SYSTEMS AND METHODS FOR IDENTIFYING MALICIOUS DOMAINS USING INTERNET-WIDE DNS LOOKUP PATTERNS
    1.
    发明公开
    SYSTEMS AND METHODS FOR IDENTIFYING MALICIOUS DOMAINS USING INTERNET-WIDE DNS LOOKUP PATTERNS 审中-公开
    方法和系统用于识别恶性畴Internet范围的DNS搜索模式

    公开(公告)号:EP2569711A1

    公开(公告)日:2013-03-20

    申请号:EP11781340.2

    申请日:2011-05-13

    IPC分类号: G06F15/173

    CPC分类号: H04L63/1425 H04L63/1416

    摘要: Systems and methods are disclosed for identifying domains as malicious based on Internet-wide DNS lookup patterns. Disclosed embodiments look for variance in the servers that look up a domain and also look at the popularity growth (quantity of queries from unique addresses) of a domain after registration to identify malicious domains. Other disclosed embodiments measure the similarity of servers that query a domain and cluster domains based on the similarity of those servers. Disclosed embodiments may use such temporal and spatial lookup patterns as input to a blacklist process to more effectively and quickly blacklist domains based on their Internet-wide lookup patterns.