Invention Grant
- Patent Title: Real-time cloud-based detection and mitigation of DNS data exfiltration and DNS tunneling
-
Application No.: US15333120Application Date: 2016-10-24
-
Publication No.: US10230760B2Publication Date: 2019-03-12
- Inventor: Sameer Thakar , Nathan Glenn
- Applicant: VERISIGN, INC.
- Applicant Address: US VA Reston
- Assignee: VERISIGN, INC.
- Current Assignee: VERISIGN, INC.
- Current Assignee Address: US VA Reston
- Agency: Artegis Law Group, LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; H04L29/06 ; H04L12/46 ; H04L29/12 ; H04L29/08

Abstract:
Various embodiments of the invention disclosed herein provide techniques for managing a domain name system (DNS) based attack. An exfiltration and tunneling mitigation platform receives a first DNS request directed to a first domain name. The exfiltration and tunneling mitigation platform determines that a first characteristic associated with a first fully qualified domain name (FQDN) included in the first DNS request exceeds a first threshold value. In response, the exfiltration and tunneling mitigation platform computes a distance between the first FQDN and a second FQDN included in a second DNS request also directed to the first domain name. The exfiltration and tunneling mitigation platform increments a first count value associated with the first domain name based on the distance. At least one advantage of the disclosed techniques is that a DNS-based attack can be detected and mitigated before a significant amount of DNS exfiltration or DNS tunneling has occurred.
Public/Granted literature
- US20180115582A1 REAL-TIME CLOUD-BASED DETECTION AND MITIGATION OF DNS DATA EXFILTRATION AND DNS TUNNELING Public/Granted day:2018-04-26
Information query