-
公开(公告)号:US20210234899A1
公开(公告)日:2021-07-29
申请号:US16774950
申请日:2020-01-28
Applicant: Cisco Technology, Inc.
Inventor: Antonio TRIFILO , Maria CARPEN AMARIE , Thomas VEGAS , Anirban KARMAKAR , Shree N. MURTHY
IPC: H04L29/06 , H04L29/12 , H04L12/911
Abstract: The use of device context in applying security policies is provided by receiving a Domain Name Service (DNS) query for a network resource from a user device (UD) at a DNS analysis server, the DNS query including a functional label describing a context of the UD; analyzing the DNS query to determine whether the UD is permitted to access the network resource based on the functional label; and in response to the functional label indicating that the UD is not permitted to access the network resource, transmitting a block page to the UD. The functional label can be added to the DNS query by a Mobile Device Management application on the UD, a router associated with the UD, or an enterprise server. Contexts for previously blocked DNS queries can be aggregated to identify UDs sharing at least one value with the previously blocked DNS queries as security compromised devices.