Patents by Inventor Daiping Liu

Daiping Liu has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20250247403
    Abstract: A signature generator has been designed that can create a malicious campaign signature with substantial coverage of malicious campaign behavior without impeding benign traffic. The malicious campaign signature generator uses data of multiple, known malicious campaigns to identify abused, benign network entities. The signature generator builds a graph data structure for each malicious campaign that represents the abused network entities. The relationships encoded in the graph data structure indicate the use of the combination of abused network entities in the campaign. The signature generator aggregates the graph data structures and identifies a combination of the benign network entities that were highly abused across the multiple malicious campaigns with respect to all of the abused network entities represented in the graph data structures. A signature is then created from the identifiers of this combination of highly abused network entities.
    Type: Application
    Filed: January 30, 2024
    Publication date: July 31, 2025
    Inventors: Zhanhao Chen, Chao Lei, Chien-Hua Lu, Daiping Liu
  • Patent number: 12355792
    Abstract: Detection of strategically aged domains is detected. A list of aged dormant domains is determined, including by evaluating passive Domain Name System (DNS) information. The list of aged dormant domains is monitored for a change by an aged dormant domain from a dormant domain status to an active status. In response to determining the change to active status of the aged dormant domain, an action is taken with respect to the aged dormant domain.
    Type: Grant
    Filed: November 30, 2022
    Date of Patent: July 8, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Zhanhao Chen, Daiping Liu, Wanjin Li, Fan Fei
  • Patent number: 12348563
    Abstract: Detection of squatting domains is disclosed. A set of new fully qualified domain names (FQDNs) is received. The set of new FQDNs is analyzed to detect domain squatting by identifying a subset of the new FQDNs as candidate squatting domains. The candidate squatting domains are distributed to a security device/service.
    Type: Grant
    Filed: March 19, 2024
    Date of Patent: July 1, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Zhanhao Chen, Jun Wang, Daiping Liu
  • Publication number: 20250202916
    Abstract: Various embodiments provide a system, method, and device for applying a DNS activity classification framework. The method incudes (i) collecting DNS-related activity, (ii) determining whether the DNS-related activity is associated with a DNS tunneling campaign or tool, and (iii) performing an active measure in response to detecting DNS traffic associated with a tunneling domain.
    Type: Application
    Filed: December 13, 2023
    Publication date: June 19, 2025
    Inventors: Ruian Duan, Daiping Liu, Zihang Xiao
  • Patent number: 12301595
    Abstract: The present application discloses a method, system, and computer system for predicting responses to DNS queries. The method includes receiving a DNS query comprising a subdomain portion and a root domain portion from a client device, determining whether to obtain target address information corresponding to the DNS from a predictive cache, in response to determining to obtain the target address information from the predictive cache, obtaining the target address information from the predictive cache, and providing the target address information to the client device.
    Type: Grant
    Filed: May 21, 2024
    Date of Patent: May 13, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Daiping Liu, Jun Wang, Wei Xu
  • Patent number: 12294592
    Abstract: Techniques for generating actionable indicators of compromise (IOCs) are disclosed. A set of potential sources for IOCs are received. One or more candidate IOCs are extracted from at least one source included in the set of potential sources. An actionable IOC is automatically identified from the one or more candidate IOCs. The actionable IOC is provided to a security enforcement service.
    Type: Grant
    Filed: September 27, 2023
    Date of Patent: May 6, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Janos Szurdi, Daiping Liu, Jun Wang
  • Publication number: 20250063066
    Abstract: The present application discloses a method, system, and computer system for identifying dangling records. The method includes obtaining a set of domains, determining whether a record associated with a domain comprised in the set of domains is dangling, and in response to determining that the record associated with the domain is dangling, providing, to a registrant, a notification that the record is dangling.
    Type: Application
    Filed: November 6, 2024
    Publication date: February 20, 2025
    Inventors: Daiping Liu, Ruian Duan, Jun Wang
  • Publication number: 20250047687
    Abstract: Techniques for detecting and protecting claimable non-existent domains are disclosed. A system, process, and/or computer program product for detecting and protecting claimable non-existent domains includes monitoring network activity using a network security device, detecting that a session is querying a claimable non-existent domain using a domain name system (DNS) security service, and performing an action in response to the session querying the claimable non-existent domain.
    Type: Application
    Filed: July 31, 2023
    Publication date: February 6, 2025
    Inventors: Ruian Duan, Zhanhao Chen, Janos Szurdi, Daiping Liu
  • Patent number: 12179448
    Abstract: Techniques presented herein relate to vulcanizing equipment that includes a vulcanizing mold in which a vulcanizing cavity is formed, a vulcanizing bladder suitable for being placed in the vulcanizing cavity, and a supporting assembly that includes a center rod and a clamping device arranged on the center rod. The clamping device is suitable for installing the curing bladder in the cavity in a sealed manner. The vulcanizing equipment further includes a heating assembly and a gas circulation assembly that are arranged in the curing bladder in a stacked manner in the axial direction of the center rod. The gas circulation assembly is suitable for circulating a heated heating medium in the curing bladder. A driving assembly of the vulcanizing equipment includes a rotating shaft sleeve that is arranged on the outer side of the center rod in a clearance-fit manner and is connected to the gas circulation assembly.
    Type: Grant
    Filed: September 23, 2022
    Date of Patent: December 31, 2024
    Assignee: Himile Mechanical Science and Technology (Shandong) Co., Ltd
    Inventors: Wei Zhang, Yang Zhao, Zhilan Liu, Riwen Sun, Longfei Gao, Qiang Fang, Daiping Liu
  • Patent number: 12166792
    Abstract: The present application discloses a method, system, and computer system for identifying dangling records. The method includes obtaining a set of domains, determining whether a record associated with a domain comprised in the set of domains is dangling, and in response to determining that the record associated with the domain is dangling, providing, to a registrant, a notification that the record is dangling.
    Type: Grant
    Filed: October 26, 2021
    Date of Patent: December 10, 2024
    Assignee: Palo Alto Networks, Inc.
    Inventors: Daiping Liu, Ruian Duan, Jun Wang
  • Publication number: 20240364742
    Abstract: A service includes a trained model comprising a classifier that predicts whether domain names are dictionary DGA generated. Using passive DNS data and/or a heuristic analysis based on natural language processing of the domain name, the service filters domain names that are not candidate (i.e., potential) dictionary DGA domain names out of the detection pipeline. There domain names are thus classified without being fed into the model for more computationally expensive processing. Domain names that are not filtered out are queued for input into an instance of the model and classification by the model, with the queued domain names processed in small batches and load balanced across model instances. Predicted domain name classes output by the model are cached for subsequent cache reads to avoid multiple runs of the model for one domain name.
    Type: Application
    Filed: April 28, 2023
    Publication date: October 31, 2024
    Inventors: Janos Szurdi, Daiping Liu, Tong Zhao, Tingxiang Zhu, Linan Li
  • Patent number: 12132759
    Abstract: Inline package name based supply chain attack detection and prevention is disclosed. An indication that a client device has made a request to a remote server for a package is received. A data appliance then performs an action responsive to the received indication. In an example implementation, the data appliance makes a determination of whether the request for the package is associated with a nonexisting package.
    Type: Grant
    Filed: November 2, 2023
    Date of Patent: October 29, 2024
    Assignee: Palo Alto Networks, Inc.
    Inventors: Ruian Duan, Daiping Liu, Jun Wang, Zihang Xiao
  • Publication number: 20240314144
    Abstract: The present application discloses a method, system, and computer system for predicting responses to DNS queries. The method includes receiving a DNS query comprising a subdomain portion and a root domain portion from a client device, determining whether to obtain target address information corresponding to the DNS from a predictive cache, in response to determining to obtain the target address information from the predictive cache, obtaining the target address information from the predictive cache, and providing the target address information to the client device.
    Type: Application
    Filed: May 21, 2024
    Publication date: September 19, 2024
    Inventors: Daiping Liu, Jun Wang, Wei Xu
  • Publication number: 20240259427
    Abstract: Detection of squatting domains is disclosed. A set of new fully qualified domain names (FQDNs) is received. The set of new FQDNs is analyzed to detect domain squatting by identifying a subset of the new FQDNs as candidate squatting domains. The candidate squatting domains are distributed to a security device/service.
    Type: Application
    Filed: March 19, 2024
    Publication date: August 1, 2024
    Inventors: Zhanhao Chen, Jun Wang, Daiping Liu
  • Publication number: 20240227336
    Abstract: The present invention relates to the technical field of vulcanizing equipment, and in particular, to vulcanizing equipment, comprising: a vulcanizing mold in which a vulcanizing cavity is formed; a vulcanizing bladder suitable for being placed in the vulcanizing cavity; and a supporting assembly comprising a center rod and a clamping device arranged on the center rod, the clamping device being suitable for installing the curing bladder in the cavity in a sealed manner. The vulcanizing equipment further comprises: a heating assembly and a gas circulation assembly that are arranged in the curing bladder in a stacked manner in the axial direction of the center rod, the gas circulation assembly being suitable for circulating a heated heating medium in the curing bladder; and a driving assembly comprising a rotating shaft sleeve that is arranged on the outer side of the center rod in a clearance-fit manner and connected to the gas circulation assembly.
    Type: Application
    Filed: September 23, 2022
    Publication date: July 11, 2024
    Inventors: Wei ZHANG, Yang ZHAO, Zhilan LIU, Riwen SUN, Longfei GAO, Qiang FANG, Daiping LIU
  • Patent number: 12028354
    Abstract: The present application discloses a method, system, and computer system for predicting responses to DNS queries. The method includes receiving a DNS query comprising a subdomain portion and a root domain portion from a client device, determining whether to obtain target address information corresponding to the DNS from a predictive cache, in response to determining to obtain the target address information from the predictive cache, obtaining the target address information from the predictive cache, and providing the target address information to the client device.
    Type: Grant
    Filed: October 26, 2021
    Date of Patent: July 2, 2024
    Assignee: Palo Alto Networks, Inc.
    Inventors: Daiping Liu, Jun Wang, Wei Xu
  • Publication number: 20240205240
    Abstract: Real-time detection of DNS infiltration traffic is disclosed. A DNS response associated with a DNS query sent by a client device is received. An attempted DNS infiltration is detected based at least in part on an automated analysis of the DNS response. In response to the detection, a remedial action is performed.
    Type: Application
    Filed: June 30, 2023
    Publication date: June 20, 2024
    Inventors: Ruian Duan, Daiping Liu, Tingxiang Zhu, Xing Wang, Jun Wang
  • Publication number: 20240179164
    Abstract: Detection of strategically aged domains is detected. A list of aged dormant domains is determined, including by evaluating passive Domain Name System (DNS) information. The list of aged dormant domains is monitored for a change by an aged dormant domain from a dormant domain status to an active status. In response to determining the change to active status of the aged dormant domain, an action is taken with respect to the aged dormant domain.
    Type: Application
    Filed: November 30, 2022
    Publication date: May 30, 2024
    Inventors: Zhanhao Chen, Daiping Liu, Wanjin Li, Fan Fei
  • Patent number: 11973800
    Abstract: Detection of squatting domains is disclosed. A set of new fully qualified domain names (FQDNs) is received. The set of new FQDNs is analyzed to detect domain squatting by identifying a subset of the new FQDNs as candidate squatting domains. The candidate squatting domains are distributed to a security device/service.
    Type: Grant
    Filed: August 20, 2021
    Date of Patent: April 30, 2024
    Assignee: Palo Alto Networks, Inc.
    Inventors: Zhanhao Chen, Jun Wang, Daiping Liu
  • Publication number: 20240073244
    Abstract: Inline package name based supply chain attack detection and prevention is disclosed. An indication that a client device has made a request to a remote server for a package is received. A data appliance then performs an action responsive to the received indication. In an example implementation, the data appliance makes a determination of whether the request for the package is associated with a nonexisting package.
    Type: Application
    Filed: November 2, 2023
    Publication date: February 29, 2024
    Inventors: Ruian Duan, Daiping Liu, Jun Wang, Zihang Xiao