Patents by Inventor Zhanhao Chen

Zhanhao Chen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260189577
    Abstract: Techniques for detecting and protecting claimable non-existent domains are disclosed. A system, process, and/or computer program product for detecting and protecting claimable non-existent domains includes monitoring network activity using a network security device, detecting that a session is querying a claimable non-existent domain using a domain name system (DNS) security service, and performing an action in response to the session querying the claimable non-existent domain.
    Type: Application
    Filed: February 18, 2026
    Publication date: July 2, 2026
    Inventors: Ruian Duan, Zhanhao Chen, Janos Szurdi, Daiping Liu
  • Publication number: 20260172447
    Abstract: The present application discloses a method, system, and computer system for detecting hijacked domains. The method includes (i) filtering a set of DNS records in real-time to filter out DNS records determined not to be associated with DNS hijacking and store an indication of a set of resultant filtered DNS records, (ii) detecting DNS hijacking records based at least in part on processing a batch of resultant filtered DNS records, and (iii) performing an active measure in response to detecting the DNS hijacking records. The set of resultant filtered DNS records are batched according to a predefined timeframe.
    Type: Application
    Filed: December 12, 2024
    Publication date: June 18, 2026
    Inventors: Janos Szurdi, Mohammad Ghasemisharif, Zhanhao Chen, Daiping Liu, Wanjin Li, Fan Fei
  • Publication number: 20260122080
    Abstract: One or more identifications of one or more newly observed domains are received. The one or more newly observed domains are store in a newly observed domain watch list for a specified watch interval. One or more automatic analyses are periodically performed to determine whether any newly observed domain stored in the newly observed domain watch list for the specified watch interval is determined to be suspicious or malicious.
    Type: Application
    Filed: October 30, 2024
    Publication date: April 30, 2026
    Inventors: Shu Wang, Zhanhao Chen, Ruian Duan, Daiping Liu
  • Publication number: 20260122086
    Abstract: Network traffic associated with a domain name server (DNS) resolver is collected. Network traffic is simulated using a plurality of sandboxed DNS resolvers. A DNS-related attack on the DNS resolver is detected based on the corresponding outputs associated with the plurality of different sandboxed DNS resolvers.
    Type: Application
    Filed: October 31, 2024
    Publication date: April 30, 2026
    Inventors: Zhanhao Chen, Daiping Liu, Fan Fei
  • Patent number: 12592941
    Abstract: Domain Name System (DNS) security using process information is provided. An application accessing an internet service using a domain name is determined. Process information associated with the application along with an associated DNS query to identify an IP address associated with the domain name are identified. The process information and the associated DNS query to a DNS security service are sent. An action based on a response from the DNS security service is performed.
    Type: Grant
    Filed: June 5, 2024
    Date of Patent: March 31, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Zihang Xiao, Zhanhao Chen
  • Publication number: 20260085619
    Abstract: A variable geometry turbine device includes: a turbine casing provided with an inlet duct, and defining an exhaust port and a bypass chamber therein; a gear rotating sleeve disposed inside the bypass chamber; a rack actuator; combined nozzle guide vanes including: a fixed nozzle and an elastic nozzle mechanism; and a turbine. A first annular chamber and a second annular chamber are defined between the exhaust port and the bypass chamber. A first radial channel and a second radial channel are defined under the bypass chamber, and are connected to the first annular chamber and the second annular chamber respectively. A side of the gear rotating sleeve defines a first notch and a second notch configured to be selectively connected to the first radial channel and the second radial channel respectively; and opening and closing of the first radial channel and the second radial channel have a time difference.
    Type: Application
    Filed: May 24, 2025
    Publication date: March 26, 2026
    Inventors: Quan LIU, Chao MA, Jianjun HUANG, Xinyuan XIONG, Zhanhao CHEN, Quan WANG, Yangli SUN
  • Publication number: 20260081936
    Abstract: A signature generator has been designed that can create a malicious campaign signature with substantial coverage of malicious campaign behavior without impeding benign traffic. The malicious campaign signature generator uses data of multiple, known malicious campaigns to identify abused, benign network entities. The signature generator builds a graph data structure for each malicious campaign that represents the abused network entities. The relationships encoded in the graph data structure indicate the use of the combination of abused network entities in the campaign. The signature generator aggregates the graph data structures and identifies a combination of the benign network entities that were highly abused across the multiple malicious campaigns with respect to all of the abused network entities represented in the graph data structures. A signature is then created from the identifiers of this combination of highly abused network entities.
    Type: Application
    Filed: November 20, 2025
    Publication date: March 19, 2026
    Inventors: Zhanhao Chen, Chao Lei, Chien-Hua Lu, Daiping Liu
  • Patent number: 12580927
    Abstract: Techniques for detecting and protecting claimable non-existent domains are disclosed. A system, process, and/or computer program product for detecting and protecting claimable non-existent domains includes monitoring network activity using a network security device, detecting that a session is querying a claimable non-existent domain using a domain name system (DNS) security service, and performing an action in response to the session querying the claimable non-existent domain.
    Type: Grant
    Filed: July 31, 2023
    Date of Patent: March 17, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Ruian Duan, Zhanhao Chen, Janos Szurdi, Daiping Liu
  • Publication number: 20260067317
    Abstract: A DNS security service evaluates detected DNS requests to determine if the DNS requests should be forwarded to their destination. For DNS requests permitted to be forwarded to their destination, the service determines from the corresponding DNS response if the resource record (RR) included therein is known benign. If the RR is not known benign, the service determines a best RR that is known benign by performing one or more lookups in a resource record history. If a known benign RR is identified as a result of the lookup(s), the service incorporates data from the known RR into a new RR included in a DNS response that is forwarded to the client. For DNS requests that are not permitted to be forwarded to their destination, the service determines data of a known benign RR to return to the client in a constructed DNS response without forwarding the DNS request to its destination to obtain a DNS response.
    Type: Application
    Filed: August 30, 2024
    Publication date: March 5, 2026
    Inventors: Janos Szurdi, Daiping Liu, Zhanhao Chen, Ruian Duan, Mohammad Ghasemisharif
  • Publication number: 20260056104
    Abstract: An accelerated wear device for a ceramic tile and a wear test method thereof. The accelerated wear device includes an X-axis drive mechanism; a Z-axis drive mechanism, disposed on the X-axis drive mechanism; a rotary friction mechanism, disposed on the Z-axis drive mechanism; and an abrasive tool seat, disposed on the rotary friction mechanism, where the abrasive tool seat is used for mounting a wearing part, and drives the wearing part to perform a friction motion with a to-be-tested ceramic tile under the drive of the X-axis drive mechanism, the Z-axis drive mechanism and the rotary friction mechanism.
    Type: Application
    Filed: October 30, 2024
    Publication date: February 26, 2026
    Applicants: DONGGUAN CITY WONDERFUL CERAMICS INDUSTRIAL PARK CO., LTD., MARCOPOLO HOLDINGS CO., LTD.
    Inventors: Zhanhao CHEN, Zhengqiang SHENG, Jiaqi HUANG, Zhanwen GU, Kehui LIN, Yongqiang WANG, Zhongmin LI, Xuebin LIU, Duanxu CAO, Daocong HUANG, Hanling YANG
  • Publication number: 20260056103
    Abstract: A test method for anti-slip long effectiveness of an anti-slip ceramic tile. The test method includes: performing a wear test on a testing surface of a to-be-tested anti-slip ceramic tile; performing an anti-slip performance test on the worn testing surface, to obtain a wear test value; and determining an anti-slip long effectiveness grade of the to-be-tested anti-slip ceramic tile according to the wear test value. In the embodiments, the worn to-be-tested anti-slip ceramic tile is subjected to the anti-slip performance test, to obtain the anti-slip long effectiveness grade, thus explaining the performance of the worn anti-slip ceramic tile, which is conductive to determining the long effectiveness anti-slip performance of the anti-slip ceramic tile, and provides the long effectiveness anti-slip performance test method and determination basis for the manufacturing of the anti-slip ceramic tile.
    Type: Application
    Filed: October 30, 2024
    Publication date: February 26, 2026
    Applicants: DONGGUAN CITY WONDERFUL CERAMICS INDUSTRIAL PARK CO., LTD., MARCOPOLO HOLDINGS CO., LTD.
    Inventors: Zhengqiang SHENG, Jiaqi HUANG, Zhanwen GU, Kehui LIN, Yuezeng XIE, Duanxu CAO, Yongqiang WANG, Zhanhao CHEN, Xuebin LIU, Daocong HUANG, Zhiyong OU, Hanling YANG
  • Publication number: 20260039681
    Abstract: The present application discloses a method, system, and computer system for detecting DNS hijacking records. The method includes (i) obtaining passive DNS (pDNS) data pertaining to a set of resource records, (ii) extracting a first set of features based at least in part on the pDNS data for a selected resource record, wherein the selected resource record is selected from the set of resource records, (iii) using a classifier to determine whether a candidate record corresponding to the selected resource record is a result of a DNS hijacking based at least in part on the first set of features, and (iv) performing an active measure in response to determining that the candidate record is the result of the DNS hijacking.
    Type: Application
    Filed: May 30, 2025
    Publication date: February 5, 2026
    Inventors: Janos Szurdi, Mohammad Ghasemisharif, Daiping Liu, Zhanhao Chen, Rebekah Houser, Fan Fei, Arun Bala Kumar, Yu-Hsiang Kao
  • Patent number: 12500903
    Abstract: A signature generator has been designed that can create a malicious campaign signature with substantial coverage of malicious campaign behavior without impeding benign traffic. The malicious campaign signature generator uses data of multiple, known malicious campaigns to identify abused, benign network entities. The signature generator builds a graph data structure for each malicious campaign that represents the abused network entities. The relationships encoded in the graph data structure indicate the use of the combination of abused network entities in the campaign. The signature generator aggregates the graph data structures and identifies a combination of the benign network entities that were highly abused across the multiple malicious campaigns with respect to all of the abused network entities represented in the graph data structures. A signature is then created from the identifiers of this combination of highly abused network entities.
    Type: Grant
    Filed: January 30, 2024
    Date of Patent: December 16, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Zhanhao Chen, Chao Lei, Chien-Hua Lu, Daiping Liu
  • Publication number: 20250343814
    Abstract: Detection of strategically aged domains is detected. A set of initially benign aged dormant domains is determined as a list of candidate strategically aged domains. The list of candidate strategically aged domains is monitored for a change by a particular domain from a dormant domain status to an active status. In response to determining the change to active status of the particular domain, an action is taken with respect to the aged dormant domain.
    Type: Application
    Filed: May 30, 2025
    Publication date: November 6, 2025
    Inventors: Zhanhao Chen, Daiping Liu, Wanjin Li, Fan Fei
  • Patent number: 12432224
    Abstract: The present application discloses a method, system, and computer system for determining whether a registered domain is malicious. The method includes that a newly registered domain is registered, applying a malicious domain detector in connection with determining whether the newly registered domain is malicious, and in response to determining that the newly registered domain is malicious, sending to a security entity an indication that the newly registered domain is malicious.
    Type: Grant
    Filed: December 14, 2021
    Date of Patent: September 30, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Zhanhao Chen, Daiping Liu
  • Publication number: 20250247403
    Abstract: A signature generator has been designed that can create a malicious campaign signature with substantial coverage of malicious campaign behavior without impeding benign traffic. The malicious campaign signature generator uses data of multiple, known malicious campaigns to identify abused, benign network entities. The signature generator builds a graph data structure for each malicious campaign that represents the abused network entities. The relationships encoded in the graph data structure indicate the use of the combination of abused network entities in the campaign. The signature generator aggregates the graph data structures and identifies a combination of the benign network entities that were highly abused across the multiple malicious campaigns with respect to all of the abused network entities represented in the graph data structures. A signature is then created from the identifiers of this combination of highly abused network entities.
    Type: Application
    Filed: January 30, 2024
    Publication date: July 31, 2025
    Inventors: Zhanhao Chen, Chao Lei, Chien-Hua Lu, Daiping Liu
  • Patent number: 12355792
    Abstract: Detection of strategically aged domains is detected. A list of aged dormant domains is determined, including by evaluating passive Domain Name System (DNS) information. The list of aged dormant domains is monitored for a change by an aged dormant domain from a dormant domain status to an active status. In response to determining the change to active status of the aged dormant domain, an action is taken with respect to the aged dormant domain.
    Type: Grant
    Filed: November 30, 2022
    Date of Patent: July 8, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Zhanhao Chen, Daiping Liu, Wanjin Li, Fan Fei
  • Patent number: 12348563
    Abstract: Detection of squatting domains is disclosed. A set of new fully qualified domain names (FQDNs) is received. The set of new FQDNs is analyzed to detect domain squatting by identifying a subset of the new FQDNs as candidate squatting domains. The candidate squatting domains are distributed to a security device/service.
    Type: Grant
    Filed: March 19, 2024
    Date of Patent: July 1, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Zhanhao Chen, Jun Wang, Daiping Liu
  • Publication number: 20250071095
    Abstract: Automatic generation of network signatures is disclosed. Network profiles for malware samples are generated. Network signature candidates are selected based on the network profiles. The network signature candidates are automatically evaluated to automatically generate a new set of network signatures. The new set of network signatures is distributed to a security device/service to enforce the new set of network signatures to detect malware.
    Type: Application
    Filed: November 14, 2024
    Publication date: February 27, 2025
    Inventors: Zhanhao Chen, Jun Wang, Wei Xu
  • Publication number: 20250047687
    Abstract: Techniques for detecting and protecting claimable non-existent domains are disclosed. A system, process, and/or computer program product for detecting and protecting claimable non-existent domains includes monitoring network activity using a network security device, detecting that a session is querying a claimable non-existent domain using a domain name system (DNS) security service, and performing an action in response to the session querying the claimable non-existent domain.
    Type: Application
    Filed: July 31, 2023
    Publication date: February 6, 2025
    Inventors: Ruian Duan, Zhanhao Chen, Janos Szurdi, Daiping Liu