Systems and methods to detect and monitor dns tunneling
US-2019058718-A1 · Feb 21, 2019 · US
US2018255083A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2018255083-A1 |
| Application number | US-201515754282-A |
| Country | US |
| Kind code | A1 |
| Filing date | Sep 21, 2015 |
| Priority date | Sep 21, 2015 |
| Publication date | Sep 6, 2018 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Examples determine a number of hosts, within an enterprise, which are resolving a particular domain. Based on the number of hosts within the enterprise resolving the particular domain, the examples identify whether the particular domain is benign.
Opening claim text (preview).
We claim: 1 . A method, executable by a computing device, the method comprising: determining a number of hosts, within an enterprise, resolving a particular domain; and identifying whether the particular domain is benign based on the number of hosts resolving the particular domain. 2 . The method of claim 1 wherein identifying whether the particular domain is benign based on the number of hosts resolving the particular domain comprises: determining a number of resolutions corresponding to the particular domain; and in response to the identified number of hosts and the identified number of resolutions, identifying whether the particular domain is benign. 3 . The method of claim 2 wherein a higher number of resolutions indicates the particular domain is benign. 4 . The method of claim 2 wherein determining the number of resolutions corresponding to the particular domain comprises: determining an aggregate number of domain name system (DNS) packets resolving the particular domain over a period of time. 5 . The method of claim 1 wherein identifying whether the particular domain is benign based the number of hosts resolving the particular domain comprises: identifying the domain as benign if the number of hosts resolving the particular domain is above a threshold; and identifying the domain as malicious if the number of hosts resolving the particular domain is below the threshold. 6 . The method of claim 1 comprising: discarding a domain name system (DNS) log associated with the particular domain in response to the identification of the particular domain as benign. 7 . The method of claim 1 comprising: in response to the identification the particular domain as benign, incorporating the particular domain name into a whitelist. 8 . A non-transitory machine-readable storage medium comprising instructions that when executed by a processing resource cause a computing device to: determine a number of hosts resolving a particular domain; determine a number of resolutions corresponding to the particular domain; and identify whether the particular domain is benign based on the number of hosts and the number of resolutions. 9 . The non-transitory machine-readable medium of claim 8 wherein to determine the number of resolutions corresponding to the particular domain comprises instructions that when executed by the processing resource causes the computing device to: determine an aggregate number of domain name system (DNS) packets resolving the particular domain over a period of time. 10 . The non-transitory machine-readable storage medium of claim 8 comprising instructions that when executed by the processing resource cause the computing device to: discard DNS traffic log in response to the identification the particular domain is benign; and incorporate the particular domain into a whitelist. 11 . The non-transitory machine-readable medium of claim 8 wherein to identify whether the particular domain is benign based on the number of hosts and the number of resolutions comprises instructions that when executed by the processing resource causes the computing device to: identify the particular domain as benign if the number of hosts and the number of resolutions are each above a threshold; and identify the domain as malicious if the number of hosts or the number of resolutions are below the threshold. 12 . The non-transitory machine-readable medium of claim 8 a higher number of hosts and a higher number of resolutions indicates the particular domain is benign. 13 . A networking system comprising: an appliance to: process domain name system (DNS) traffic between a DNS server and hosts; determine a number of hosts, within an enterprise, resolving a particular domain; and determine a number of resolutions corresponding to the particular domain; and identify whether the particular domain is benign based on the number of hosts and the number of resolutions. 14 . The system of claim 13 further comprising: a domain name system (DNS) server to exchange DNS traffic with the number of hosts. 15 . The system of claim 13 wherein to identify whether the particular domain is benign, the appliance is to: identify the particular domain as benign if the number of hosts and the number of resolutions are above a threshold; and identify the particular domain as malicious if the number of hosts or the number of resolutions are below the threshold.
Traffic logging, e.g. anomaly detection · CPC title
Electricity · mapped topic
Filtering by address, protocol, port number or service, e.g. IP-address or URL · CPC title
Name registration, generation or assignment · CPC title
Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.