Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

275 results about "Domain Name System" patented technology

The Domain Name System (DNS) is a hierarchical and decentralized naming system for computers, services, or other resources connected to the Internet or a private network. It associates various information with domain names assigned to each of the participating entities. Most prominently, it translates more readily memorized domain names to the numerical IP addresses needed for locating and identifying computer services and devices with the underlying network protocols. By providing a worldwide, distributed directory service, the Domain Name System has been an essential component of the functionality of the Internet since 1985.

Multi-modal attack identification method fusing BMama and difference to guide trans-attention

PendingCN121333666ABiological modelsSecuring communicationAddress Resolution ProtocolDomain name
The invention discloses a multi-modal attack identification method fusing BMama and difference to guide trans-attention, which comprises the following steps: simulating a false data injection attack, a denial of service attack, an address resolution protocol spoofing attack and a domain name system spoofing attack, collecting physical layer sensor data and network layer flow data, and preprocessing multi-modal data; bMama is constructed to perform dynamic time modeling on multi-modal data, a graph neural network is combined to adversariate a variational auto-encoder, features of a power grid system topology and a communication topology structure are fused, and robustness of potential representation is enhanced through adversarial training; the method comprises the following steps of: guiding feature complementary fusion by using modal difference through a difference guide iteration cross-attention fusion mechanism, improving the capability of distinguishing complex attacks, finally carrying out attack detection and classification on fused modals, and executing end-to-end optimization according to a weighted combination of loss of each part. The method can effectively detect and classify the multi-modal attack in the smart power grid, and enhances the safety and reliability of a complex system.
Owner:SOUTHEAST UNIV

DNS configuration provisioning

Method and apparatus for improvement of DNS configuration for applications are disclosed. A method performed at a server comprises generating Domain Name System (DNS) information; deciding whether to transmit the DNS information to a User Equipment (UE) or to a network or to both the UE and the network; and transmitting the DNS information for use with at least one application associated with the UE according to the decision.
Owner:LENOVO (BEIJING) LTD

Methods and systems for prevention of attacks associated with the domain name system

The attack vectors for some denial-of-service cyber attacks on the Internet's Domain Name System (DNS) are bad, bogus, or unregistered domain name DNS requests to resolve domain names that are not registered in the DNS. Some other cyber attacks steal sensitive data by encoding the data in bogus domain names, or domain names otherwise not registered in the DNS, that are transferred across networks in bogus DNS requests. A DNS gatekeeper may filter in-transit packets containing DNS requests and may efficiently determine if a request's domain name is registered in the DNS. When the domain name is not registered in the DNS, the DNS gatekeeper may take one of a plurality of protective actions. The DNS gatekeeper drops requests determined not to be legitimate, which may prevent an attack.
Owner:CENTRIPETAL NETWORKS INC

Configuring application availability using anycast addressing

Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port / protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.
Owner:PALO ALTO NETWORKS INC

Method and apparatus for selecting edge application server, and network element device, user equipment and storage medium

The present disclosure relates to method and apparatus for selecting an edge application server, and element network device, user equipment and storage medium. The method includes: a user equipment receiving first indication information, which is sent by an SMF, wherein the first indication information is used for indicating the priority of domain name system (DNS) information; and the user equipment making a DNS policy decision according to the first indication information, and sending a DNS query request to an EASDF, wherein the DNS query request is used by the EASDF to execute the discovery or selection of an edge application server (EAS).
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Organizing distribution of DNS information in a computer network

A method of organizing distribution of information related to a domain name system, DNS, in a computer network is provided. The method includes, by a first node of the computer network: performing a container-based execution of a first instance of a software application, thereby aggregating DNS information specific to the software application; generating a DNS message indicative of the DNS information; and transmitting the DNS message to a second node of the computer network for usage of the DNS information by a container-based execution of a second instance of the software application.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Arrangement and a method of threat prevention in a computer or computer network

A computer-implemented method, system, and computer-readable medium for threat detection in a computer or computer network are disclosed, comprising collecting DNS (Domain Name System) queries and / or information relating to DNS queries, identifying failed queries from the collected DNS queries and / or from information relating to DNS queries, and determining whether a domain related to the failed DNS query is related to an expired and / or unregistered domain, e.g. from a domain name related database.
Owner:F SECURE CORP

Inline detect and block relayed DNS tunneling traffic

The present application discloses a method, system, and computer system for detecting DNS tunneling traffic. The method includes (i) obtaining non-DNS network traffic across an enterprise network, (ii) obtaining a hostname comprised in the non-DNS network traffic, (iii) querying a security service for a Domain Name System (DNS) tunneling attack verdict based at least in part on the hostname, (iv) determining whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict, and (v) handling the non-DNS network traffic based at least in part on a determination of whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict.
Owner:PALO ALTO NETWORKS INC

System and method for autonomously fingerprinting and enumerating internet of thing (IoT) devices based on nated IPFIX and DNS traffic

This document describes a system and method for detecting the presence of Internet of Things (IoTs) from network traffic that has undergone a Network Address Translation (NAT) process, i.e., NATed network traffic, regardless of whether the network traffic comprises IP Flow Information Export (IPFIX) type of traffic or Domain Name System (DNS) type of traffic. Such a capability is crucial as the adoption rate of IoTs have increased exponentially over the past few years. In order to protect IoTs from cyber-attacks, one would first have to understand what type of IoTs are being used, and how many / how widely used these IoTs are. Once the IoT landscape has been defined, cyber defenders may then dedicate resources to identify and subsequently address vulnerabilities that may be in these IoTs.
Owner:ENSIGN INFOSECURITY PTE LTD

DNS security operation center insights

PCT designated stageWO2026024337A9Digital data protectionInternal/peripheral component protectionDomain nameSecurity operations center
Various techniques for DNS security operations center insights are disclosed. In some embodiments, a system / process / computer program product for DNS security operations center insights includes collecting Domain Name System (DNS) security associated events; generating a plurality of insights based on the collected DNS security associated events; and performing an action based on one or more of the insights.
Owner:INFOBLOX INC

Printer configuration webpage access method based on USB-to-network conversion

ActiveCN116723173BImprove user experienceSimplify the process of configuring web accessTransmissionEnergy efficient computingComputer printingIp address
The application discloses a printer configuration webpage access method based on a USB-to-network port and a printer device, and the method comprises the following steps: controlling a LINUX kernel to load a USB virtual network card driver, allocating an IP address and a subnet mask for a USB port, and generating a virtual network port according to the USB port; performing domain name system configuration processing on the virtual network port, and allocating a slave IP address for a terminal device connected to the USB port according to the IP address and the subnet mask, wherein, the USB port of the printer is simulated into a virtual network port through the USB virtual network card driver, so that the terminal device can obtain the slave IP address allocated by the virtual network port by connecting the USB port, access the network of the printer device through the slave IP address, and access the configuration webpage of the printer device, thereby simply and effectively realizing the printer configuration webpage access, not needing additional hardware devices, and further simplifying the configuration webpage access process and improving the use experience of users.
Owner:JIANGMEN DASCOM COMP PERIPHERAL +1

Traffic control method, device, system, electronic device, and storage medium

This application relates to a flow control method, apparatus, system, electronic device, and storage medium, applied in the field of flow control technology. The method includes: determining an initial policy based on a baseline flow in a target line; using the initial policy as a target policy; sending the target policy to a Domain Name System (DNS) server; sending the target policy to a flow feedback server, so that if the flow feedback server determines that there is a flow anomaly based on the current flow monitoring result corresponding to the node and the target flow, it sends a first flow anomaly result to a policy server; if the first flow anomaly result is received, determining the abnormal node in the target line based on the first flow anomaly result; replacing the abnormal node in the initial policy with the first target node to obtain the target policy, and returning to the step of sending the target policy to the DNS server, until there is no flow anomaly. This application can improve the accuracy of flow control by the DNS server.
Owner:BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD

Communication method and apparatus

This application provides a communication method and apparatus. The method may include receiving, by a second session management network element in a visited network, from a first session management network element in a home network, indication information, wherein the indication information indicates that traffic routing is allowed in the visited network. The method may further include sending, by the second session management network element and based on the indication information, IP address information of the visited network to a user plane network element in the visited network, wherein the IP address information is information used to determine an extension mechanisms for domain name system DNS client subnet option, or the IP address information is a local DNS server address.
Owner:HUAWEI TECH CO LTD

A method and electronic device for accessing the network

This application provides a method and electronic device for accessing a network. In this method, the electronic device stores M sets of domain name information in a first file. The M sets of domain name information include a first domain name and its corresponding first IP address, where M is a positive integer. The device periodically requests the current IP addresses of the M domain names from a Domain Name System (DNS) server. After receiving the current IP addresses of the M domain names, the device replaces the initial IP addresses corresponding to the M domain names with their current IP addresses. When a first application requests access to the server corresponding to the first domain name, the device queries the first file for the IP address corresponding to the first domain name to obtain a second IP address. The device then accesses the server corresponding to the first domain name based on the second IP address. This method can improve the speed of network access.
Owner:HONOR DEVICE CO LTD

Data detection method and related device

The embodiment of the invention provides a data detection method and a related device, and the method comprises the steps: mapping collected domain name system data to a virtual table, and generating a temporary analysis view; detecting the domain name system data in the temporary analysis view based on a time constraint condition and a node aggregation query rule, and determining abnormal nodes in the domain name system data; and for each piece of domain name system data, determining a data detection result based on the type of the abnormal node and the proportion of each type of abnormal node in the total node. According to the method, the dynamic threshold algorithm based on the proportion is introduced, and the data detection result is determined based on the types of the abnormal nodes and the proportion of each type of abnormal nodes in the total node, so that false alarm and missing alarm caused by abnormity or short-term fluctuation of a single node can be effectively reduced, and the detection accuracy is improved.
Owner:CHINA INTERNET NETWORK INFORMATION CENTER

Multi-source fusion log compression method and device for anomaly detection

ActiveCN119420534BBridging the Semantic Gapreduce dependenceSecuring communicationDomain nameAlgorithm
This application discloses a multi-source fusion log compression method and apparatus for anomaly detection, belonging to the field of anomaly detection technology. The multi-source fusion log compression method for anomaly detection includes: generating an audit origination graph corresponding to the system audit log, an application origination graph corresponding to the application log, and a domain name origination graph corresponding to the domain name system log based on the system audit log corresponding to the electronic device, the application log corresponding to the target application in the electronic device, and the domain name system log corresponding to the electronic device; fusing the domain name origination graph into the application origination graph based on the domain name nodes in the application origination graph to obtain a sub-fused origination graph; fusing the audit origination graph into the sub-fused origination graph based on the event nodes in the audit origination graph to obtain a fused origination graph; and performing anomaly detection based on the fused origination graph. The multi-source fusion log compression method for anomaly detection in this application can alleviate the problems of semantic gap and dependency explosion.
Owner:INST OF ADVANCED TECH UNIV OF SCI & TECH OF CHINA

Data protection in cloud data platform

A system is disclosed comprising a memory containing instructions and one or more computer processors. When the instructions are executed, the system performs an operation to configure a Domain Name System (DNS) proxy, executing in a node of a cloud data platform associated with a first account, to perform hostname resolution of an Account Host Identifier (AHID) of the first account. The DNS proxy receives a DNS request from a process executing in a pod of the node, and the system fails to resolve the DNS request if the name in the DNS request differs from the AHID of the first account. The system returns an Internet Protocol (IP) address if the name in the DNS request matches the AHID. The process executing in the pod of the node is configured to send data to data storage of the cloud data platform using the returned IP address.
Owner:SNOWFLAKE INC

Automatic detection of application programming interface (API) attack surfaces

Various embodiments facilitate uncovering an Application Programming Interface (API) attack surface for an organization. In some examples, an apparatus comprises storage media, a processing system, and program instructions stored on the storage media. The apparatus processes Domain Name System (DNS) data to determine a set of possible API servers. The apparatus determines a set of possible Uniform Resource Identifier (URI) paths that may lead to one or more actual API endpoints. The apparatus joins the set of possible API servers with the set of possible URI paths to generate a set of possible API Uniform Resource Locators (URLs). The apparatus performs an API-specific crawl of the set of possible API URLs by submitting API requests to the set of possible API URLs and analyzing responses to determine the one or more actual API endpoints and one or more actual API servers of the set of possible API servers.
Owner:CEQUENCE SECURITY INC

Validation of alignment of wireless and wireline network function configuration with domain name system records

Techniques for validating alignment between network element configuration and DNS records associated with a communication network are presented. Alignment management component (AMC) can retrieve respective configuration parameter data items relating to respective configuration parameters associated with respective resource-related identifiers, and respective metadata items associated with the respective resource-related identifiers, from a configuration data store; and retrieve respective DNS records from respective DNS name servers, based on analyzing the respective metadata items associated with respective DNS records. For each resource-related identifier that is supposed to have a corresponding DNS record, based on the result of analyzing the respective configuration parameter data items and respective DNS records, AMC can determine whether the resource-related identifier has a corresponding DNS record stored in the DNS name server indicated by the metadata item. AMC can generate an audit report comprising a missing DNS record data item for each DNS record determined to be missing.
Owner:AT&T INTELLECTUAL PROPERTY I L P

A CDN-based three-dimensional asset distribution method, device, equipment and medium

The application relates to the technical field of three-dimensional assets, and provides a three-dimensional asset distribution method and device based on a CDN, equipment and a medium. The three-dimensional asset distribution method comprises the following steps: receiving an access request sent by a user equipment; returning attribute information of a target three-dimensional asset to the user equipment according to identification information of the target three-dimensional asset; resolving a domain name system, and determining a target edge server closest to the user equipment according to a resolution result; receiving a final encryption string of the user equipment sent by the user equipment; the final encryption string is obtained through multiple encryption processes of the user equipment based on the attribute information of the target three-dimensional asset and a sending time of the access request; authenticating the final encryption string, and distributing the target three-dimensional asset to the user equipment through the target edge server after the authentication is passed. The three-dimensional asset distribution method can improve the distribution efficiency of the three-dimensional asset while improving the privacy of user information.
Owner:湖南芒果融创科技有限公司

Domain name resolution, method, system, apparatus, device and medium for edge computing

The present disclosure relates to the field of edge cloud technology, and discloses a domain name resolution method, a system, an apparatus, a device, and a medium for edge computing. The domain name resolution method includes: acquiring a first domain name resolution request forwarded by a virtual device through a network module; converting the first domain name resolution request into a second domain name resolution request, and sending the second domain name resolution request to an authoritative domain name system; and receiving a resolution result of the second domain name resolution request by the authoritative domain name system, and forwarding the resolution result to the virtual device through the network module.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Method, device, and system for managing domain name resolution

A domain name system DNS resolver may only allow those DNS requests that use an unencrypted communication protocol for domain name resolution by blocking DNS requests that use an encrypted communicati
Owner:CAMBIUM NETWORKS

Data processing method and system

The invention provides a data processing method and system, and relates to the technical field of data processing, and the data processing method comprises the steps: obtaining a network exception time period of a domain name system (DNS); obtaining domain name query information in the network abnormal time period, and determining a white list domain name based on the domain name query information; reading the TTL (Transistor-Transistor Logic) of the white list domain names from the cache server, and grouping the white list domain names in the cache server according to the TTL to obtain one or more groups corresponding to the white list domain names; and in response to the TTL of the group meeting the updating condition, sending an updating request to the recursive server to obtain the latest address information of the white list domain name in the group, and sending the latest address information to the cache server corresponding to the group to update the address information, the technical problem of link congestion caused by simultaneous iterative query of the same domain name in the prior art is solved, and the utilization rate of the server is improved.
Owner:XINYANG BRANCH HENAN CO LTD OF CHINA MOBILE COMM CORP +1

Service access methods, devices, electronic devices and storage media

This application provides a service access method, apparatus, electronic device, and storage medium, comprising: deploying a Domain Name System (DNS) center in a central cluster, and deploying DNS sentinels in a dedicated cluster and the central cluster respectively. The dedicated cluster includes business containers and a cluster DNS system. A communication connection is established between the central cluster and the dedicated cluster through the DNS sentinels. The cluster DNS system determines whether a business container accesses a service container in the central cluster. If a business container accesses a service container in the central cluster, the target service address is obtained through the DNS center, and the service corresponding to the target service address in the service container is accessed based on the target service address. This application, by deploying a DNS center and DNS sentinels in both the central and dedicated clusters, and utilizing the DNS sentinels to establish a link between the central and dedicated clusters, enables cross-Kubernetes cluster service access in business deployment scenarios.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Method and system for packaging development machine in K8S cluster

The invention relates to a development machine packaging method and system in a K8S cluster, which is characterized in that development machine resources are defined based on CRD and a controller, configuration information is described, and automatic life cycle management is realized in combination with operators; cRD is deployed in a host cluster, and is synchronized to K8S space of each tenant through an exclusive synchronizer; an SSH access path is opened by means of node port type service resources and an exclusive layer 4 forwarding entry; a public network IP path is automatically allocated by using the load balancer type service resources in combination with a metal load balancer component; remote access and safety control of the Zhu service are realized through a gateway, a signature verification mechanism and a domain name system analysis function of list monitoring; and deploying an exclusive daemon process set at each host node.
Owner:BEIJING INBO DIGITAL TECH CO LTD

Method and system for managing discovery of edge application servers

The present disclosure provides a method for managing discovery of an edge application servers. The method includes sending, by an edge enabler client of a UE, an initial service provisioning request to an edge configuration server. Further, the method includes receiving, by the edge enabler client, an initial service provisioning response comprises an information element from the edge configuration server, where the information element indicates the supported discovery mode. Further, the method sending, by the edge enabler client, a request for discovering the edge application server to at least one of the edge configuration server, a dedicated server for an edge application server information, and a Domain Name System (DNS) server based on the supported discovery mode.
Owner:SAMSUNG ELECTRONICS CO LTD

Method and apparatus for attack and defense drill based on programmable switch

The present disclosure provides a programmable switch-based attack and defense drill method and device, and relates to the technical field of network security. The specific implementation scheme is: obtaining a seed domain name system (DNS) query data packet; obtaining address information of a specified DNS server and IP address information of a target host to be verified; updating the seed DNS query data packet according to the address information of the specified DNS server and the IP address information of the target host to be verified; generating a DNS query data packet according to the updated seed DNS query data packet; and generating DNS reflection amplification attack traffic based on the updated seed DNS query data packet and the DNS query data packet, so as to verify the defense system of the target host. The present disclosure can improve the attack traffic generation speed of DNS reflection amplification attack drills while meeting flexibility, and improve the attack efficiency of network security attack and defense drills.
Owner:HUANENG ZHEJIANG ENERGY SALES CO LTD +2

Data flow pushing method and device, equipment, storage medium and program product

The invention provides a method and a device for pushing data, electronic equipment, a computer readable storage medium and a computer program product, and relates to the technical field of artificial intelligence such as streaming media technology, data transmission and cloud service. A specific embodiment of the method comprises the steps of detecting whether a global domain name system configuration file is maintained or not in response to a received data push flow request of a target application; in response to the absence of the global domain name system configuration file, based on the network identity identification instruction, reading domain name system information recorded by the target network identity, and determining a target address; and orienting the to-be-pushed data uploaded by the target application to the target address, and pushing the to-be-pushed data to target equipment indicated by the target application by using a push flow component of the target address. According to the mode, the configuration difficulty and the modification limitation of the domain name system can be reduced, so that the flow pushing platform can complete the analysis of the domain name system in a more flexible and quality manner, and the flow pushing capability of the flow pushing platform is improved.
Owner:GUANGZHOU DULING TECH CO LTD +1

Content recognition method, network device, and computer-readable storage medium

The application provides a content identification method, network equipment and a computer readable storage medium. The method comprises: identifying user access records corresponding to suggestive content according to collected domain name system (DNS) logs; the suggestive content is suspected flow diversion content; determining whether external addresses in the user access records have flow diversion behavior according to the user access records; if it is determined that the external addresses have flow diversion behavior, sending target external addresses having flow diversion behavior to a second device for content review; the second device is a device having a subscription relationship with a first device; and receiving review results sent by the second device. The first device of the application provides flow diversion behavior discovery capability, the second device reviews target external addresses having flow diversion behavior, and through interaction between the first device and the second device, multi-party collaborative governance of bad flow diversion behavior is realized, and the efficiency and accuracy of identifying bad content can be improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Configuring application availability using anycast addressing

Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port / protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.
Owner:PALO ALTO NETWORKS INC