CNIPA.AI
검색으로 돌아가기
기록

SYSTEM AND METHOD FOR DETECTING ANOMALIES WITHIN A DOMAIN NAME SYSTEM (DNS) TRAFFIC

발명심사 중
20청구항 · 3 독립항
§ Ⅰ

개요

발명자

Niv Peled; Alex Zelichenko; Paz Fichman; Adam Engelhart

IPC 분류

H4L 9/40

CPC 분류

H4L63/1425

A method and system for detecting anomalies within a domain name system (DNS) traffic is disclosed. Through the utilization of at least one processor, the method comprises receiving DNS traffic data from each of one or more DNS servers in real time, comparing the DNS traffic data with a data stored in a database. Furthermore, the method comprises determining a status of each of one or more DNS servers based on comparison. Further, the method comprises generating an alert for one or more users, based at least on the status. Furthermore, the method comprises determining whether each of one or more DNS servers outside a predefined learning period is queried by one or more DNS hosts. Thereafter, the method comprises adding each of one or more DNS servers to a baseline database upon determining that each of one or more DNS servers outside the predefined learning period is queried.

원문 (중국어)

A method and system for detecting anomalies within a domain name system (DNS) traffic is disclosed. Through the utilization of at least one processor, the method comprises receiving DNS traffic data from each of one or more DNS servers in real time, comparing the DNS traffic data with a data stored in a database. Furthermore, the method comprises determining a status of each of one or more DNS servers based on comparison. Further, the method comprises generating an alert for one or more users, based at least on the status. Furthermore, the method comprises determining whether each of one or more DNS servers outside a predefined learning period is queried by one or more DNS hosts. Thereafter, the method comprises adding each of one or more DNS servers to a baseline database upon determining that each of one or more DNS servers outside the predefined learning period is queried.