发明授权
- 专利标题: Detection of fast flux networks
- 专利标题(中): 快速通量网络的检测
-
申请号: US13245926申请日: 2011-09-27
-
公开(公告)号: US08904524B1公开(公告)日: 2014-12-02
- 发明人: Roy Hodgman
- 申请人: Roy Hodgman
- 申请人地址: US MA Hopkinton
- 专利权人: EMC Corporation
- 当前专利权人: EMC Corporation
- 当前专利权人地址: US MA Hopkinton
- 代理机构: BainwoodHuang
- 主分类号: G06F12/14
- IPC分类号: G06F12/14
摘要:
Improved techniques of identifying a malicious communication involve a lightweight evaluator obtaining a domain name directly from a network transmission. The lightweight evaluator performs a query of the domain name on a database of known network transactions. Results of the query include IP addresses to which the domain name has resolved in prior transactions and Time To Live (TTL) values for each of those IP addresses. To such results of the query, the lightweight evaluator applies a set of heuristics which are arranged to determine whether the domain name could plausibly be a FFDN. Based on the result of the application of the heuristics to the domain name, the lightweight evaluator sends to a backend evaluator the domain name and a command to confirm whether the domain name is a FFDN.
信息查询