Invention Application
- Patent Title: DETECTION OF THREATS BASED ON RESPONSES TO NAME RESOLUTION REQUESTS
-
Application No.: US17507548Application Date: 2021-10-21
-
Publication No.: US20230131894A1Publication Date: 2023-04-27
- Inventor: Tejas Sanjeev Panse , Aditi Vutukuri , Arnold Koon-Chee Poon , Rajiv Mordani , Margaret Petrus
- Applicant: VMware, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: VMware, Inc.
- Current Assignee: VMware, Inc.
- Current Assignee Address: US CA Palo Alto
- Main IPC: H04L29/12
- IPC: H04L29/12

Abstract:
Some embodiments provide a method for identifying security threats to a datacenter. The method receives flow attribute sets for multiple flows from multiple host computers in the datacenter on which data compute nodes (DCNs) execute. Each flow attribute set indicates at least a source DCN for the flow. The method identifies flow attribute sets that correspond to DCNs responding to name resolution requests. For each DCN of a set of DCNs executing on the host computers, the method determines whether the DCN has sent responses to name resolution requests in a manner that deviates from a historical baseline for the DCN based on the identified flow attribute sets. When a particular DCN has sent responses to name resolution requests in a manner that deviates from a historical baseline for the particular DCN, the method identifies the particular DCN as a security threat to the datacenter.
Public/Granted literature
- US11792151B2 Detection of threats based on responses to name resolution requests Public/Granted day:2023-10-17
Information query