Invention Grant
- Patent Title: Domain name system (DNS) based anomaly detection
-
Application No.: US15097236Application Date: 2016-04-12
-
Publication No.: US10079846B2Publication Date: 2018-09-18
- Inventor: Navindra Yadav , Ellen Scheib , Rachita Agasthy
- Applicant: CISCO TECHNOLOGY, INC.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agent Cindy Kaplan
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/12

Abstract:
In one embodiment, a method includes receiving at an analytics module operating at a network device, network traffic data collected from a plurality of sensors distributed throughout a network and installed in network components to obtain the network traffic data, identifying at the analytics module, Domain Name System (DNS) exchanges within the network, associating at the analytics module, the DNS exchanges with process, user, and host information, and identifying at the analytics module, anomalies in the DNS exchanges. An apparatus and logic are also disclosed herein.
Public/Granted literature
- US20160359887A1 DOMAIN NAME SYSTEM (DNS) BASED ANOMALY DETECTION Public/Granted day:2016-12-08
Information query