首页> 外国专利> Systems and methods for identifying malicious domain names from a passive domain name system server log

Systems and methods for identifying malicious domain names from a passive domain name system server log

机译:从无源域名系统服务器日志中识别恶意域名的系统和方法

摘要

Disclosed computer-implemented methods for identifying malicious domain names from a passive domain name system server log (DNS log) may include, in some examples, (1) creating a pool of domain names from the DNS log, (2) identifying respective features of each name in the pool, (3) preparing a list of known benign names and respective features of each known benign name, (4) preparing a list of known malicious names and features of each known malicious name, (5) computing a classification model based on (A) the features of each benign name on the list of benign names and (B) the features of each malicious name on the list of malicious names, (6) identifying respective features of an unclassified domain name, and (7) classifying, using the classification model, the unclassified domain name as malicious, based on the respective features of the unclassified domain name. Various other methods, systems, and computer-readable media are also disclosed.
机译:所公开了用于从无源域名系统服务器日志(DNS日志)识别恶意域名的计算机实现的方法可以包括在一些示例中(1)从DNS日志创建域名的池(2)识别各个特征池中的每个名称,(3)准备每个已知良性名称的已知良性名称和各个功能列表(4)准备每个已知恶意名称的已知恶意名称和特征列表(5)计算分类模型基于(a)良性名称列表中的每个良性名称的功能和(b)恶意名单列表中每个恶意名称的功能,(6)识别未分类域名的相应功能,以及(7)根据未分类域名的相应功能,使用分类模型进行分类,将未分类的域名作为恶意。还公开了各种其他方法,系统和计算机可读介质。

著录项

  • 公开/公告号US10944781B1

    专利类型

  • 公开/公告日2021-03-09

    原文格式PDF

  • 申请/专利权人 SYMANTEC CORPORATION;

    申请/专利号US201816018041

  • 发明设计人 LEYLA BILGE;PIERRE-ANTOINE VERVIER;

    申请日2018-06-25

  • 分类号H04L29/06;G06F17/18;H04L29/12;

  • 国家 US

  • 入库时间 2022-08-24 17:34:02

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号