SYSTEM AND METHOD FOR DETECTING ANOMALIES WITHIN A DOMAIN NAME SYSTEM (DNS) TRAFFIC
卷宗概要
发明人
Niv Peled; Alex Zelichenko; Paz Fichman; Adam Engelhart
IPC 分类
CPC 分类
A method and system for detecting anomalies within a domain name system (DNS) traffic is disclosed. Through the utilization of at least one processor, the method comprises receiving DNS traffic data from each of one or more DNS servers in real time, comparing the DNS traffic data with a data stored in a database. Furthermore, the method comprises determining a status of each of one or more DNS servers based on comparison. Further, the method comprises generating an alert for one or more users, based at least on the status. Furthermore, the method comprises determining whether each of one or more DNS servers outside a predefined learning period is queried by one or more DNS hosts. Thereafter, the method comprises adding each of one or more DNS servers to a baseline database upon determining that each of one or more DNS servers outside the predefined learning period is queried.
原文(中文)
A method and system for detecting anomalies within a domain name system (DNS) traffic is disclosed. Through the utilization of at least one processor, the method comprises receiving DNS traffic data from each of one or more DNS servers in real time, comparing the DNS traffic data with a data stored in a database. Furthermore, the method comprises determining a status of each of one or more DNS servers based on comparison. Further, the method comprises generating an alert for one or more users, based at least on the status. Furthermore, the method comprises determining whether each of one or more DNS servers outside a predefined learning period is queried by one or more DNS hosts. Thereafter, the method comprises adding each of one or more DNS servers to a baseline database upon determining that each of one or more DNS servers outside the predefined learning period is queried.