-
公开(公告)号:US20080155694A1
公开(公告)日:2008-06-26
申请号:US11971118
申请日:2008-01-08
申请人: YOUNG KWAN KWON , SE MAN OH , SANG YOUB LEE , GYU KWEON HAN , JU HWAN JEONG , SEUNG TAK OH
发明人: YOUNG KWAN KWON , SE MAN OH , SANG YOUB LEE , GYU KWEON HAN , JU HWAN JEONG , SEUNG TAK OH
IPC分类号: G06F11/30
CPC分类号: H04L63/1416 , H04L29/12066 , H04L61/1511 , H04L63/1491 , H04L2463/144
摘要: A method for dealing with attacks of malicious BOTs in a network security system includes detecting and analyzing a domain name receiving excessive DNS queries to judge the infection of a malicious BOT, registering the corresponding domain name as normal or abnormal management target, and redirecting an abnormal DNS query for the abnormal management target to a redirection processing & response system. Thereby, the automatic detection of malicious BOT attacks and the mechanism which performs the measures and the analysis simultaneously can protect the DNS servers and prevent the security accidents by malicious BOT attacks previously.
摘要翻译: 一种处理网络安全系统恶意BOT攻击的方法,包括检测和分析接收过多DNS查询的域名,判断恶意BOT的感染,将对应的域名注册为正常或异常管理目标,重定向异常 将异常管理目标的DNS查询转换为重定向处理和响应系统。 因此,恶意BOT攻击的自动检测和同时执行措施和分析的机制可以保护DNS服务器,防止以前恶意BOT攻击的安全事故。
-
公开(公告)号:US08112804B2
公开(公告)日:2012-02-07
申请号:US11971118
申请日:2008-01-08
申请人: Young Kwan Kwon , Se Man Oh , Sang Youb Lee , Gyu Kweon Han , Ju Hwan Jeong , Seung Tak Oh
发明人: Young Kwan Kwon , Se Man Oh , Sang Youb Lee , Gyu Kweon Han , Ju Hwan Jeong , Seung Tak Oh
IPC分类号: G08B23/00
CPC分类号: H04L63/1416 , H04L29/12066 , H04L61/1511 , H04L63/1491 , H04L2463/144
摘要: A method for dealing with attacks of malicious BOTs in a network security system includes detecting and analyzing a domain name receiving excessive DNS queries to judge the infection of a malicious BOT, registering the corresponding domain name as normal or abnormal management target, and redirecting an abnormal DNS query for the abnormal management target to a redirection processing & response system. Thereby, the automatic detection of malicious BOT attacks and the mechanism which performs the measures and the analysis simultaneously can protect the DNS servers and prevent the security accidents by malicious BOT attacks previously.
摘要翻译: 一种处理网络安全系统恶意BOT攻击的方法,包括检测和分析接收过多DNS查询的域名,判断恶意BOT的感染,将对应的域名注册为正常或异常管理目标,重定向异常 将异常管理目标的DNS查询转换为重定向处理和响应系统。 因此,恶意BOT攻击的自动检测和同时执行措施和分析的机制可以保护DNS服务器,防止以前恶意BOT攻击的安全事故。
-