- 专利标题: IDENTIFYING AND USING DNS CONTEXTUAL FLOWS
-
申请号: US17696081申请日: 2022-03-16
-
公开(公告)号: US20220210183A1公开(公告)日: 2022-06-30
- 发明人: David McGrew , Blake Harrell Anderson , Daniel G. Wing , Flemming Andreasen
- 申请人: Cisco Technology, Inc.
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 主分类号: H04L9/40
- IPC分类号: H04L9/40 ; H04L61/4511
摘要:
In one embodiment, a device in a network captures domain name system (DNS) response data from a DNS response sent by a DNS service to a client in the network. The device captures session data for an encrypted session of the client. The device makes a determination that the encrypted session is malicious by using the captured DNS response data and the captured session data as input to a machine learning-based or rule-based classifier. The device performs a mediation action in response to the determination that the encrypted session is malicious.
公开/授权文献
- US11785041B2 Identifying and using DNS contextual flows 公开/授权日:2023-10-10
信息查询