Abnormal domain name detection method and system
A domain name detection and domain name technology, applied in the field of network security, can solve the problems of high false positive rate, lack of discovery of unknown abnormal domain names, unsatisfactory effect, etc., and achieve the effect of reducing the false positive rate
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0055] The present invention will be described in further detail below in conjunction with the accompanying drawings.
[0056] The method process of the present invention is as figure 1 shown.
[0057] Step S100, receiving and parsing the DNS response message, making statistics with the preset statistical time interval as the statistical period, and generating a DNS resolution statistical vector set including the DNS response message information and the statistical value of the number of messages within the statistical period.
[0058] The specific implementation manner of step S100 is as follows.
[0059] Step S110, initialize relevant detection parameters.
[0060] In the embodiment, the timer T is set to 0, the statistical time interval is Ts seconds, and the detection time interval is set to T0=n×Ts seconds, where n is a positive integer. In this embodiment, Ts=300, T0=6×300=1800. Set the length of the latest change time list of the resolved address, expressed as Lt, a...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 