Automated identification of false positives in DNS tunneling detectors

    公开(公告)号:US11916942B2

    公开(公告)日:2024-02-27

    申请号:US17366813

    申请日:2021-07-02

    申请人: Infoblox Inc.

    发明人: Peter Boord

    IPC分类号: H04L9/40

    摘要: Techniques for automated identification of false positives in DNS tunneling detectors are disclosed. In some embodiments, a system, process, and/or computer program product for automated identification of false positives in DNS tunneling detectors includes receiving a set of passive DNS data, wherein the set of passive DNS data includes a DNS query and a DNS response for resolution of the DNS query for each of a plurality of DNS queries; extracting a plurality of features associated with each domain in the set of passive DNS data; and classifying DNS tunneling activities and performing false positive reduction using the plurality of features associated with each domain in the set of passive DNS data to reduce false positive detections.

    AUTOMATED IDENTIFICATION OF FALSE POSITIVES IN DNS TUNNELING DETECTORS

    公开(公告)号:US20220182401A1

    公开(公告)日:2022-06-09

    申请号:US17366813

    申请日:2021-07-02

    申请人: Infoblox Inc.

    发明人: Peter Boord

    IPC分类号: H04L29/06

    摘要: Techniques for automated identification of false positives in DNS tunneling detectors are disclosed. In some embodiments, a system, process, and/or computer program product for automated identification of false positives in DNS tunneling detectors includes receiving a set of passive DNS data, wherein the set of passive DNS data includes a DNS query and a DNS response for resolution of the DNS query for each of a plurality of DNS queries; extracting a plurality of features associated with each domain in the set of passive DNS data; and classifying DNS tunneling activities and performing false positive reduction using the plurality of features associated with each domain in the set of passive DNS data to reduce false positive detections.

    Indexing of database queries
    5.
    发明授权

    公开(公告)号:US09424296B2

    公开(公告)日:2016-08-23

    申请号:US13929424

    申请日:2013-06-27

    申请人: Infoblox Inc.

    IPC分类号: G06F17/30 G06F7/00 G06F17/00

    摘要: Making data available from a database is disclosed. Making data available includes specifying a query function having a query function name, wherein the query function includes a structure and a member, determining the structure and the member included in the query function, wherein the query function has a query function name and includes the structure and the member, creating an index for the structure on the member, and compiling the query function to be available to a user by invoking the query function name without the user having to specify the structure and the member. Retrieving data from a database is disclosed. Retrieving includes invoking a query function that specifies a plurality of structures and a value, accessing a cross index of the plurality of structures, and using the cross index to access the data.

    Platforms for implementing an analytics framework for DNS security
    6.
    发明授权
    Platforms for implementing an analytics framework for DNS security 有权
    实现DNS安全性分析框架的平台

    公开(公告)号:US09363282B1

    公开(公告)日:2016-06-07

    申请号:US14257902

    申请日:2014-04-21

    申请人: Infoblox Inc.

    IPC分类号: H04L29/06 H04L29/12

    摘要: Flux domain is generally an active threat vector, and flux domain behaviors are continually changing in an attempt to evade existing detection measures. Accordingly, new and improved techniques are disclosed for flux domain detection. In some embodiments, an online platform implementing an analytics framework for DNS security is provided for facilitating flux domain detection. For example, the online platform can implement an analytics framework for DNS security based on passive DNS traffic analysis, disclosed herein with respect to various embodiments.

    摘要翻译: 通量域通常是一个主动的威胁载体,通量域行为正在不断变化,试图逃避现有的检测措施。 因此,公开了用于磁通量域检测的新的和改进的技术。 在一些实施例中,提供了实现用于DNS安全性的分析框架的在线平台,用于促进通量域检测。 例如,在线平台可以实现基于被动DNS流量分析的DNS安全性分析框架,这里涉及各种实施例。

    Managing multiple IP address management systems
    7.
    发明授权
    Managing multiple IP address management systems 有权
    管理多个IP地址管理系统

    公开(公告)号:US09065857B2

    公开(公告)日:2015-06-23

    申请号:US14483499

    申请日:2014-09-11

    申请人: Infoblox Inc.

    摘要: Managing multiple IP address management systems is provided. In some embodiments, managing multiple IP address management systems includes providing an IP address management (IPAM) manager system for receiving a configuration command to manage a first IP address management system; receiving a configuration command to manage a second IP address management system; receiving a join request from the first IP address management system; and receiving a join request from the second IP address management system, in which the IP address management manager system is in communication with the first IP address management system and the second IP address management system for managing each of the first IP address management system and the second IP address management system.

    摘要翻译: 提供管理多个IP地址管理系统。 在一些实施例中,管理多个IP地址管理系统包括提供用于接收管理第一IP地址管理系统的配置命令的IP地址管理(IPAM)管理器系统; 接收用于管理第二IP地址管理系统的配置命令; 从第一IP地址管理系统接收加入请求; 以及从第二IP地址管理系统接收加入请求,其中IP地址管理管理系统与第一IP地址管理系统通信,第二IP地址管理系统用于管理第一IP地址管理系统和 第二个IP地址管理系统。

    Methods and apparatus for identifying the impact of changes in computer networks
    8.
    发明授权
    Methods and apparatus for identifying the impact of changes in computer networks 有权
    用于识别计算机网络变化影响的方法和装置

    公开(公告)号:US09065738B2

    公开(公告)日:2015-06-23

    申请号:US14062690

    申请日:2013-10-24

    申请人: Infoblox Inc.

    IPC分类号: H04L12/24

    摘要: The impact of device configuration changes on operational issues and policy compliance in a computer network can be discerned from a visual data presentation that jointly shows representations of changes, issues, and policy compliance in a common view for a group of network devices. Configuration information is collected from devices in the computer network and processed to determine whether a change has occurred in a configuration of any of the devices, whether any operational issues exist for each of the devices, and whether any of the devices are not in compliance with any applicable operational policies. A display device displays the visual data presentation to allow an operator to see trends and relationships between device configuration changes and operational issues and incidents of policy non-compliance. The visual data presentation can be depicted as a graphical timeline view, a network topology view, or a table view of the information.

    摘要翻译: 可以从视觉数据呈现中识别设备配置更改对计算机网络中的操作问题和策略合规性的影响,该视觉数据表示在一组网络设备的共同视图中共同显示更改,问题和策略合规性的表示。 配置信息从计算机网络中的设备收集并被处理以确定是否在任何设备的配置中发生了改变,每个设备是否存在任何操作问题,以及是否任何设备不符合 任何适用的运营政策。 显示设备显示视觉数据呈现,以允许操作者查看设备配置更改与操作问题之间的趋势和关系以及策略不合规事件。 视觉数据呈现可以被描绘为图形时间线视图,网络拓扑视图或信息的表视图。

    Database migration
    9.
    发明授权
    Database migration 有权
    数据库迁移

    公开(公告)号:US09053101B2

    公开(公告)日:2015-06-09

    申请号:US13719888

    申请日:2012-12-19

    申请人: Infoblox Inc.

    IPC分类号: G06F17/30

    CPC分类号: G06F17/30008 G06F17/303

    摘要: A technique for converting a first version of a database to a second version is disclosed. The technique includes determining available translation steps, selecting a translation path from the first version of the database to the second version, and executing the selected translation steps in the translation path. The translation path includes selected translation steps from among the available translation steps.

    摘要翻译: 公开了将数据库的第一版本转换为第二版本的技术。 该技术包括确定可用的翻译步骤,从数据库的第一版本到第​​二版本选择翻译路径,以及在翻译路径中执行所选择的翻译步骤。 翻译路径包括从可用的翻译步骤中选择的翻译步骤。

    Semantic replication
    10.
    发明授权
    Semantic replication 有权
    语义复制

    公开(公告)号:US08874516B2

    公开(公告)日:2014-10-28

    申请号:US13970303

    申请日:2013-08-19

    申请人: Infoblox, Inc.

    IPC分类号: G06F17/30

    摘要: Replicating data in a distributed database having a plurality of nodes is disclosed. Replicating includes receiving a semantic command at a local version of the database at a node, interpreting the semantic command, and applying the semantic command to the local version of the database.

    摘要翻译: 公开了在具有多个节点的分布式数据库中复制数据。 复制包括在节点处的数据库的本地版本处接收语义命令,解释语义命令,以及将语义命令应用于数据库的本地版本。