Application (pre-grant publication)
Domain Security Assurance Automation
- Number
- 20230034954
- Published
- 2023-02-02
- Filed
- 2021-07-27
- Assignee
- Disney Enterprises, Inc.
- Inventors
- Chen; Wen Tung et al.
- CPC
- H04L63/20; H04L63/1433
- Verdict
- Set aside IT domain security, unrelated
- Source
- Google Patents · FreePatentsOnline
Abstract
A domain security assurance system includes a computing platform having processing hardware and a memory storing software code. The processing hardware is configured to execute the software code to obtain domain inventory data identifying multiple domains, to predict, using the domain inventory data, which of the domains are owned by the same entity to identify commonly owned domains, and to determine, using the domain inventory data and the commonly owned domains, which of the commonly owned domains are controlled by the same administrator to identify one or more group(s) of commonly administered domains. When executed, the software code also removes, using the domain inventory data, duplicate domains included in the group(s) to identify non-duplicate domains, evaluates a susceptibility of each of the non-duplicate domains to a cyber-attack to identify one or more target domain(s) vulnerable to the cyber-attack, and identifies the target domain(s) for a security assessment.
Background
BACKGROUND
A large organization, such as a government entity or an affiliation of corporate subsidiaries, for example, may establish and support thousands of domains accessible by consumers or other users. In such an environment, the efficient identification of commonly owned or administered domains can be important for effective deployment of resources for assessing and mitigating security vulnerabilities of those domains.
Conventional solutions for identifying domains that are commonly owned or administered typically include costly and labor intensive manual investigation by human contributors. Consequently, conventional solutions may take many months to complete for a large organization and may nevertheless fail to identify some domains owned or administered by the organization. Thus, there is a need in the art for an automated solution for efficiently and inexpensively identifying and assessing the security vulnerabilities of commonly owned or administered domains.