Invention Grant
- Patent Title: Security threat detection using domain name registrations
- Patent Title (中): 使用域名注册进行安全威胁检测
-
Application No.: US14815972Application Date: 2015-08-01
-
Publication No.: US09432396B2Publication Date: 2016-08-30
- Inventor: Munawar Monzy Merza
- Applicant: Splunk Inc.
- Applicant Address: US CA San Francisco
- Assignee: Splunk Inc.
- Current Assignee: Splunk Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Wong & Rees LLP
- Agent Kirk D. Wong
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/12 ; A61G17/007 ; A61G17/04 ; G06F21/50 ; G06T11/20 ; H04L29/08

Abstract:
Domain names are determined for each computational event in a set, each event detailing requests or posts of webpages. A number of events or accesses associated with each domain name within a time period is determined. A registrar is further queried to determine when the domain name was registered. An object is generated that includes a representation of the access count and an age since registration for each domain names. A client can interact with the object to explore representations of domain names associated with high access counts and recent registrations. Upon determining that a given domain name is suspicious, a rule can be generated to block access to the domain name.
Public/Granted literature
- US20160036851A1 Security Threat Detection Using Domain Name Registrations Public/Granted day:2016-02-04
Information query