首页> 外国专利> Selective sinkholing of malware domains by a security device via DNS poisoning

Selective sinkholing of malware domains by a security device via DNS poisoning

机译:通过DNS中毒选择安全设备的恶意软件域的选择性散落

摘要

Techniques for selective sinkholing of malware domains by a security device via DNS poisoning are provided. In some embodiments, selective sinkholing of malware domains by a security device via DNS poisoning includes intercepting a DNS query for a network domain from a local DNS server at the security device, in which the network domain was determined to be a bad network domain and the bad network domain was determined to be associated with malware (e.g., a malware domain); and generating a DNS query response to the DNS query to send to the local DNS server, in which the DNS query response includes a designated sinkholed IP address for the bad network domain to facilitate identification of an infected host by the security device.
机译:提供了通过DNS中毒通过安全装置选择性地占恶意软件域的技术。 在一些实施例中,通过DNS中毒通过安全设备选择性地汇总恶意软件域包括从安全设备处的本地DNS服务器拦截用于网络域的DNS查询,其中网络域被确定为坏网络域和 确定不良网络域与恶意软件(例如,恶意软件域)相关联; 并生成对DNS查询的DNS查询响应以发送到本地DNS服务器,其中DNS查询响应包括用于坏网络域的指定的沉孔IP地址,以便于安全设备识别受感染主机的识别。

著录项

  • 公开/公告号US11128656B2

    专利类型

  • 公开/公告日2021-09-21

    原文格式PDF

  • 申请/专利权人 PALO ALTO NETWORKS INC.;

    申请/专利号US201916283545

  • 发明设计人 HUAGANG XIE;TAYLOR ETTEMA;

    申请日2019-02-22

  • 分类号G06F11;G06F12/14;G06F12/16;G08B23;H04L29/06;H04L29/12;

  • 国家 US

  • 入库时间 2022-08-24 21:08:57

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号