发明授权
- 专利标题: Systems and methods for detecting covert DNS tunnels
- 专利标题(中): 检测隐蔽DNS隧道的系统和方法
-
申请号: US12873553申请日: 2010-09-01
-
公开(公告)号: US09003518B2公开(公告)日: 2015-04-07
- 发明人: Daniel Wyschogrod , David Patrick Mankins
- 申请人: Daniel Wyschogrod , David Patrick Mankins
- 申请人地址: US MA Cambridge
- 专利权人: Raytheon BBN Technologies Corp.
- 当前专利权人: Raytheon BBN Technologies Corp.
- 当前专利权人地址: US MA Cambridge
- 代理机构: Ropes & Gray LLP
- 主分类号: G06F12/14
- IPC分类号: G06F12/14 ; H04L29/06 ; H04L29/12
摘要:
Systems and methods are disclosed for detecting covert DNS tunnels using n-grams. The majority of legitimate DNS requests originate from network content itself, for example, through hyperlinks in websites. So, comparing data from incoming network communications to a hostname included in a DNS request can give an indication on whether the DNS request is a legitimate request or associated with a covert DNS tunnel. This process can be made computationally efficient by extracting n-grams from incoming network content and storing the n-grams in an efficient data structure, such as a Bloom filter. The stored n-grams are compared with n-grams extracted from outgoing DNS requests. If n-grams from an outgoing DNS request are not found in the data structure, the domain associated with the DNS request is determined to be associated with a suspected covert DNS tunnel.
公开/授权文献
- US20120054860A1 SYSTEMS AND METHODS FOR DETECTING COVERT DNS TUNNELS 公开/授权日:2012-03-01
信息查询