Invention Grant
- Patent Title: Apparatus and method for identifying domain name system tunneling, exfiltration and infiltration
-
Application No.: US14508987Application Date: 2014-10-07
-
Publication No.: US09729413B2Publication Date: 2017-08-08
- Inventor: Neil Cook , Olivier Lemarié , Mark Richard Stemm
- Applicant: Cloudmark, Inc.
- Applicant Address: US CA San Francisco
- Assignee: Coudmark, Inc.
- Current Assignee: Coudmark, Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Cooley LLP
- Main IPC: H04L12/26
- IPC: H04L12/26 ; H04L12/851 ; H04L29/06

Abstract:
A machine includes a processor and a memory connected to the processor. The memory stores instructions executed by the processor to preserve a second level domain, track requests for subdomains of the second level domain, determine the size of encoded subdomain data and determine the size of response data for subdomain requests. When the ratio of the number of unique subdomains versus the number of subdomain requests is over a first threshold a first satisfied condition is established. It is determined, in response to the first satisfied condition, when the size of the subdomain data exceeds a second threshold and the size of response data exceeds a third threshold to establish a second satisfied condition corresponding to deemed domain name system tunnel activity. It is determined, in response to the first satisfied condition, when the size of the subdomain data exceeds the second threshold to establish a third satisfied condition corresponding to deemed domain name system data exfiltration activity.
Public/Granted literature
- US20160099852A1 Apparatus and Method for Identifying Domain Name System Tunneling, Exfiltration and Infiltration Public/Granted day:2016-04-07
Information query