APPARATUS AND METHOD FOR IDENTIFYING DOMAIN NAME SYSTEM TUNNELING, EXFILTRATION AND INFILTRATION

    公开(公告)号:EP3204857A4

    公开(公告)日:2018-05-16

    申请号:EP15849113

    申请日:2015-10-05

    申请人: CLOUDMARK INC

    IPC分类号: G06F11/00 H04L12/26 H04L29/06

    摘要: A machine includes a processor and a memory connected to the processor. The memory stores instructions executed by the processor to preserve a second level domain, track requests for subdomains of the second level domain, determine the size of encoded subdomain data and determine the size of response data for subdomain requests. When the ratio of the number of unique subdomains versus the number of subdomain requests is over a first threshold a first satisfied condition is established. It is determined, in response to the first satisfied condition, when the size of the subdomain data exceeds a second threshold and the size of response data exceeds a third threshold to establish a second satisfied condition corresponding to deemed domain name system tunnel activity. It is determined, in response to the first satisfied condition, when the size of the subdomain data exceeds the second threshold to establish a third satisfied condition corresponding to deemed domain name system data exfiltration activity.