Invention Grant
- Patent Title: Security threat detection using access patterns and domain name registrations
-
Application No.: US15224652Application Date: 2016-07-31
-
Publication No.: US09648037B2Publication Date: 2017-05-09
- Inventor: Munawar Monzy Merza
- Applicant: Splunk Inc.
- Applicant Address: US CA San Francisco
- Assignee: Splunk Inc.
- Current Assignee: Splunk Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Wong & Rees LLP
- Agent Kirk D. Wong
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06T11/20 ; H04L29/12 ; H04L29/08

Abstract:
Domain names are determined for each computational event in a set, each event detailing requests or posts of webpages. A number of events or accesses associated with each domain name within a time period is determined. A registrar is further queried to determine when the domain name was registered. An object is generated that includes a representation of the access count and an age since registration for each domain names. A client can interact with the object to explore representations of domain names associated with high access counts and recent registrations. Upon determining that a given domain name is suspicious, a rule can be generated to block access to the domain name.
Public/Granted literature
- US20170034206A1 SECURITY THREAT DETECTION USING ACCESS PATTERNS AND DOMAIN NAME REGISTRATIONS Public/Granted day:2017-02-02
Information query