- 专利标题: Clustering-based security monitoring of accessed domain names
-
申请号: US17386989申请日: 2021-07-28
-
公开(公告)号: US11606384B2公开(公告)日: 2023-03-14
- 发明人: Munawar Monzy Merza
- 申请人: Splunk Inc.
- 申请人地址: US CA San Francisco
- 专利权人: Splunk Inc.
- 当前专利权人: Splunk Inc.
- 当前专利权人地址: US CA San Francisco
- 代理机构: Nicholson De Vos Webster & Elliott LLP
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L9/40 ; A61G17/04 ; H04L61/4511 ; A61G17/007 ; G06F21/50 ; G06T11/20 ; H04L67/02
摘要:
Domain names are determined for each computational event in a set, each event detailing requests or posts of webpages. A number of events or accesses associated with each domain name within a time period is determined. A registrar is further queried to determine when the domain name was registered. An object is generated that includes a representation of the access count and an age since registration for each domain names. A client can interact with the object to explore representations of domain names associated with high access counts and recent registrations. Upon determining that a given domain name is suspicious, a rule can be generated to block access to the domain name.
公开/授权文献
信息查询