Patents by Inventor Daiping Liu

Daiping Liu has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11973800
    Abstract: Detection of squatting domains is disclosed. A set of new fully qualified domain names (FQDNs) is received. The set of new FQDNs is analyzed to detect domain squatting by identifying a subset of the new FQDNs as candidate squatting domains. The candidate squatting domains are distributed to a security device/service.
    Type: Grant
    Filed: August 20, 2021
    Date of Patent: April 30, 2024
    Assignee: Palo Alto Networks, Inc.
    Inventors: Zhanhao Chen, Jun Wang, Daiping Liu
  • Publication number: 20240073244
    Abstract: Inline package name based supply chain attack detection and prevention is disclosed. An indication that a client device has made a request to a remote server for a package is received. A data appliance then performs an action responsive to the received indication. In an example implementation, the data appliance makes a determination of whether the request for the package is associated with a nonexisting package.
    Type: Application
    Filed: November 2, 2023
    Publication date: February 29, 2024
    Inventors: Ruian Duan, Daiping Liu, Jun Wang, Zihang Xiao
  • Publication number: 20240039890
    Abstract: A method and system for detecting shadowed domains is provided. New hostnames are collected for a predetermined period of time. Candidate shadowed domains are selected from the new hostnames. Classification of the candidate shadowed domains is performed based on a plurality of features relating to the candidate shadowed domains to output a set of identified shadowed domains. An action is performed based on the set of identified shadowed domains.
    Type: Application
    Filed: August 1, 2022
    Publication date: February 1, 2024
    Inventors: Janos Szurdi, Rebekah Houser, Daiping Liu
  • Publication number: 20240031383
    Abstract: Techniques for generating actionable indicators of compromise (IOCs) are disclosed. A set of potential sources for IOCs are received. One or more candidate IOCs are extracted from at least one source included in the set of potential sources. An actionable IOC is automatically identified from the one or more candidate IOCs. The actionable IOC is provided to a security enforcement service.
    Type: Application
    Filed: September 27, 2023
    Publication date: January 25, 2024
    Inventors: Janos Szurdi, Daiping Liu, Jun Wang
  • Patent number: 11882130
    Abstract: Techniques for generating actionable indicators of compromise (IOCs) are disclosed. A set of potential sources for IOCs are received. One or more candidate IOCs are extracted from at least one source included in the set of potential sources. An actionable IOC is automatically identified from the one or more candidate IOCs. The actionable IOC is provided to a security enforcement service.
    Type: Grant
    Filed: February 25, 2021
    Date of Patent: January 23, 2024
    Assignee: Palo Alto Networks, Inc.
    Inventors: Janos Szurdi, Daiping Liu, Jun Wang
  • Patent number: 11863586
    Abstract: Inline package name based supply chain attack detection and prevention is disclosed. An indication that a client device has made a request to a remote server for a package is received. A data appliance then performs an action responsive to the received indication. In an example implementation, the data appliance makes a determination of whether the request for the package is associated with a nonexisting package.
    Type: Grant
    Filed: September 30, 2022
    Date of Patent: January 2, 2024
    Assignee: Palo Alto Networks, Inc.
    Inventors: Ruian Duan, Daiping Liu, Jun Wang, Zihang Xiao
  • Publication number: 20230370492
    Abstract: Techniques for identifying and blocking domains used for NXNS-based distributed denial of service (DDos) attacks are disclosed. An analysis of DNS data is performed to identify a candidate attack domain associated with an NXNS attack. The candidate attack domain is confirmed as a confirmed attack domain based at least in part on a validation.
    Type: Application
    Filed: May 27, 2022
    Publication date: November 16, 2023
    Inventors: Ruian Duan, Daiping Liu
  • Publication number: 20230336524
    Abstract: Detection of algorithmically generated domains is disclosed. A DNS query is received. Markov Chain analysis is performed on a domain included in the received query. A determination of whether the received query implicates an algorithmically generated domain is made based at least in part on a result of the Markov Chain analysis.
    Type: Application
    Filed: June 21, 2023
    Publication date: October 19, 2023
    Inventors: Daiping Liu, Martin Walter, Ben Hua, Suquan Li, Fan Fei, Seokkyung Chung, Jun Wang, Wei Xu
  • Patent number: 11729134
    Abstract: Detection of algorithmically generated domains is disclosed. A DNS query is received. Markov Chain analysis is performed on a domain included in the received query. A determination of whether the received query implicates an algorithmically generated domain is made based at least in part on a result of the Markov Chain analysis.
    Type: Grant
    Filed: September 30, 2019
    Date of Patent: August 15, 2023
    Assignee: Palo Alto Networks, Inc.
    Inventors: Daiping Liu, Martin Walter, Ben Hua, Suquan Li, Fan Fei, Seokkyung Chung, Jun Wang, Wei Xu
  • Publication number: 20230188541
    Abstract: The present application discloses a method, system, and computer system for determining whether a registered domain is malicious. The method includes that a newly registered domain is registered, applying a malicious domain detector in connection with determining whether the newly registered domain is malicious, and in response to determining that the newly registered domain is malicious, sending to a security entity an indication that the newly registered domain is malicious.
    Type: Application
    Filed: December 14, 2021
    Publication date: June 15, 2023
    Inventors: Zhanhao Chen, Daiping Liu
  • Publication number: 20230130115
    Abstract: The present application discloses a method, system, and computer system for identifying dangling records. The method includes obtaining a set of domains, determining whether a record associated with a domain comprised in the set of domains is dangling, and in response to determining that the record associated with the domain is dangling, providing, to a registrant, a notification that the record is dangling.
    Type: Application
    Filed: October 26, 2021
    Publication date: April 27, 2023
    Inventors: Daiping Liu, Ruian Duan, Jun Wang
  • Publication number: 20230130232
    Abstract: The present application discloses a method, system, and computer system for predicting responses to DNS queries. The method includes receiving a DNS query comprising a subdomain portion and a root domain portion from a client device, determining whether to obtain target address information corresponding to the DNS from a predictive cache, in response to determining to obtain the target address information from the predictive cache, obtaining the target address information from the predictive cache, and providing the target address information to the client device.
    Type: Application
    Filed: October 26, 2021
    Publication date: April 27, 2023
    Inventors: Daiping Liu, Jun Wang, Wei Xu
  • Publication number: 20230057438
    Abstract: Detection of squatting domains is disclosed. A set of new fully qualified domain names (FQDNs) is received. The set of new FQDNs is analyzed to detect domain squatting by identifying a subset of the new FQDNs as candidate squatting domains. The candidate squatting domains are distributed to a security device/service.
    Type: Application
    Filed: August 20, 2021
    Publication date: February 23, 2023
    Inventors: Zhanhao Chen, Jun Wang, Daiping Liu
  • Publication number: 20220272109
    Abstract: Techniques for generating actionable indicators of compromise (IOCs) are disclosed. A set of potential sources for IOCs are received. One or more candidate IOCs are extracted from at least one source included in the set of potential sources. An actionable IOC is automatically identified from the one or more candidate IOCs. The actionable IOC is provided to a security enforcement service.
    Type: Application
    Filed: February 25, 2021
    Publication date: August 25, 2022
    Inventors: Janos Szurdi, Daiping Liu, Jun Wang
  • Publication number: 20210266293
    Abstract: Detection of DNS tunneling traffic is disclosed. A DNS query comprising a subdomain portion and a root domain portion is received from a client device. A determination is made that the root domain portion received in the DNS query is associated with a malicious DNS tunneling root domain. A remedial action is taken in response to the determining.
    Type: Application
    Filed: February 24, 2020
    Publication date: August 26, 2021
    Inventors: Daiping Liu, Jun Wang, Martin Walter, Fan Fei, Wei Xu
  • Publication number: 20210099414
    Abstract: Detection of algorithmically generated domains is disclosed. A DNS query is received. Markov Chain analysis is performed on a domain included in the received query. A determination of whether the received query implicates an algorithmically generated domain is made based at least in part on a result of the Markov Chain analysis.
    Type: Application
    Filed: September 30, 2019
    Publication date: April 1, 2021
    Inventors: Daiping Liu, Martin Walter, Ben Hua, Suquan Li, Fan Fei, Seokkyung Chung, Jun Wang, Wei Xu