- Number
- 11736510
- Published
- 2023-08-22
- Filed
- 2021-07-27
- Assignee
- Disney Enterprises, Inc.
- Inventors
- Chen; Wen Tung et al.
- CPC
- H04L63/1433; H04L63/20
- Verdict
- Set aside IT domain security, unrelated
- Source
- Google Patents · FreePatentsOnline
Abstract
A domain security assurance system includes a computing platform having processing hardware and a memory storing software code. The processing hardware is configured to execute the software code to obtain domain inventory data identifying multiple domains, to predict, using the domain inventory data, which of the domains are owned by the same entity to identify commonly owned domains, and to determine, using the domain inventory data and the commonly owned domains, which of the commonly owned domains are controlled by the same administrator to identify one or more group(s) of commonly administered domains. When executed, the software code also removes, using the domain inventory data, duplicate domains included in the group(s) to identify non-duplicate domains, evaluates a susceptibility of each of the non-duplicate domains to a cyber-attack to identify one or more target domain(s) vulnerable to the cyber-attack, and identifies the target domain(s) for a security assessment.
Background
BACKGROUND (1) A large organization, such as a government entity or an affiliation of corporate subsidiaries, for example, may establish and support thousands of domains accessible by consumers or other users. In such an environment, the efficient identification of commonly owned or administered domains can be important for effective deployment of resources for assessing and mitigating security vulnerabilities of those domains. (2) Conventional solutions for identifying domains that are commonly owned or administered typically include costly and labor intensive manual investigation by human contributors. Consequently, conventional solutions may take many months to complete for a large organization and may nevertheless fail to identify some domains owned or administered by the organization. Thus, there is a need in the art for an automated solution for efficiently and inexpensively identifying and assessing the security vulnerabilities of commonly owned or administered domains.
Claims
1. A domain security assurance system comprising: a computing platform having a processing hardware and a system memory storing a software code; the processing hardware configured to execute the software code to: obtain domain inventory data identifying a plurality of domains; predict, using the domain inventory data, which of the plurality of domains are owned by a same entity to identify a plurality of commonly owned domains; determine, using the domain inventory data and the plurality of commonly owned domains, which of the plurality of commonly owned domains are controlled by a same administrator to identify one or more groups of commonly administered domains; remove, using the domain inventory data, duplicate domains included in the one or more groups of commonly administered domains to identify a plurality of non-duplicate domains; evaluate a susceptibility of each of the plurality of non-duplicate domains to a cyber-attack to identify at least one target domain vulnerable to the cyber-attack; and identify the at least one target domain for a security assessment; wherein the susceptibility of one of the plurality of non-duplicate domains to the cyber-attack is evaluated based on at least one of (i) an amount of content available on the one of the plurality of non-duplicate domains, (ii) an amount of interactive content available on the one of the plurality of non-duplicate domains, or (iii) a firewall quality of the one of the plurality of non-duplicate domains. ||
11. A method for use by a domain security assurance system including a computing platform having a processing hardware and a system memory storing a software code, the method comprising: obtaining, by the software code executed by the processing hardware, domain inventory data identifying a plurality of domains; predicting, by the software code executed by the processing hardware and using the domain inventory data, which of the plurality of domains are owned by a same entity to identify a plurality of commonly owned domains; determining, by the software code executed by the processing hardware and using the domain inventory data and the plurality of commonly owned domains, which of the plurality of commonly owned domains are controlled by a same administrator to identify one or more groups of commonly administered domains; removing, by the software code executed by the processing hardware and using the domain inventory data, duplicate domains included in the one or more groups of commonly administered domains to identify a plurality of non-duplicate domains; evaluating, by the software code executed by the processing hardware, a susceptibility of each of the plurality of non-duplicate domains to a cyber-attack to identify at least one target domain vulnerable to the cyber-attack; and identifying, by the software code executed by the processing hardware, the at least one target domain for a security assessment; wherein evaluating the susceptibility of one of the plurality of non-duplicate domains to the cyber-attack is based on at least one of (i) an amount of content available on the one of the plurality of non-duplicate domains, (ii) an amount of interactive content available on the one of the plurality of non-duplicate domains, or (iii) a firewall quality of the one of the plurality of non-duplicate domains.