发明授权
US08904524B1 Detection of fast flux networks 有权
快速通量网络的检测

  • 专利标题: Detection of fast flux networks
  • 专利标题(中): 快速通量网络的检测
  • 申请号: US13245926
    申请日: 2011-09-27
  • 公开(公告)号: US08904524B1
    公开(公告)日: 2014-12-02
  • 发明人: Roy Hodgman
  • 申请人: Roy Hodgman
  • 申请人地址: US MA Hopkinton
  • 专利权人: EMC Corporation
  • 当前专利权人: EMC Corporation
  • 当前专利权人地址: US MA Hopkinton
  • 代理机构: BainwoodHuang
  • 主分类号: G06F12/14
  • IPC分类号: G06F12/14
Detection of fast flux networks
摘要:
Improved techniques of identifying a malicious communication involve a lightweight evaluator obtaining a domain name directly from a network transmission. The lightweight evaluator performs a query of the domain name on a database of known network transactions. Results of the query include IP addresses to which the domain name has resolved in prior transactions and Time To Live (TTL) values for each of those IP addresses. To such results of the query, the lightweight evaluator applies a set of heuristics which are arranged to determine whether the domain name could plausibly be a FFDN. Based on the result of the application of the heuristics to the domain name, the lightweight evaluator sends to a backend evaluator the domain name and a command to confirm whether the domain name is a FFDN.
信息查询
0/0