首页> 外国专利> DNS MISUSE DETECTION THROUGH ATTRIBUTE CARDINALITY TRACKING

DNS MISUSE DETECTION THROUGH ATTRIBUTE CARDINALITY TRACKING

机译:通过属性基数跟踪进行DNS滥用检测

摘要

A system and computer-implemented method to detect particular Domain Name System (DNS) misuse, wherein the method includes obtaining monitored network data. The monitored network data includes respective instances of request traffic. The request traffic is associated with DNS requests that request resolution of a name that belongs to at least one identified domain. Each DNS request is sent from a source address of one or more stub resolver; the source address of the stub resolver may be spoofed. Each instance of request traffic includes the source address, the name for which DNS resolution is requested to be resolved, and the at least one identified domain associated with a corresponding DNS request. The method further includes tracking over time, using a probabilistic algorithm, an approximation of a first cardinality of names belonging to a selected domain of the at least one identified domain included in the instances of request traffic. The method further includes tracking over time, using the probabilistic algorithm, an approximation of a second cardinality of source addresses associated with the selected domain included in the instances of request traffic. The method further includes detecting a combination of a first condition of the approximation of the first cardinality and the second condition of the approximation of the second cardinality, wherein the combination of the first and second conditions indicates the occurrence of a specific DNS misuse. The method further includes performing an action to at least one of output a notification of and correct a condition associated with the detected occurrence of the specific DNS misuse.
机译:一种检测特定域名系统(DNS)滥用的系统和计算机实现的方法,其中,该方法包括获取监视的网络数据。监视的网络数据包括请求流量的各个实例。该请求业务与DNS请求相关联,DNS请求请求解析至少属于一个识别的域的名称。每个DNS请求都是从一个或多个存根解析器的源地址发送的;存根解析器的源地址可能是欺骗性的。请求流量的每个实例包括源地址,请求解析DNS解析的名称以及与相应DNS请求关联的至少一个已标识域。该方法还包括使用概率算法随时间跟踪属于请求流量实例中包括的至少一个识别域的所选域的名称的第一基数的近似值。该方法还包括使用概率算法随时间跟踪与请求流量实例中包括的与所选域相关联的源地址的第二基数的近似值。该方法还包括检测第一基数的近似的第一条件和第二基数的近似的第二条件的组合,其中第一和第二条件的组合指示特定DNS滥用的发生。该方法还包括执行动作以输出与检测到的特定DNS滥用的发生相关联的条件的通知和校正中的至少一项。

著录项

  • 公开/公告号US2020014714A1

    专利类型

  • 公开/公告日2020-01-09

    原文格式PDF

  • 申请/专利权人 ARBOR NETWORKS INC.;

    申请/专利号US201816030733

  • 发明设计人 ANDREW DAVID MORTENSEN;ALAN SAQUI;

    申请日2018-07-09

  • 分类号H04L29/06;H04L29/12;H04L12/26;

  • 国家 US

  • 入库时间 2022-08-21 11:18:39

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号