发明名称 Using Aggregated DNS Information Originating from Multiple Sources to Detect Anomalous DNS Name Resolutions
摘要 A DNS security system collects and uses aggregated DNS information originating from a plurality of client computers to detect anomalous DNS name resolutions. A server DNS security component receives multiple transmissions of DNS information from a plurality of client computers, each transmission of DNS information concerning a specific instance of a resolution of a specific DNS name. The server component aggregates the DNS information from the multiple client computers. The server component compares DNS information received from a specific client computer concerning a specific DNS name to aggregated DNS information received from multiple client computers concerning the same DNS name to identify anomalous DNS name resolutions. Where an anomaly concerning received DNS information is identified, a warning can be transmitted to the specific client computer from which the anomalous DNS information was received.
申请公布号 US2013061321(A1) 申请公布日期 2013.03.07
申请号 US201213663271 申请日期 2012.10.29
申请人 SYMANTEC CORPORATION;SYMANTEC CORPORATION 发明人 GARDNER PATRICK
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址