Invention Grant
- Patent Title: DGA behavior detection
-
Application No.: US16878377Application Date: 2020-05-19
-
Publication No.: US11032297B2Publication Date: 2021-06-08
- Inventor: Wei Xu , Xin Ouyang
- Applicant: Palo Alto Networks, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Palo Alto Networks, Inc.
- Current Assignee: Palo Alto Networks, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Van Pelt, Yi & James LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/12

Abstract:
Techniques for Domain Generation Algorithm (DGA) behavior detection are provided. In some embodiments, a system, process, and/or computer program product for DGA behavior detection includes receiving passive Domain Name System (DNS) data that comprises a plurality of DNS responses at a security device; and applying a signature to the passive DNS data to detect DGA behavior, in which applying the signature to the passive DNS data to detect DGA behavior further comprises: parsing each of the plurality of DNS responses to determine whether one or more of the plurality of DNS responses correspond to a non-existent domain (NXDOMAIN) response.
Public/Granted literature
- US20200280572A1 DGA BEHAVIOR DETECTION Public/Granted day:2020-09-03
Information query