DNS EARLY THREAT RESPONSE

Various techniques for providing a DNS Early Threat Executive Response System (DETERS) are disclosed. In some embodiments, DETERS is a comprehensive DNS threat detection, response, and reporting system with a modular analytics architecture that allows for early detection of suspicious activity in ne...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Johnson, Darin, Burton, Renée Carol
Format: Patent
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Various techniques for providing a DNS Early Threat Executive Response System (DETERS) are disclosed. In some embodiments, DETERS is a comprehensive DNS threat detection, response, and reporting system with a modular analytics architecture that allows for early detection of suspicious activity in near real-time. DETERS can identify threats before they are able to spread or compromise systems. DETERS uses a combination of streaming and batch processing, as well as historical DNS information. The DNS-centric design allows a DNS resolver to quickly mitigate threats and for the reporting system to alert users allowing them to take further actions that are reflected in the DNS resolver response policy.