发明名称 White listing DNS top-talkers
摘要 Systems and methods for creating a list of trustworthy resolvers in a domain name system. A computer receives a resolver profile for a resolver sending queries to a domain name server. The resolver profile is based on one or more of a top-talker status of the resolver, a normalcy of distribution of domain names queried, a continuity of distribution of query type, and an IP time-to-live variance of queries from the resolver. Resolver profiles can be compared to a trust policy to determine whether the resolver is trustworthy. Resolvers deemed trustworthy can be added to a list of trustworthy resolvers. Embodiments can detect the occurrence of a network-based attack. Embodiments can mitigate the effect of a network-based attack by responding only to queries from resolvers on the list of trustworthy resolvers. QUERIES FROM A RESOLVE 710 715 720 725 IP TTL VARIANCE Q-TYPE PROFILE Q-NAME PROFILE TO-TLKRINCREASE? CHANGE? CHANGE? RESOLVER PROFILE TRUST IS THE PROFILE POLICY TRSWRH? NO 745 NO MODE? ADD TO WHITE L1ST 70 RESPOND TO N QUERIES 70 IGNORE QUERIES FROM THIS RESOLVER FROM THIS RESOLVER Figure 7
申请公布号 AU2012211489(A1) 申请公布日期 2013.02.28
申请号 AU20120211489 申请日期 2012.08.10
申请人 VERISIGN, INC. 发明人 OSTERWEIL, ERIC;MCPHERSON, DANNY
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址