Invention Grant
- Patent Title: Systems and methods to detect and monitor DNS tunneling
-
Application No.: US15679519Application Date: 2017-08-17
-
Publication No.: US10432651B2Publication Date: 2019-10-01
- Inventor: Sushil Pangeni , Vladimir Stepanenko , Ravinder Verma , Srikanth Devarajan
- Applicant: Zscaler, Inc.
- Applicant Address: US CA San Jose
- Assignee: Zscaler, Inc.
- Current Assignee: Zscaler, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Clements Bernard Walker PLLC
- Agent Lawrence A. Baratta, Jr.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/12 ; H04L12/26

Abstract:
Systems and methods of detecting Domain Name System (DNS) tunnels for monitoring thereof include obtaining data related to DNS traffic between DNS nameservers and clients; determining a score for each DNS nameserver based on the data to characterize DNS queries over a period of time for each DNS nameserver, wherein the score incorporates all DNS queries associated with the associated DNS nameserver over the period of time; determining one or more DNS nameservers likely operating DNS tunnels based on the score; and performing one or more actions on the one or more DNS nameservers related to the DNS tunnels.
Public/Granted literature
- US20190058718A1 SYSTEMS AND METHODS TO DETECT AND MONITOR DNS TUNNELING Public/Granted day:2019-02-21
Information query