: 06/30/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method of identifying malicious websites, the method comprising:

  • identifying a candidate suspicious website;

    identifying a plurality of lightweight features associated with the candidate suspicious website;

    identifying a dataset comprising a plurality of lightweight features associated with a plurality of known malicious websites and a plurality of lightweight features associated with a plurality of known innocuous websites;

    generating a filter classifier comprising a statistical model including weights for the plurality of lightweight features associated with the plurality of known malicious websites and the plurality of lightweight features associated with the plurality of known innocuous websites that distinguish the plurality of known malicious websites from the plurality of known innocuous websites;

    determining, with the weights of the generated filter classifier, a continuous filter score for the candidate suspicious website based on the plurality of lightweight features associated with the candidate suspicious website, the continuous filter score indicating similarity between the lightweight features associated with the candidate suspicious website and the lightweight features of the known malicious websites;

    prioritizing a scan of the candidate suspicious website relative to other candidate suspicious websites in response to the continuous filter score for the candidate suspicious website and continuous filter scores for the other candidate suspicious websites;

    determining whether the candidate suspicious website is a malicious website responsive at least in part to the scan;

    updating, in response to determining that the suspicious website is a malicious website, the plurality of lightweight features associated with the plurality of known malicious websites in the dataset to include the plurality of lightweight features associated with the suspicious website; and

    re-generating the filter classifier to update the statistical model to include at least one modified weight for the plurality of lightweight features based on the updated dataset.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×