APPARATUS AND METHOD FOR DETECTING MALICIOUS DOMAIN CLUSTER
    1.
    发明申请
    APPARATUS AND METHOD FOR DETECTING MALICIOUS DOMAIN CLUSTER 有权
    用于检测恶性域簇的装置和方法

    公开(公告)号:US20160294859A1

    公开(公告)日:2016-10-06

    申请号:US14735579

    申请日:2015-06-10

    Abstract: An apparatus and method for detecting a malicious domain cluster. The apparatus for detecting a malicious domain cluster includes a domain name server (DNS) data collection unit and a malicious domain cluster detection unit. The DNS data collection unit collects DNS traffic over a network, and stores the DNS traffic in a database. The malicious domain cluster detection unit generates a domain cluster based on the DNS data, learns the characteristics of normal and malicious clusters in the domain cluster, and detects whether the domain cluster is malicious based on the result of the learning.

    Abstract translation: 一种用于检测恶意域群集的装置和方法。 用于检测恶意域群集的装置包括域名服务器(DNS)数据收集单元和恶意域群集检测单元。 DNS数据收集单元通过网络收集DNS流量,并将DNS流量存储在数据库中。 恶意域群集检测单元根据DNS数据生成域集群,学习域群中正常和恶意群集的特征,根据学习结果,检测域群集是否恶意。

Patent Agency Ranking