首页>
外国专利>
TIMELY DETECTION OF NETWORK TRAFFIC TO REGISTERED DGA GENERATED DOMAINS
TIMELY DETECTION OF NETWORK TRAFFIC TO REGISTERED DGA GENERATED DOMAINS
展开▼
机译:及时检测注册DGA生成的域的网络流量
展开▼
页面导航
摘要
著录项
相似文献
摘要
A non-transitory computer-readable medium having a program stored thereon that, when executed by one or more processors, directs a computing system to secure a communication network. The program comprises a traffic inspection engine, a domain generation algorithm (DGA) inspection engine, and a message bus communicationally coupling the traffic inspection engine and the DGA inspection engine. The traffic inspection engine is configured to identify if a traffic session containing a domain name system (DNS) request and/or response in a communication network includes a DGA generated domain and send information about the identified DGA generated domain to the DGA inspection engine via the message bus. The DGA inspection engine is configured to verify if the identified DGA generated domain is registered, and send information about the registered DGA domain to the traffic inspection engine via the message bus. The traffic inspection engine is further configured to inspect, using the information about the registered DGA generated domain, if a subsequent traffic session in the communication network contains the registered DGA generated domain.
展开▼