Method and device for detecting anomaly of domain name system
A domain name system and abnormal technology, applied in the field of computer networks, can solve the problems of high missed detection rate and DNS lag in detection, and achieve the effect of low missed detection rate and reduced loss.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0032] figure 1 It is a schematic flow chart of an embodiment of the method for detecting DNS anomalies in the present invention, such as figure 1 As shown, the method includes:
[0033] Step 101: dividing the DNS query data flow into multiple data blocks;
[0034] It should be noted that: the larger the divided data block, that is to say, the more query data each data block contains, the more gentle the change of the entropy value of the data block, which can effectively reduce the occurrence of false detection, but at the same time It also reduces the sensitivity to abnormal traffic, and the missed detection rate increases; on the contrary, the smaller the data block, that is to say, the smaller the amount of query data included in each data block, the higher the sensitivity of detecting DNS anomalies, but the accuracy is lower. will decrease accordingly.
[0035] In practical applications, the DNS query data flow can be divided into multiple data blocks according to a sp...
Embodiment 2
[0070] Figure 5 It is a schematic diagram of an embodiment of a device for detecting DNS anomalies in the present invention, such as Figure 5 As shown, the device includes: a division module 201, a calculation module 202 and a judgment module 203;
[0071] Wherein, the division module 201 is used to divide the DNS query data flow into a plurality of data blocks;
[0072] Specifically, the division module 201 is configured to divide the DNS query data flow into multiple data blocks according to a specified time and / or according to a specified query volume.
[0073] A calculation module 202, configured to calculate entropy values of multiple data blocks divided by the division module 201 according to preset query attributes, and obtain corresponding multiple entropy values;
[0074] Wherein, the calculation module 202 includes a first calculation unit and a second calculation unit;
[0075] The first calculation unit is used to calculate the probability that each element ...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com