METHOD AND SYSTEM FOR FILTERING OF NETWORK TRAFFIC
    1.
    发明公开
    METHOD AND SYSTEM FOR FILTERING OF NETWORK TRAFFIC 审中-公开
    方法和系统网络流量过滤

    公开(公告)号:EP2462753A1

    公开(公告)日:2012-06-13

    申请号:EP10807097.0

    申请日:2010-08-04

    申请人: VeriSign, Inc.

    IPC分类号: H04W4/00

    摘要: A method of filtering a plurality of DNS queries, wherein each DNS query includes a query name and a resource record type, includes defining a filter rule including a domain name, a filter type, and a throttle percentage and forming a filter file including the filter rule. The method also includes transmitting the filter file from a server to a plurality of filter proxies, transmitting the filter file from each of the plurality of filter proxies to one or more processing engines, and receiving the plurality of DNS queries at one of the one or more processing engines. The method includes determining a match between the domain name and the query name and between the resource record type and the filter type for a subset of the plurality of DNS queries, and blocking a predetermined percentage (equal to the throttle percentage) of the subset of the plurality of DNS queries.

    SYSTEM AND METHOD FOR ADDING A WHITELIST ENTRY VIA DNS
    2.
    发明公开
    SYSTEM AND METHOD FOR ADDING A WHITELIST ENTRY VIA DNS 审中-公开
    系统在VERFAHREN ZUMHINZUFÜGENEINER威斯汀

    公开(公告)号:EP3007411A1

    公开(公告)日:2016-04-13

    申请号:EP15188397.2

    申请日:2015-10-05

    申请人: Verisign, Inc.

    IPC分类号: H04L29/12 H04L29/06

    摘要: A method for adding a blacklisted site to a whitelist. At least one whitelisting query may be generated for an encoded domain in the tag format: a nonce, a hash, a blocked-domain, and a static domain, each separated by a delimiter. The nonce is a unique identifier for the at least one query. The hash is a cryptographic hash of an IP address of the user, a normalized timestamp, and the blocked domain. The static domain is a constant domain representing the at least one query. The at least one query may be sent to a first recursive DNS server. The first recursive DNS server may create a message including whitelist information. The first recursive DNS server may send the message to a second recursive DNS server.

    摘要翻译: 将列入黑名单的网站添加到白名单的方法。 可以为标签格式的编码域生成至少一个白名单查询:随机数,散列,阻塞域和静态域,每个由分隔符分隔。 nonce是至少一个查询的唯一标识符。 散列是用户的IP地址,归一化时间戳和被阻止域的加密散列。 静态域是表示至少一个查询的常量域。 可以将至少一个查询发送到第一递归DNS服务器。 第一个递归DNS服务器可能会创建包含白名单信息的消息。 第一递归DNS服务器可以将消息发送到第二递归DNS服务器。