Patents by Inventor Zhanhao Chen
Zhanhao Chen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260189577Abstract: Techniques for detecting and protecting claimable non-existent domains are disclosed. A system, process, and/or computer program product for detecting and protecting claimable non-existent domains includes monitoring network activity using a network security device, detecting that a session is querying a claimable non-existent domain using a domain name system (DNS) security service, and performing an action in response to the session querying the claimable non-existent domain.Type: ApplicationFiled: February 18, 2026Publication date: July 2, 2026Inventors: Ruian Duan, Zhanhao Chen, Janos Szurdi, Daiping Liu
-
Publication number: 20260172447Abstract: The present application discloses a method, system, and computer system for detecting hijacked domains. The method includes (i) filtering a set of DNS records in real-time to filter out DNS records determined not to be associated with DNS hijacking and store an indication of a set of resultant filtered DNS records, (ii) detecting DNS hijacking records based at least in part on processing a batch of resultant filtered DNS records, and (iii) performing an active measure in response to detecting the DNS hijacking records. The set of resultant filtered DNS records are batched according to a predefined timeframe.Type: ApplicationFiled: December 12, 2024Publication date: June 18, 2026Inventors: Janos Szurdi, Mohammad Ghasemisharif, Zhanhao Chen, Daiping Liu, Wanjin Li, Fan Fei
-
Publication number: 20260122080Abstract: One or more identifications of one or more newly observed domains are received. The one or more newly observed domains are store in a newly observed domain watch list for a specified watch interval. One or more automatic analyses are periodically performed to determine whether any newly observed domain stored in the newly observed domain watch list for the specified watch interval is determined to be suspicious or malicious.Type: ApplicationFiled: October 30, 2024Publication date: April 30, 2026Inventors: Shu Wang, Zhanhao Chen, Ruian Duan, Daiping Liu
-
Publication number: 20260122086Abstract: Network traffic associated with a domain name server (DNS) resolver is collected. Network traffic is simulated using a plurality of sandboxed DNS resolvers. A DNS-related attack on the DNS resolver is detected based on the corresponding outputs associated with the plurality of different sandboxed DNS resolvers.Type: ApplicationFiled: October 31, 2024Publication date: April 30, 2026Inventors: Zhanhao Chen, Daiping Liu, Fan Fei
-
Patent number: 12592941Abstract: Domain Name System (DNS) security using process information is provided. An application accessing an internet service using a domain name is determined. Process information associated with the application along with an associated DNS query to identify an IP address associated with the domain name are identified. The process information and the associated DNS query to a DNS security service are sent. An action based on a response from the DNS security service is performed.Type: GrantFiled: June 5, 2024Date of Patent: March 31, 2026Assignee: Palo Alto Networks, Inc.Inventors: Zihang Xiao, Zhanhao Chen
-
Publication number: 20260085619Abstract: A variable geometry turbine device includes: a turbine casing provided with an inlet duct, and defining an exhaust port and a bypass chamber therein; a gear rotating sleeve disposed inside the bypass chamber; a rack actuator; combined nozzle guide vanes including: a fixed nozzle and an elastic nozzle mechanism; and a turbine. A first annular chamber and a second annular chamber are defined between the exhaust port and the bypass chamber. A first radial channel and a second radial channel are defined under the bypass chamber, and are connected to the first annular chamber and the second annular chamber respectively. A side of the gear rotating sleeve defines a first notch and a second notch configured to be selectively connected to the first radial channel and the second radial channel respectively; and opening and closing of the first radial channel and the second radial channel have a time difference.Type: ApplicationFiled: May 24, 2025Publication date: March 26, 2026Inventors: Quan LIU, Chao MA, Jianjun HUANG, Xinyuan XIONG, Zhanhao CHEN, Quan WANG, Yangli SUN
-
Publication number: 20260081936Abstract: A signature generator has been designed that can create a malicious campaign signature with substantial coverage of malicious campaign behavior without impeding benign traffic. The malicious campaign signature generator uses data of multiple, known malicious campaigns to identify abused, benign network entities. The signature generator builds a graph data structure for each malicious campaign that represents the abused network entities. The relationships encoded in the graph data structure indicate the use of the combination of abused network entities in the campaign. The signature generator aggregates the graph data structures and identifies a combination of the benign network entities that were highly abused across the multiple malicious campaigns with respect to all of the abused network entities represented in the graph data structures. A signature is then created from the identifiers of this combination of highly abused network entities.Type: ApplicationFiled: November 20, 2025Publication date: March 19, 2026Inventors: Zhanhao Chen, Chao Lei, Chien-Hua Lu, Daiping Liu
-
Patent number: 12580927Abstract: Techniques for detecting and protecting claimable non-existent domains are disclosed. A system, process, and/or computer program product for detecting and protecting claimable non-existent domains includes monitoring network activity using a network security device, detecting that a session is querying a claimable non-existent domain using a domain name system (DNS) security service, and performing an action in response to the session querying the claimable non-existent domain.Type: GrantFiled: July 31, 2023Date of Patent: March 17, 2026Assignee: Palo Alto Networks, Inc.Inventors: Ruian Duan, Zhanhao Chen, Janos Szurdi, Daiping Liu
-
Publication number: 20260067317Abstract: A DNS security service evaluates detected DNS requests to determine if the DNS requests should be forwarded to their destination. For DNS requests permitted to be forwarded to their destination, the service determines from the corresponding DNS response if the resource record (RR) included therein is known benign. If the RR is not known benign, the service determines a best RR that is known benign by performing one or more lookups in a resource record history. If a known benign RR is identified as a result of the lookup(s), the service incorporates data from the known RR into a new RR included in a DNS response that is forwarded to the client. For DNS requests that are not permitted to be forwarded to their destination, the service determines data of a known benign RR to return to the client in a constructed DNS response without forwarding the DNS request to its destination to obtain a DNS response.Type: ApplicationFiled: August 30, 2024Publication date: March 5, 2026Inventors: Janos Szurdi, Daiping Liu, Zhanhao Chen, Ruian Duan, Mohammad Ghasemisharif
-
Publication number: 20260056104Abstract: An accelerated wear device for a ceramic tile and a wear test method thereof. The accelerated wear device includes an X-axis drive mechanism; a Z-axis drive mechanism, disposed on the X-axis drive mechanism; a rotary friction mechanism, disposed on the Z-axis drive mechanism; and an abrasive tool seat, disposed on the rotary friction mechanism, where the abrasive tool seat is used for mounting a wearing part, and drives the wearing part to perform a friction motion with a to-be-tested ceramic tile under the drive of the X-axis drive mechanism, the Z-axis drive mechanism and the rotary friction mechanism.Type: ApplicationFiled: October 30, 2024Publication date: February 26, 2026Applicants: DONGGUAN CITY WONDERFUL CERAMICS INDUSTRIAL PARK CO., LTD., MARCOPOLO HOLDINGS CO., LTD.Inventors: Zhanhao CHEN, Zhengqiang SHENG, Jiaqi HUANG, Zhanwen GU, Kehui LIN, Yongqiang WANG, Zhongmin LI, Xuebin LIU, Duanxu CAO, Daocong HUANG, Hanling YANG
-
Publication number: 20260056103Abstract: A test method for anti-slip long effectiveness of an anti-slip ceramic tile. The test method includes: performing a wear test on a testing surface of a to-be-tested anti-slip ceramic tile; performing an anti-slip performance test on the worn testing surface, to obtain a wear test value; and determining an anti-slip long effectiveness grade of the to-be-tested anti-slip ceramic tile according to the wear test value. In the embodiments, the worn to-be-tested anti-slip ceramic tile is subjected to the anti-slip performance test, to obtain the anti-slip long effectiveness grade, thus explaining the performance of the worn anti-slip ceramic tile, which is conductive to determining the long effectiveness anti-slip performance of the anti-slip ceramic tile, and provides the long effectiveness anti-slip performance test method and determination basis for the manufacturing of the anti-slip ceramic tile.Type: ApplicationFiled: October 30, 2024Publication date: February 26, 2026Applicants: DONGGUAN CITY WONDERFUL CERAMICS INDUSTRIAL PARK CO., LTD., MARCOPOLO HOLDINGS CO., LTD.Inventors: Zhengqiang SHENG, Jiaqi HUANG, Zhanwen GU, Kehui LIN, Yuezeng XIE, Duanxu CAO, Yongqiang WANG, Zhanhao CHEN, Xuebin LIU, Daocong HUANG, Zhiyong OU, Hanling YANG
-
Publication number: 20260039681Abstract: The present application discloses a method, system, and computer system for detecting DNS hijacking records. The method includes (i) obtaining passive DNS (pDNS) data pertaining to a set of resource records, (ii) extracting a first set of features based at least in part on the pDNS data for a selected resource record, wherein the selected resource record is selected from the set of resource records, (iii) using a classifier to determine whether a candidate record corresponding to the selected resource record is a result of a DNS hijacking based at least in part on the first set of features, and (iv) performing an active measure in response to determining that the candidate record is the result of the DNS hijacking.Type: ApplicationFiled: May 30, 2025Publication date: February 5, 2026Inventors: Janos Szurdi, Mohammad Ghasemisharif, Daiping Liu, Zhanhao Chen, Rebekah Houser, Fan Fei, Arun Bala Kumar, Yu-Hsiang Kao
-
Patent number: 12500903Abstract: A signature generator has been designed that can create a malicious campaign signature with substantial coverage of malicious campaign behavior without impeding benign traffic. The malicious campaign signature generator uses data of multiple, known malicious campaigns to identify abused, benign network entities. The signature generator builds a graph data structure for each malicious campaign that represents the abused network entities. The relationships encoded in the graph data structure indicate the use of the combination of abused network entities in the campaign. The signature generator aggregates the graph data structures and identifies a combination of the benign network entities that were highly abused across the multiple malicious campaigns with respect to all of the abused network entities represented in the graph data structures. A signature is then created from the identifiers of this combination of highly abused network entities.Type: GrantFiled: January 30, 2024Date of Patent: December 16, 2025Assignee: Palo Alto Networks, Inc.Inventors: Zhanhao Chen, Chao Lei, Chien-Hua Lu, Daiping Liu
-
Publication number: 20250343814Abstract: Detection of strategically aged domains is detected. A set of initially benign aged dormant domains is determined as a list of candidate strategically aged domains. The list of candidate strategically aged domains is monitored for a change by a particular domain from a dormant domain status to an active status. In response to determining the change to active status of the particular domain, an action is taken with respect to the aged dormant domain.Type: ApplicationFiled: May 30, 2025Publication date: November 6, 2025Inventors: Zhanhao Chen, Daiping Liu, Wanjin Li, Fan Fei
-
Patent number: 12432224Abstract: The present application discloses a method, system, and computer system for determining whether a registered domain is malicious. The method includes that a newly registered domain is registered, applying a malicious domain detector in connection with determining whether the newly registered domain is malicious, and in response to determining that the newly registered domain is malicious, sending to a security entity an indication that the newly registered domain is malicious.Type: GrantFiled: December 14, 2021Date of Patent: September 30, 2025Assignee: Palo Alto Networks, Inc.Inventors: Zhanhao Chen, Daiping Liu
-
Publication number: 20250247403Abstract: A signature generator has been designed that can create a malicious campaign signature with substantial coverage of malicious campaign behavior without impeding benign traffic. The malicious campaign signature generator uses data of multiple, known malicious campaigns to identify abused, benign network entities. The signature generator builds a graph data structure for each malicious campaign that represents the abused network entities. The relationships encoded in the graph data structure indicate the use of the combination of abused network entities in the campaign. The signature generator aggregates the graph data structures and identifies a combination of the benign network entities that were highly abused across the multiple malicious campaigns with respect to all of the abused network entities represented in the graph data structures. A signature is then created from the identifiers of this combination of highly abused network entities.Type: ApplicationFiled: January 30, 2024Publication date: July 31, 2025Inventors: Zhanhao Chen, Chao Lei, Chien-Hua Lu, Daiping Liu
-
Patent number: 12355792Abstract: Detection of strategically aged domains is detected. A list of aged dormant domains is determined, including by evaluating passive Domain Name System (DNS) information. The list of aged dormant domains is monitored for a change by an aged dormant domain from a dormant domain status to an active status. In response to determining the change to active status of the aged dormant domain, an action is taken with respect to the aged dormant domain.Type: GrantFiled: November 30, 2022Date of Patent: July 8, 2025Assignee: Palo Alto Networks, Inc.Inventors: Zhanhao Chen, Daiping Liu, Wanjin Li, Fan Fei
-
Patent number: 12348563Abstract: Detection of squatting domains is disclosed. A set of new fully qualified domain names (FQDNs) is received. The set of new FQDNs is analyzed to detect domain squatting by identifying a subset of the new FQDNs as candidate squatting domains. The candidate squatting domains are distributed to a security device/service.Type: GrantFiled: March 19, 2024Date of Patent: July 1, 2025Assignee: Palo Alto Networks, Inc.Inventors: Zhanhao Chen, Jun Wang, Daiping Liu
-
Publication number: 20250071095Abstract: Automatic generation of network signatures is disclosed. Network profiles for malware samples are generated. Network signature candidates are selected based on the network profiles. The network signature candidates are automatically evaluated to automatically generate a new set of network signatures. The new set of network signatures is distributed to a security device/service to enforce the new set of network signatures to detect malware.Type: ApplicationFiled: November 14, 2024Publication date: February 27, 2025Inventors: Zhanhao Chen, Jun Wang, Wei Xu
-
Publication number: 20250047687Abstract: Techniques for detecting and protecting claimable non-existent domains are disclosed. A system, process, and/or computer program product for detecting and protecting claimable non-existent domains includes monitoring network activity using a network security device, detecting that a session is querying a claimable non-existent domain using a domain name system (DNS) security service, and performing an action in response to the session querying the claimable non-existent domain.Type: ApplicationFiled: July 31, 2023Publication date: February 6, 2025Inventors: Ruian Duan, Zhanhao Chen, Janos Szurdi, Daiping Liu