Invention Grant
- Patent Title: Malware domain detection using passive DNS
-
Application No.: US15653381Application Date: 2017-07-18
-
Publication No.: US10237283B2Publication Date: 2019-03-19
- Inventor: Yanxin Zhang , Xinran Wang , Huagang Xie , Wei Xu
- Applicant: Palo Alto Networks, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Palo Alto Networks, Inc.
- Current Assignee: Palo Alto Networks, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Van Pelt, Yi & James LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/12 ; G06F17/30

Abstract:
Techniques for malware domain detection using passive Domain Name Service (DNS) are disclosed. In some embodiments, malware domain detection using passive DNS includes generating a malware association graph that associates a plurality of malware samples with malware source information, in which the malware source information includes a first domain; generating a reputation score for the first domain using the malware association graph and passive DNS information; and determining whether the first domain is a malware domain based on the reputation score for the first domain.
Public/Granted literature
- US20180041521A1 MALWARE DOMAIN DETECTION USING PASSIVE DNS Public/Granted day:2018-02-08
Information query