Invention Grant
- Patent Title: Systems and methods for detecting suspicious internet addresses
- Patent Title (中): 用于检测可疑互联网地址的系统和方法
-
Application No.: US14324824Application Date: 2014-07-07
-
Publication No.: US09332022B1Publication Date: 2016-05-03
- Inventor: Peter Ashley
- Applicant: Symantec Corporation
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: ALG Intellectual Property, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
The disclosed computer-implemented method for detecting suspicious Internet addresses may include (1) monitoring Internet communications of an entity (e.g., an organization or individual), (2) compiling an Internet-address history for the entity that includes one or more Internet addresses involved in the Internet communications of the entity, (3) detecting, after compiling the Internet-address history for the entity, an additional Internet address that may be used in future Internet communications involving the entity, (4) computing a similarity metric between the additional Internet address and at least one Internet-address in the Internet-address history, (5) determining that the similarity metric indicates that the additional Internet address is suspicious, and (6) performing a security action in response to determining that the similarity metric indicates that the additional Internet address is suspicious. Various other methods, systems, and computer-readable media are also disclosed.
Information query