Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

163 results about "Domain Name System" patented technology

The Domain Name System (DNS) is a hierarchical and decentralized naming system for computers, services, or other resources connected to the Internet or a private network. It associates various information with domain names assigned to each of the participating entities. Most prominently, it translates more readily memorized domain names to the numerical IP addresses needed for locating and identifying computer services and devices with the underlying network protocols. By providing a worldwide, distributed directory service, the Domain Name System has been an essential component of the functionality of the Internet since 1985.

Multi-modal attack identification method fusing BMama and difference to guide trans-attention

PendingCN121333666ABiological modelsSecuring communicationAddress Resolution ProtocolDomain name
The invention discloses a multi-modal attack identification method fusing BMama and difference to guide trans-attention, which comprises the following steps: simulating a false data injection attack, a denial of service attack, an address resolution protocol spoofing attack and a domain name system spoofing attack, collecting physical layer sensor data and network layer flow data, and preprocessing multi-modal data; bMama is constructed to perform dynamic time modeling on multi-modal data, a graph neural network is combined to adversariate a variational auto-encoder, features of a power grid system topology and a communication topology structure are fused, and robustness of potential representation is enhanced through adversarial training; the method comprises the following steps of: guiding feature complementary fusion by using modal difference through a difference guide iteration cross-attention fusion mechanism, improving the capability of distinguishing complex attacks, finally carrying out attack detection and classification on fused modals, and executing end-to-end optimization according to a weighted combination of loss of each part. The method can effectively detect and classify the multi-modal attack in the smart power grid, and enhances the safety and reliability of a complex system.
Owner:SOUTHEAST UNIV

Methods and systems for prevention of attacks associated with the domain name system

The attack vectors for some denial-of-service cyber attacks on the Internet's Domain Name System (DNS) are bad, bogus, or unregistered domain name DNS requests to resolve domain names that are not registered in the DNS. Some other cyber attacks steal sensitive data by encoding the data in bogus domain names, or domain names otherwise not registered in the DNS, that are transferred across networks in bogus DNS requests. A DNS gatekeeper may filter in-transit packets containing DNS requests and may efficiently determine if a request's domain name is registered in the DNS. When the domain name is not registered in the DNS, the DNS gatekeeper may take one of a plurality of protective actions. The DNS gatekeeper drops requests determined not to be legitimate, which may prevent an attack.
Owner:CENTRIPETAL NETWORKS INC

Method and apparatus for selecting edge application server, and network element device, user equipment and storage medium

The present disclosure relates to method and apparatus for selecting an edge application server, and element network device, user equipment and storage medium. The method includes: a user equipment receiving first indication information, which is sent by an SMF, wherein the first indication information is used for indicating the priority of domain name system (DNS) information; and the user equipment making a DNS policy decision according to the first indication information, and sending a DNS query request to an EASDF, wherein the DNS query request is used by the EASDF to execute the discovery or selection of an edge application server (EAS).
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Inline detect and block relayed DNS tunneling traffic

The present application discloses a method, system, and computer system for detecting DNS tunneling traffic. The method includes (i) obtaining non-DNS network traffic across an enterprise network, (ii) obtaining a hostname comprised in the non-DNS network traffic, (iii) querying a security service for a Domain Name System (DNS) tunneling attack verdict based at least in part on the hostname, (iv) determining whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict, and (v) handling the non-DNS network traffic based at least in part on a determination of whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict.
Owner:PALO ALTO NETWORKS INC

DNS security operation center insights

PCT designated stageWO2026024337A9Digital data protectionInternal/peripheral component protectionDomain nameSecurity operations center
Various techniques for DNS security operations center insights are disclosed. In some embodiments, a system / process / computer program product for DNS security operations center insights includes collecting Domain Name System (DNS) security associated events; generating a plurality of insights based on the collected DNS security associated events; and performing an action based on one or more of the insights.
Owner:INFOBLOX INC

Printer configuration webpage access method based on USB-to-network conversion

ActiveCN116723173BImprove user experienceSimplify the process of configuring web accessTransmissionEnergy efficient computingComputer printingIp address
The application discloses a printer configuration webpage access method based on a USB-to-network port and a printer device, and the method comprises the following steps: controlling a LINUX kernel to load a USB virtual network card driver, allocating an IP address and a subnet mask for a USB port, and generating a virtual network port according to the USB port; performing domain name system configuration processing on the virtual network port, and allocating a slave IP address for a terminal device connected to the USB port according to the IP address and the subnet mask, wherein, the USB port of the printer is simulated into a virtual network port through the USB virtual network card driver, so that the terminal device can obtain the slave IP address allocated by the virtual network port by connecting the USB port, access the network of the printer device through the slave IP address, and access the configuration webpage of the printer device, thereby simply and effectively realizing the printer configuration webpage access, not needing additional hardware devices, and further simplifying the configuration webpage access process and improving the use experience of users.
Owner:JIANGMEN DASCOM COMP PERIPHERAL +1

Traffic control method, device, system, electronic device, and storage medium

This application relates to a flow control method, apparatus, system, electronic device, and storage medium, applied in the field of flow control technology. The method includes: determining an initial policy based on a baseline flow in a target line; using the initial policy as a target policy; sending the target policy to a Domain Name System (DNS) server; sending the target policy to a flow feedback server, so that if the flow feedback server determines that there is a flow anomaly based on the current flow monitoring result corresponding to the node and the target flow, it sends a first flow anomaly result to a policy server; if the first flow anomaly result is received, determining the abnormal node in the target line based on the first flow anomaly result; replacing the abnormal node in the initial policy with the first target node to obtain the target policy, and returning to the step of sending the target policy to the DNS server, until there is no flow anomaly. This application can improve the accuracy of flow control by the DNS server.
Owner:BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD

A method and electronic device for accessing the network

This application provides a method and electronic device for accessing a network. In this method, the electronic device stores M sets of domain name information in a first file. The M sets of domain name information include a first domain name and its corresponding first IP address, where M is a positive integer. The device periodically requests the current IP addresses of the M domain names from a Domain Name System (DNS) server. After receiving the current IP addresses of the M domain names, the device replaces the initial IP addresses corresponding to the M domain names with their current IP addresses. When a first application requests access to the server corresponding to the first domain name, the device queries the first file for the IP address corresponding to the first domain name to obtain a second IP address. The device then accesses the server corresponding to the first domain name based on the second IP address. This method can improve the speed of network access.
Owner:HONOR DEVICE CO LTD

Data detection method and related device

The embodiment of the invention provides a data detection method and a related device, and the method comprises the steps: mapping collected domain name system data to a virtual table, and generating a temporary analysis view; detecting the domain name system data in the temporary analysis view based on a time constraint condition and a node aggregation query rule, and determining abnormal nodes in the domain name system data; and for each piece of domain name system data, determining a data detection result based on the type of the abnormal node and the proportion of each type of abnormal node in the total node. According to the method, the dynamic threshold algorithm based on the proportion is introduced, and the data detection result is determined based on the types of the abnormal nodes and the proportion of each type of abnormal nodes in the total node, so that false alarm and missing alarm caused by abnormity or short-term fluctuation of a single node can be effectively reduced, and the detection accuracy is improved.
Owner:CHINA INTERNET NETWORK INFORMATION CENTER

Multi-source fusion log compression method and device for anomaly detection

ActiveCN119420534BBridging the Semantic Gapreduce dependenceSecuring communicationDomain nameAlgorithm
This application discloses a multi-source fusion log compression method and apparatus for anomaly detection, belonging to the field of anomaly detection technology. The multi-source fusion log compression method for anomaly detection includes: generating an audit origination graph corresponding to the system audit log, an application origination graph corresponding to the application log, and a domain name origination graph corresponding to the domain name system log based on the system audit log corresponding to the electronic device, the application log corresponding to the target application in the electronic device, and the domain name system log corresponding to the electronic device; fusing the domain name origination graph into the application origination graph based on the domain name nodes in the application origination graph to obtain a sub-fused origination graph; fusing the audit origination graph into the sub-fused origination graph based on the event nodes in the audit origination graph to obtain a fused origination graph; and performing anomaly detection based on the fused origination graph. The multi-source fusion log compression method for anomaly detection in this application can alleviate the problems of semantic gap and dependency explosion.
Owner:INST OF ADVANCED TECH UNIV OF SCI & TECH OF CHINA

Data protection in cloud data platform

A system is disclosed comprising a memory containing instructions and one or more computer processors. When the instructions are executed, the system performs an operation to configure a Domain Name System (DNS) proxy, executing in a node of a cloud data platform associated with a first account, to perform hostname resolution of an Account Host Identifier (AHID) of the first account. The DNS proxy receives a DNS request from a process executing in a pod of the node, and the system fails to resolve the DNS request if the name in the DNS request differs from the AHID of the first account. The system returns an Internet Protocol (IP) address if the name in the DNS request matches the AHID. The process executing in the pod of the node is configured to send data to data storage of the cloud data platform using the returned IP address.
Owner:SNOWFLAKE INC

Automatic detection of application programming interface (API) attack surfaces

Various embodiments facilitate uncovering an Application Programming Interface (API) attack surface for an organization. In some examples, an apparatus comprises storage media, a processing system, and program instructions stored on the storage media. The apparatus processes Domain Name System (DNS) data to determine a set of possible API servers. The apparatus determines a set of possible Uniform Resource Identifier (URI) paths that may lead to one or more actual API endpoints. The apparatus joins the set of possible API servers with the set of possible URI paths to generate a set of possible API Uniform Resource Locators (URLs). The apparatus performs an API-specific crawl of the set of possible API URLs by submitting API requests to the set of possible API URLs and analyzing responses to determine the one or more actual API endpoints and one or more actual API servers of the set of possible API servers.
Owner:CEQUENCE SECURITY INC

Domain name resolution, method, system, apparatus, device and medium for edge computing

The present disclosure relates to the field of edge cloud technology, and discloses a domain name resolution method, a system, an apparatus, a device, and a medium for edge computing. The domain name resolution method includes: acquiring a first domain name resolution request forwarded by a virtual device through a network module; converting the first domain name resolution request into a second domain name resolution request, and sending the second domain name resolution request to an authoritative domain name system; and receiving a resolution result of the second domain name resolution request by the authoritative domain name system, and forwarding the resolution result to the virtual device through the network module.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Method, device, and system for managing domain name resolution

PendingGB2700665ATransmissionDomain nameAdministrative domain
A domain name system DNS resolver may only allow those DNS requests that use an unencrypted communication protocol for domain name resolution by blocking DNS requests that use an encrypted communicati
Owner:CAMBIUM NETWORKS

Method and system for packaging development machine in K8S cluster

The invention relates to a development machine packaging method and system in a K8S cluster, which is characterized in that development machine resources are defined based on CRD and a controller, configuration information is described, and automatic life cycle management is realized in combination with operators; cRD is deployed in a host cluster, and is synchronized to K8S space of each tenant through an exclusive synchronizer; an SSH access path is opened by means of node port type service resources and an exclusive layer 4 forwarding entry; a public network IP path is automatically allocated by using the load balancer type service resources in combination with a metal load balancer component; remote access and safety control of the Zhu service are realized through a gateway, a signature verification mechanism and a domain name system analysis function of list monitoring; and deploying an exclusive daemon process set at each host node.
Owner:BEIJING INBO DIGITAL TECH CO LTD

Method and apparatus for attack and defense drill based on programmable switch

The present disclosure provides a programmable switch-based attack and defense drill method and device, and relates to the technical field of network security. The specific implementation scheme is: obtaining a seed domain name system (DNS) query data packet; obtaining address information of a specified DNS server and IP address information of a target host to be verified; updating the seed DNS query data packet according to the address information of the specified DNS server and the IP address information of the target host to be verified; generating a DNS query data packet according to the updated seed DNS query data packet; and generating DNS reflection amplification attack traffic based on the updated seed DNS query data packet and the DNS query data packet, so as to verify the defense system of the target host. The present disclosure can improve the attack traffic generation speed of DNS reflection amplification attack drills while meeting flexibility, and improve the attack efficiency of network security attack and defense drills.
Owner:HUANENG ZHEJIANG ENERGY SALES CO LTD +2

Content recognition method, network device, and computer-readable storage medium

The application provides a content identification method, network equipment and a computer readable storage medium. The method comprises: identifying user access records corresponding to suggestive content according to collected domain name system (DNS) logs; the suggestive content is suspected flow diversion content; determining whether external addresses in the user access records have flow diversion behavior according to the user access records; if it is determined that the external addresses have flow diversion behavior, sending target external addresses having flow diversion behavior to a second device for content review; the second device is a device having a subscription relationship with a first device; and receiving review results sent by the second device. The first device of the application provides flow diversion behavior discovery capability, the second device reviews target external addresses having flow diversion behavior, and through interaction between the first device and the second device, multi-party collaborative governance of bad flow diversion behavior is realized, and the efficiency and accuracy of identifying bad content can be improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Configuring application availability using anycast addressing

Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port / protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.
Owner:PALO ALTO NETWORKS INC

Communication methods and communication devices

This application provides a communication method and a communication device. The method includes the following: A first network element receives a first query message from a terminal, the first query message includes information about a first domain name, the first domain name is not authorized in the terminal's visited network, the first network element is a network element within the terminal's visited network, the first network element sends a second query message to a domain name system server based on the first query message, the second query message includes information about the first domain name and information about the terminal's home network, the home network information is used to determine the address of the application server, and the first network element receives the address of the application server from a DNS server. This avoids the problem where a terminal cannot access a service corresponding to a domain name because the domain name is not authorized in the visited network, and improves the quality of the terminal's communication service.
Owner:HUAWEI TECH CO LTD

Systems and methods for mitigating domain name system amplification attacks

Systems and methods for mitigating DNS amplification attacks are provided. In one example, a threat intelligence system collects data about the requests received by a DNS server, and / or responses generated by the DNS server. The threat intelligence system triggers a threat mitigation action upon detecting evidence (in one or more forms) of a DNS amplification attack. The threat mitigation action may include filtering DNS responses generated by the DNS server. The filtering rule may indicate that a DNS response in which the payload size is above a threshold payload size is to be dropped. In examples, the payload threshold size is dynamically set by the threat intelligence system using a machine learning model to minimize the filtering of DNS responses for valid DNS queries, while maximizing filtering of DNS responses for malicious DNS queries.
Owner:CENTURYLINK INTELLECTUAL PROPERTY LLC

A wireless communication method, platform, device and storage medium

The application discloses a wireless communication method, a wireless communication platform, an electronic device and a computer readable storage medium, receiving first DNS configuration information associated with a first application network element sent by an edge computing server; the first DNS configuration information comprises at least one of a data network address, an application network element service identifier, a data network access identifier, a fully qualified domain name, a service filtering identifier and domain name system information; configuring the first DNS configuration information for a to-be-configured network element associated with the first application network element in a core network device, and sending DNS feedback information to the edge computing server; the DNS feedback information is used for indicating that the to-be-configured network element is successfully configured, or indicating that the to-be-configured network element fails to be configured. In this way, it is ensured that a terminal device can access services carried on the edge computing server through local DNS services.
Owner:CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1

Access method of application server, chip module, terminal and storage medium

The embodiment of the present specification provides an application server access method, a chip module, a terminal and a storage medium, and relates to the technical field of communication. The application server access method comprises the following steps: detecting that a first domain name is accessed for a target application; sending a first domain name resolution request to a domain name system server, so as to request a plurality of first IPv4 addresses and a plurality of first IPv6 addresses corresponding to the first domain name; sending a first connection request to the application server, wherein the first connection request comprises a first target IPv6 address in the plurality of first IPv6 addresses; in response to the network quality being lower than a set quality level when the application server is accessed based on the first target IPv6 address, and detecting that the target application accesses the first domain name again; sending a second domain name resolution request to the domain name system server, so as to request a plurality of second IPv4 addresses and a plurality of second IPv6 addresses corresponding to the first domain name; and sending a second connection request to the application server, wherein the second connection request comprises a second target IPv6 address in the plurality of second IPv6 addresses.
Owner:HUAWEI TECH CO LTD

Device anomaly detection based on DNS queries

PCT designated stageWO2026049806A1TransmissionDomain nameNetwork activity
Techniques for providing device anomaly detection based on DNS queries are disclosed. In some embodiments, a system, a process, and / or a computer program product for device anomaly detection based on DNS queries includes receiving Domain Name System (DNS) network activity, wherein the DNS network activity includes a plurality of DNS queries; processing the DNS network activity to generate a plurality of metrics; and automatically detecting anomalies associated with one or more devices for a monitored network.
Owner:INFOBLOX INC

Domain name system resolution record processing method and apparatus, and electronic device

PCT designated stageWO2026016731A1TransmissionDomain nameIp address
The present application relates to the technical field of data processing, and discloses a domain name system (DNS) resolution record processing method and apparatus, and an electronic device. The method comprises: a resolution record distribution system performs data sharding on a plurality of DNS resolution records according to a subdomain name dimension to obtain a plurality of sharded DNS resolution records, wherein the sharded DNS resolution records are used for recording a mapping relationship between domain name information in a DNS and an IP address; and the resolution record distribution system distributes the plurality of sharded DNS resolution records to a resolution node of the DNS. The present application solves the technical problem in the related art of the low efficiency in DNS resolution record distribution caused by using zone dimension-based data sharding to implement DNS resolution record distribution.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1

Domain name system resolution record processing method and device and electronic equipment

The invention discloses a domain name system resolution record processing method and device and electronic equipment. Relates to the technical field of data processing, and the method comprises the following steps: carrying out data fragmentation on a plurality of domain name system resolution records according to sub-domain name dimensions through a resolution record distribution system to obtain a plurality of fragmented domain name system resolution records, the fragmented domain name system analysis record is used for recording a mapping relation between domain name information and an IP address in a domain name system; and distributing the plurality of fragment domain name system analysis records to an analysis node of the domain name system through the analysis record distribution system. According to the method and the device, the technical problem that the issuing efficiency of the DNS resolution record is relatively low due to the fact that the DNS resolution record is issued in a mode of performing data fragmentation according to the zone dimension in the related technology is solved.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

Organizing distribution of DNS information in a computer network

PCT designated stageWO2026002553A1TransmissionDomain nameComputer network
The invention relates to a method of organizing distribution of information related to a domain name system, DNS, in a computer network, the method comprising, by a first node of the computer network: performing a container-based execution of a first instance of a software application, thereby aggregating DNS information specific to the software application; generating a DNS message indicative of the DNS information; and transmitting the DNS message to a second node of the computer network for usage of the DNS information by a container-based execution of a second instance of the software application.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +1

A domain name resolution method suitable for mobile target defense

ActiveCN116471594BTransmissionSecurity arrangementDomain nameInternet network
The application discloses a domain name resolution method suitable for mobile target defense, and comprises the following steps: 1) a domain name system continuous updating device random address flow; 2) an identity authentication-oriented key negotiation flow; 3) a network device identity authentication flow; 4) a network device random address obtaining flow of a communication opposite end device; and 5) a network communication flow. The method can realize convenient authentication and security protection of internet devices, and help to improve the security of next-generation internet devices on the basis of guaranteeing the security of the internet.
Owner:GUILIN UNIV OF ELECTRONIC TECH

DNS Request Obfuscation

DNS request obfuscation includes generating decoy Domain Name System (DNS) requests to obfuscate DNS request activity processed by the organization's private DNS server, sending the decoy DNS requests to an external DNS server for resolution, receiving DNS requests for DNS lookups on behalf of client devices, sending the DNS requests to an external DNS server of the external DNS server interspersed with at least some of the generated decoy DNS requests sent to the external DNS server, receiving DNS responses to the sent DNS requests from the external DNS server, and providing the DNS responses to the source of the DNS requests (Figure 3).
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Communication method and device, equipment, storage medium and program product

The invention discloses a communication method and device, equipment, a storage medium and a program product. The method comprises the following steps: sending at least one of the following items to a second network function: first information and at least one full domain name; the first information is used for instructing the second network function to cache domain name system response information, and / or the first information is used for instructing the second network function to report the domain name system response information, and / or the first information is used for instructing the second network function to report the domain name system response information. The first information is used for indicating a first full domain name and / or an edge application server address in the second network function report domain name system response information; according to the invention, the discovery of the N6 time delay sensitive service and the L-PSA selection can be processed in a C scene (that is, the discovery of the N6 time delay sensitive service and the selection of a local PDU session anchor point may need to be processed because the EASDF does not exist in the local service discovery, such as the discovery of the local service using a local DNS server).
Owner:CHINA MOBILE COMM LTD RES INST +1

A MQTT-based device connection method, device, apparatus and medium

The application discloses an MQTT-based device connection method and device, equipment and medium, relates to the technical field of Internet communication, and the method is applied to a device end and comprises the following steps: loading device identity configuration information; adopting a hierarchical domain name system resolution strategy to resolve access point information and acquiring a target connection address; initiating an MQTT connection request and completing authentication through an encrypted channel; if the connection fails, switching to a standby access point to repeat the resolution and connection processes; after the connection is established, directing message transmission based on a set topic format, realizing request and response interaction through a message association mechanism, and completing timeout control by using an MQTT delay message. The scheme improves the device connection speed, stability and interaction reliability, guarantees communication safety, and adapts to the multi-scene requirements of Internet of Things.
Owner:SHENZHEN LINGDECHUANG TECH CO LTD