Patent · US Active

Network anomaly detection

US10686814B2 · kind B2 · utility

3Cited by
12References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 10, 2015
Grant dateJun 16, 2020
Priority date
Expiry dateOct 10, 2035

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/144
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Examples relate to detecting network anomalies. In one example, a computing device may: receive, from each of a plurality of packet capture devices of a private network, domain name system (DNS) query packets that were sent by a particular client computing device operating on the private network, each DNS query packet specifying i) a destination DNS server, ii) a query domain name, and iii) a source address that specifies the particular client computing device; provide at least one of the DNS query packets to a DNS traffic analyzer that is trained to identify DNS anomalies based on characteristics of the DNS query packets; receive anomaly output from the DNS traffic analyzer, the anomaly output indicating a DNS anomaly that was identified for the DNS query packets; and in response to receiving the anomaly output, provide a user device with data specifying the identified DNS anomaly.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.