Domain name system (dns) based anomaly detection

US2016359887A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016359887-A1
Application numberUS-201615097236-A
CountryUS
Kind codeA1
Filing dateApr 12, 2016
Priority dateJun 4, 2015
Publication dateDec 8, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In one embodiment, a method includes receiving at an analytics module operating at a network device, network traffic data collected from a plurality of sensors distributed throughout a network and installed in network components to obtain the network traffic data, identifying at the analytics module, Domain Name System (DNS) exchanges within the network, associating at the analytics module, the DNS exchanges with process, user, and host information, and identifying at the analytics module, anomalies in the DNS exchanges. An apparatus and logic are also disclosed herein.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: receiving at an analytics module operating at a network device, network traffic data collected from a plurality of sensors distributed throughout a network and installed in network components to obtain the network traffic data; identifying at the analytics module, Domain Name System (DNS) exchanges within the network; associating at the analytics module, said DNS exchanges with process, user, and host information; and identifying at the analytics module, anomalies in said DNS exchanges. 2 . The method of claim 1 wherein the network traffic data is collected from packets transmitted to and from the network components to monitor network flows at hosts and within the network from multiple perspectives in the network. 3 . The method of claim 1 wherein identifying said anomalies comprises calculating scores for said DNS exchanges to identify said anomalies. 4 . The method of claim 1 wherein identifying said anomalies comprises identifying TTL (Time to Live) inconsistencies within said DNS exchanges. 5 . The method of claim 1 wherein identifying said anomalies comprises identifying network inconsistencies within said DNS exchanges. 6 . The method of claim 1 further comprising performing a second level domain check and wherein said anomalies are identified based on said second level domain check. 7 . The method of claim 1 wherein identifying said anomalies comprises detecting a Domain Generation Algorithm (DGA). 8 . The method of claim 1 wherein identifying said anomalies comprises detecting domain fluxing. 9 . The method of claim 1 wherein identifying said anomalies comprises identifying use of DNS tunnels to carry data. 10 . The method of claim 1 wherein identifying said anomalies comprises utilizing cross correlation between host and network views of the network traffic data. 11 . The method of claim 1 wherein identifying said DNS exchanges further comprises discovering applications in the network. 12 . The method of claim 1 further comprising generating application specific features for SSH (Secure Shell) traffic using machine learning. 13 . The method of claim 1 further comprising identifying SSH (Secure Shell) traffic using packet snooping. 14 . The method of claim 1 wherein the network traffic data is received from at least one network device comprising multiple sensors. 15 . An apparatus comprising: an interface for receiving network traffic data collected from a plurality of sensors distributed throughout a network and installed in network components to obtain the network traffic data; and a processor for identifying Domain Name System (DNS) exchanges within the network, associating said DNS exchanges with process, user, and host information, and identifying anomalies in said DNS exchanges. 16 . The apparatus of claim 15 wherein the network traffic data comprises data collected from a network device comprising multiple sensors. 17 . The apparatus of claim 15 wherein identifying said anomalies comprises identifying use of DNS tunnels to carry data. 18 . Logic encoded on one or more non-transitory computer readable media for execution and when executed operable to: process at an analytics module operating at a network device, network traffic data collected from a plurality of sensors distributed throughout a network and installed in network components to obtain the network traffic data; identify at the analytics module, Domain Name System (DNS) exchanges within the network; associate at the analytics module, said DNS exchanges with process, user, and host information; and identify at the analytics module, anomalies in said DNS exchanges. 19 . The logic of claim 18 wherein identifying said anomalies comprises identifying use of DNS tunnels to carry data. 20 . The logic of claim 18 further operable to generate application specific features for DNS traffic using machine learning.

Assignees

Inventors

Classifications

  • Electricity · mapped topic

  • Domain name generation or assignment · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • using domain name system [DNS] · CPC title

  • between local and global IP addresses · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016359887A1 cover?
In one embodiment, a method includes receiving at an analytics module operating at a network device, network traffic data collected from a plurality of sensors distributed throughout a network and installed in network components to obtain the network traffic data, identifying at the analytics module, Domain Name System (DNS) exchanges within the network, associating at the analytics module, the…
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Dec 08 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).