Systems and methods for detecting DNS communications through time-to-live analyses

    公开(公告)号:US11477161B1

    公开(公告)日:2022-10-18

    申请号:US17514814

    申请日:2021-10-29

    Applicant: SPLUNK Inc.

    Abstract: A computerized method is disclosed that includes accessing domain name server (DNS) record data including a plurality of DNS records spanning a first time period, performing a time-to-live (TTL) analysis to determine a TTL run length distribution for the DNS record data, wherein the TTL analysis includes: generating a vector of the TTL values of each DNS record ordered sequentially in time, parsing the vector of the TTL values into segments, where a segment consists of one or more TTL values where a current TTL value is less than an immediately preceding TTL value, and determining the TTL run length distribution, determining whether DNS beaconing is present based on a result of the TTL analysis and in response to determining that DNS beaconing is present, generating an alert for a system administrator.

    Systems and methods for DNS text classification

    公开(公告)号:US12056169B1

    公开(公告)日:2024-08-06

    申请号:US17513670

    申请日:2021-10-28

    Applicant: SPLUNK Inc.

    CPC classification number: G06F16/334 G06F16/35 G06N20/00

    Abstract: A computerized method is disclosed that includes operations of training a machine learning model using a labeled training set of data, wherein the machine learning model is configured to classify domain name server (DNS) records, obtaining DNS record data including at least a first DNS Txt record, applying the trained machine learning model to the first DNS Txt record to classify the first DNS Txt record and responsive to the classification of the first DNS Txt record, generating a flag for a system administrator. The trained machine learning model may classify the first DNS Txt record using logistic regression. In some instances, applying the trained machine learning model to the first DNS Txt record includes performing a tokenizing operation on the first DNS Txt record to generate a tokenized first DNS Txt record.

Patent Agency Ranking