发明名称 USING AGGREGATED DNS INFORMATION ORIGINATING FROM MULTIPLE SOURCES TO DETECT ANOMALOUS DNS NAME RESOLUTIONS
摘要 A DNS security system collects and uses aggregated DNS information originating from a plurality of client computers to detect anomalous DNS name resolutions. A server DNS security component receives multiple transmissions of DNS information from a plurality of client computers, each transmission of DNS information concerning a specific instance of a resolution of a specific DNS name. The server component aggregates the DNS information from the multiple client computers. The server component compares DNS information received from a specific client computer concerning a specific DNS name to aggregated DNS information received from multiple client computers concerning the same DNS name to identify anomalous DNS name resolutions. Where an anomaly concerning received DNS information is identified, a warning can be transmitted to the specific client computer from which the anomalous DNS information was received.
申请公布号 EP2532121(A4) 申请公布日期 2014.04.23
申请号 EP20100845413 申请日期 2010.12.30
申请人 SYMANTEC CORPORATION 发明人 GARDNER, PATRICK
分类号 H04L12/28 主分类号 H04L12/28
代理机构 代理人
主权项
地址