Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

369 results about "Domain Name System" patented technology

The Domain Name System (DNS) is a hierarchical and decentralized naming system for computers, services, or other resources connected to the Internet or a private network. It associates various information with domain names assigned to each of the participating entities. Most prominently, it translates more readily memorized domain names to the numerical IP addresses needed for locating and identifying computer services and devices with the underlying network protocols. By providing a worldwide, distributed directory service, the Domain Name System has been an essential component of the functionality of the Internet since 1985.

Route selection method and apparatus for edge application server, communication device and storage medium

A route selection method for an Edge Application Server (EAS) is provided, the method is performed by a terminal, and includes: receiving a Domain Name System (DNS) information indication sent by a first network function; executing a DNS policy decision based on the DNS information indication; and sending a DNS query request to a second network function based on the decision, where the DNS query request is used to request the second network function to select an EAS.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

DevOps-oriented containerized test environment deployment system and method

The invention relates to a DevOps-oriented containerized test environment deployment system and method, and belongs to the technical field of Internet. A multi-service test environment is defined through a YAML file, environment variables are managed in combination with an. Env configuration file, dependency is optimized through dependency layering and a cache library, a container mirror image is constructed, and a container cluster is started; managing multiple tasks through a centralized scheduling architecture, and realizing resource isolation of a container cluster by using Cgroup; adjusting the number of container instances in real time based on a capacity expansion and contraction mechanism; a bridging network is used for automatically distributing a container IP, a built-in domain name system analyzes a service name dynamic discovery service, and rapid reconstruction of a containerized test environment is achieved. According to the method, a YAML and environment variable separation mechanism is adopted, real-time loading of development, testing and production environment configuration is supported, the deployment time is shortened to the second level, the resource utilization rate is increased to 90% from 60%, the multi-service communication difference is eliminated, and efficient interconnection between containers is ensured.
Owner:ZHEJIANG UNIV

Multi-modal attack identification method fusing BMama and difference to guide trans-attention

The invention discloses a multi-modal attack identification method fusing BMama and difference to guide trans-attention, which comprises the following steps: simulating a false data injection attack, a denial of service attack, an address resolution protocol spoofing attack and a domain name system spoofing attack, collecting physical layer sensor data and network layer flow data, and preprocessing multi-modal data; bMama is constructed to perform dynamic time modeling on multi-modal data, a graph neural network is combined to adversariate a variational auto-encoder, features of a power grid system topology and a communication topology structure are fused, and robustness of potential representation is enhanced through adversarial training; the method comprises the following steps of: guiding feature complementary fusion by using modal difference through a difference guide iteration cross-attention fusion mechanism, improving the capability of distinguishing complex attacks, finally carrying out attack detection and classification on fused modals, and executing end-to-end optimization according to a weighted combination of loss of each part. The method can effectively detect and classify the multi-modal attack in the smart power grid, and enhances the safety and reliability of a complex system.
Owner:SOUTHEAST UNIV

DNS configuration provisioning

Method and apparatus for improvement of DNS configuration for applications are disclosed. A method performed at a server comprises generating Domain Name System (DNS) information; deciding whether to transmit the DNS information to a User Equipment (UE) or to a network or to both the UE and the network; and transmitting the DNS information for use with at least one application associated with the UE according to the decision.
Owner:LENOVO (BEIJING) LTD

Real user monitoring statistics from end users

Systems and methods for implemented by a user device for Real User Monitoring (RUM) include operating an add on for a web browser; receiving a list of domains or Uniform Resource Locators (URLs) to calculate RUM data thereon; responsive to the web browser accessing any of the domains or URLs in the list, calculating and storing RUM data; and periodically sending the stored RUM data to a cloud-based system. The RUM data can include statistics, metrics, and errors that are detected based on any of start of navigation, redirects, Domain Name System (DBS), connection establishment and teardown, Hypertext Transfer Protocol (HTTP) request and response start and end, Document Object Model (DOM) load time, page load time, and Java Script and AJAX error detection.
Owner:ZSCALER INC

Provisioning applications with mobile network provided DNS settings

The present disclosure relates to Edge Computing enhancements by provisioning applications with mobile network provided Domain Name System (DNS) settings. In one embodiment, a method performed by a User Equipment (UE), which supports an Edge Application Server (EAS) discovery procedure with an Edge Application Server Discovery Function (EASDF), includes receiving a DNS setting provided by a mobile network, and storing a first copy of the DNS setting provided by the mobile network as a first DNS setting and a second copy of the DNS setting provided by the mobile network. Herein, the stored first DNS setting is not impacted by any changes made to the second copy of the DNS setting provided by the mobile network.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Methods and systems for prevention of attacks associated with the domain name system

The attack vectors for some denial-of-service cyber attacks on the Internet's Domain Name System (DNS) are bad, bogus, or unregistered domain name DNS requests to resolve domain names that are not registered in the DNS. Some other cyber attacks steal sensitive data by encoding the data in bogus domain names, or domain names otherwise not registered in the DNS, that are transferred across networks in bogus DNS requests. A DNS gatekeeper may filter in-transit packets containing DNS requests and may efficiently determine if a request's domain name is registered in the DNS. When the domain name is not registered in the DNS, the DNS gatekeeper may take one of a plurality of protective actions. The DNS gatekeeper drops requests determined not to be legitimate, which may prevent an attack.
Owner:CENTRIPETAL NETWORKS INC

Cybersecurity based on domain name system protocol processing

In response to intercepting (106), by a customer-premises equipment, CPE, a connection request from a connected device to an external encrypted domain name system, DNS, server, blocking (108), by the CPE, the connection request to cause the connected device to fall back to a use of an unencrypted DNS. And, in response to intercepting (110), by the CPE, an unencrypted DNS query from the connected device, performing (124), by the CPE, a cybersecurity operation related to the unencrypted DNS query.
Owner:CUJO LLC

Software defined network (SDN)- based domain name system (DNS) resolution for a non-SDN service

The present disclosure relates generally to an SDN providing DNS resolution for a non-SDN service. In particular, the SDN hosts a first endpoint communicatively coupled with the non-SDN service. The SDN also hosts a DNS proxy in support of a second private network of a customer. A second endpoint of the customer can be accessible via the second private network The non-SDN service can send a DNS resolution request (that includes, for example, an FQDN of the second endpoint) to the first endpoint. The first endpoint forwards this request to the DNS proxy. In turn, the DNS proxy determines the IP address of the second endpoint and returns a reserved IP address corresponding to the DNS proxy and mapped to the second endpoint's IP address. The first endpoint sends this DNS resolution to the non-SDN service that then learns that the FQDN is resolved to the reserved IP address.
Owner:ORACLE INT CORP

Configuring application availability using anycast addressing

Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port / protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.
Owner:PALO ALTO NETWORKS INC

System and method for leak prevention for domain name system requests

Embodiments of systems and methods for DNS leak prevention and protection are disclosed herein. In particular, certain embodiments include a local DNS protection agent installed on a system and an associated trusted external DNS protection server. The DNS protection agent prevents DNS leaks from applications on the system such that all DNS requests from the system are confined to requests from the DNS protection agent to the associated DNS protection server. As the DNS leak prevention provided by the DNS protection agent stops applications on the system from circumventing the DNS protection server, all DNS requests originating from the system remain under the control of the DNS protection server and thus desired DNS protection (e.g., as implemented on the DNS protection server) may be maintained. Certain embodiments prevent applications from using certain DNS security protocols, such as DoH and DoT, without going through the DNS protection agent.
Owner:OPEN TEXT CORPORATION

Method and apparatus for selecting edge application server, and network element device, user equipment and storage medium

The present disclosure relates to method and apparatus for selecting an edge application server, and element network device, user equipment and storage medium. The method includes: a user equipment receiving first indication information, which is sent by an SMF, wherein the first indication information is used for indicating the priority of domain name system (DNS) information; and the user equipment making a DNS policy decision according to the first indication information, and sending a DNS query request to an EASDF, wherein the DNS query request is used by the EASDF to execute the discovery or selection of an edge application server (EAS).
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Communicate DNS zone metadata to dynamic nameserver proxies

Techniques and devices are described for communicating domain name system zone metadata to dynamic nameserver proxies. A method can include signing service receiving a first request for a resource record (RR). The signing service can transmit to a backend unit, a domain name system (DNS) query for information associated with a subdomain. The signing service can receive, from the backend unit of the computing system, a first DNS response comprising the information associated with the subdomain. The signing service can determine whether the information comprises a flagged nameserver record. The signing service can generate a second DNS response, content of the DNS response based at least in part on whether the information associated with the subdomain comprises the flagged nameserver record. The signing service can transmit the second DNS response to the DNS resolver.
Owner:ORACLE INT CORP

System and method for leak prevention for domain name system requests

Embodiments of systems and methods for DNS leak prevention and protection are disclosed herein. In particular, certain embodiments include a local DNS protection agent installed on a system and an associated trusted external DNS protection server. The DNS protection agent prevents DNS leaks from applications on the system such that all DNS requests from the system are confined to requests from the DNS protection agent to the associated DNS protection server. As the DNS leak prevention provided by the DNS protection agent stops applications on the system from circumventing the DNS protection server, all DNS requests originating from the system remain under the control of the DNS protection server and thus desired DNS protection (e.g., as implemented on the DNS protection server) may be maintained. Certain embodiments prevent applications from using certain DNS security protocols, such as DoH and DoT, without going through the DNS protection agent.
Owner:OPEN TEXT CORPORATION

Providing a split-configuration virtual private network

A method in a virtual private network (VPN) environment is disclosed. A user device transmits, to a VPN server before establishment of a VPN connection between the user device and the VPN server, an initiation request to establish the VPN connection. The initiation request includes remote content information indicating remote content that is unavailable in a geographic location of the user device. The user device receives, from the VPN server after establishment of the VPN connection, the remote content based at least in part on a configuration of domain name services (DNS) settings associated with the VPN connection to utilize a remote DNS server that is capable of obtaining the remote content. Various other aspects are contemplated.
Owner:UAB 360 IT

Organizing distribution of DNS information in a computer network

A method of organizing distribution of information related to a domain name system, DNS, in a computer network is provided. The method includes, by a first node of the computer network: performing a container-based execution of a first instance of a software application, thereby aggregating DNS information specific to the software application; generating a DNS message indicative of the DNS information; and transmitting the DNS message to a second node of the computer network for usage of the DNS information by a container-based execution of a second instance of the software application.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Information leakage detection method and device using the same

An information leakage detection method and a device using the same are disclosed. The method includes the following steps. Network connection data of an electronic device is obtained. Log data related to a (domain name system) DNS is extracted from the network connection data. A DNS request in the log data is analyzed to obtain multiple character distribution feature values according to an analysis result. The character distribution feature values reflect a character distribution status of a domain name in the DNS request under different classification rules. A machine learning model determines whether the DNS request is a malicious DNS request according to the character distribution feature values, and the malicious DNS request is used to carry leaked data to a remote host.
Owner:ACER CYBER SECURITY INC

Systems and methods for publishing and using images of DNS zone configurations

Systems and methods for publishing and using images of domain name system (DNS) zone configurations are described. An image file containing a copy of some or all of the DNS records associated with a zone DNS server (e.g., a DNS server for a zone) may be stored in a repository. In response to detecting that the zone DNS server is unavailable, an image server system retrieves the image file and stores the image file in an image DNS server. The image server system notifies a higher-level DNS server that the image DNS server is a DNS server for the zone. In some examples, the image file includes a zone signing key (ZSK) associated with the image DNS server that is signed by a key signing key (KSK) associated with the zone DNS server. The image DNS server uses the signed ZSK to sign DNS records for subsequent authentication.
Owner:CENTURYLINK INTELLECTUAL PROPERTY LLC

Automated delegation of domain name system (DNS) configuration operations by hosted zones

PendingUS20250233844A1TransmissionDomain nameRecordset
This disclosure describes example techniques for automatically configuring domain name system (DNS) servers to handle custom hostnames assigned to hosted zones. The techniques monitor DNS record sets of the hosted zones for special DNS records registering new hostnames. When such a special DNS record is detected, the central DNS server checks a database to see if that hostname is already assigned to another hosted zone. If the hostname is not assigned to another hosted zone, the central DNS server automatically updates its own DNS configuration data pair the new hostname with the Internet Protocol (IP) address of the hosted zone requesting the hostname. This allows the central DNS server to resolve future DNS queries for the new hostname by routing requests to the proper zone.
Owner:STATE FARM MUTAL AUTOMOBILE INSURANCE COMPANY

Arrangement and a method of threat prevention in a computer or computer network

A computer-implemented method, system, and computer-readable medium for threat detection in a computer or computer network are disclosed, comprising collecting DNS (Domain Name System) queries and / or information relating to DNS queries, identifying failed queries from the collected DNS queries and / or from information relating to DNS queries, and determining whether a domain related to the failed DNS query is related to an expired and / or unregistered domain, e.g. from a domain name related database.
Owner:F SECURE CORP

Enterprise asset classification model training method and device

The invention provides an enterprise asset classification model training method and device, is applied to the technical field of data processing, and is used for improving the accuracy of enterprise asset classification. The method comprises the following steps: constructing a first knowledge graph according to website data and domain name system data of each enterprise in a plurality of enterprises; obtaining at least one path corresponding to any enterprise from the first knowledge graph, and inputting each path into an enterprise asset classification model for prediction; obtaining a predicted value of the enterprise asset classification model for each edge in each path, and calculating a first loss value between the predicted value of each edge and the true value of each edge; obtaining a predicted value of the enterprise asset classification model for each sub-path in each path, and calculating a second loss value between the predicted value of each sub-path and the true value of each sub-path; and obtaining a total loss value according to the first loss value and the second loss value, and adjusting parameters of the enterprise asset classification model with the purpose that the total loss value is smaller than a first threshold value.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Strategically aged domain detection

Detection of strategically aged domains is detected. A list of aged dormant domains is determined, including by evaluating passive Domain Name System (DNS) information. The list of aged dormant domains is monitored for a change by an aged dormant domain from a dormant domain status to an active status. In response to determining the change to active status of the aged dormant domain, an action is taken with respect to the aged dormant domain.
Owner:PALO ALTO NETWORKS INC

Cybersecurity based on domain name system protocol processing

In response to intercepting, by a customer-premises equipment (CPE) a connection request from a connected device to an external encrypted domain name system (DNS) server, blocking, by the CPE, the connection request to cause the connected device to fall back to a use of an unencrypted DNS. And, in response to intercepting, by the CPE, an unencrypted DNS query from the connected device, performing, by the CPE, a cybersecurity operation related to the unencrypted DNS query.
Owner:CUJO LLC

Inline detect and block relayed DNS tunneling traffic

The present application discloses a method, system, and computer system for detecting DNS tunneling traffic. The method includes (i) obtaining non-DNS network traffic across an enterprise network, (ii) obtaining a hostname comprised in the non-DNS network traffic, (iii) querying a security service for a Domain Name System (DNS) tunneling attack verdict based at least in part on the hostname, (iv) determining whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict, and (v) handling the non-DNS network traffic based at least in part on a determination of whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict.
Owner:PALO ALTO NETWORKS INC

Configurable in-vehicle network supply method, apparatus and system, and vehicle

The present application relates to the technical field of in-vehicle network communications. Specifically disclosed are a configurable in-vehicle network supply method, apparatus and system, and a vehicle. The method comprises: acquiring a plurality of pre-configured management tables and a network residence state, wherein the plurality of management tables comprise a dialing address management table and a domain name forwarding management table; starting a dialing program, and performing multi-path dialing on the basis of the dialing address management table and the network residence state; and generating a routing table and a domain name system (DNS) mapping table on the basis of the domain name forwarding management table and the multi-path dialing, wherein the DNS mapping table comprises a mapping relationship between a target domain name and an IP address, and the routing table comprises a correspondence between the target domain name and a dialing channel. By means of the method, the configuration of network-supply strategies for controllers of a vehicle is implemented, multi-path dialing, multi-path VLAN and multi-device network supply are supported, and services such as data are distributed on the basis of a target domain name.
Owner:CHONGQING CHANGAN TECH CO LTD

System and method for autonomously fingerprinting and enumerating internet of thing (IoT) devices based on nated IPFIX and DNS traffic

This document describes a system and method for detecting the presence of Internet of Things (IoTs) from network traffic that has undergone a Network Address Translation (NAT) process, i.e., NATed network traffic, regardless of whether the network traffic comprises IP Flow Information Export (IPFIX) type of traffic or Domain Name System (DNS) type of traffic. Such a capability is crucial as the adoption rate of IoTs have increased exponentially over the past few years. In order to protect IoTs from cyber-attacks, one would first have to understand what type of IoTs are being used, and how many / how widely used these IoTs are. Once the IoT landscape has been defined, cyber defenders may then dedicate resources to identify and subsequently address vulnerabilities that may be in these IoTs.
Owner:ENSIGN INFOSECURITY PTE LTD

DNS security operation center insights

PCT designated stageWO2026024337A9Digital data protectionInternal/peripheral component protectionDomain nameSecurity operations center
Various techniques for DNS security operations center insights are disclosed. In some embodiments, a system / process / computer program product for DNS security operations center insights includes collecting Domain Name System (DNS) security associated events; generating a plurality of insights based on the collected DNS security associated events; and performing an action based on one or more of the insights.
Owner:INFOBLOX INC

Printer configuration webpage access method based on USB-to-network conversion

ActiveCN116723173BImprove user experienceSimplify the process of configuring web accessTransmissionEnergy efficient computingComputer printingIp address
The application discloses a printer configuration webpage access method based on a USB-to-network port and a printer device, and the method comprises the following steps: controlling a LINUX kernel to load a USB virtual network card driver, allocating an IP address and a subnet mask for a USB port, and generating a virtual network port according to the USB port; performing domain name system configuration processing on the virtual network port, and allocating a slave IP address for a terminal device connected to the USB port according to the IP address and the subnet mask, wherein, the USB port of the printer is simulated into a virtual network port through the USB virtual network card driver, so that the terminal device can obtain the slave IP address allocated by the virtual network port by connecting the USB port, access the network of the printer device through the slave IP address, and access the configuration webpage of the printer device, thereby simply and effectively realizing the printer configuration webpage access, not needing additional hardware devices, and further simplifying the configuration webpage access process and improving the use experience of users.
Owner:JIANGMEN DASCOM COMP PERIPHERAL +1

Traffic control method, device, system, electronic device, and storage medium

This application relates to a flow control method, apparatus, system, electronic device, and storage medium, applied in the field of flow control technology. The method includes: determining an initial policy based on a baseline flow in a target line; using the initial policy as a target policy; sending the target policy to a Domain Name System (DNS) server; sending the target policy to a flow feedback server, so that if the flow feedback server determines that there is a flow anomaly based on the current flow monitoring result corresponding to the node and the target flow, it sends a first flow anomaly result to a policy server; if the first flow anomaly result is received, determining the abnormal node in the target line based on the first flow anomaly result; replacing the abnormal node in the initial policy with the first target node to obtain the target policy, and returning to the step of sending the target policy to the DNS server, until there is no flow anomaly. This application can improve the accuracy of flow control by the DNS server.
Owner:BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD

Communication method and apparatus

This application provides a communication method and apparatus. The method may include receiving, by a second session management network element in a visited network, from a first session management network element in a home network, indication information, wherein the indication information indicates that traffic routing is allowed in the visited network. The method may further include sending, by the second session management network element and based on the indication information, IP address information of the visited network to a user plane network element in the visited network, wherein the IP address information is information used to determine an extension mechanisms for domain name system DNS client subnet option, or the IP address information is a local DNS server address.
Owner:HUAWEI TECH CO LTD