Invention Grant
- Patent Title: Detecting domain name system (DNS) tunneling based on DNS logs and network data
-
Application No.: US15466300Application Date: 2017-03-22
-
Publication No.: US10412107B2Publication Date: 2019-09-10
- Inventor: Alon Brutzkus , Roy Levin
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Workman Nydegger
- Main IPC: H04L9/00
- IPC: H04L9/00 ; H04L29/06 ; H04L29/12 ; H04L12/46 ; H04L12/26

Abstract:
A system to detect domain name server tunneling includes a processor and machine readable instructions stored on a tangible machine readable medium, which when executed by the processor, configure the processor to collect, during a predetermined time period, responses received from a domain name server to queries sent to the domain name server by a computing device, the responses including internet protocol (IP) addresses; collect IP addresses accessed by the computing device during the predetermined time period; compare the IP addresses received by the computing device in the responses from the domain name server to the IP addresses accessed by the computing device; and detect domain name server tunneling based on the comparison.
Public/Granted literature
- US20180278633A1 DETECTING DOMAIN NAME SYSTEM (DNS) TUNNELING BASED ON DNS LOGS AND NETWORK DATA Public/Granted day:2018-09-27
Information query