Patent · US Active

System and method for detecting DNS traffic anomalies

US9172716B2 · kind B2 · utility

6Cited by
11References
26Claims
0Family size

Assignee

Inventors

Key dates

Filing dateNov 8, 2012
Grant dateOct 27, 2015
Priority date
Expiry dateNov 8, 2032

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1425
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Systems and methods for analyzing domain name system (“DNS”) lookup data perform operations that may include: calculating traffic scores for a network address based on a set of DNS lookup data associated with the network address, where the set of DNS lookup data includes a plurality of query records having one or more queried network addresses; calculating a first variance and a second variance for the network address based on the traffic scores for the network address; and determining a rank of the network address based on the first and second variances.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.