Cisco Systems, Inc.
Identifying and using DNS contextual flows
Last updated:
Abstract:
In one embodiment, a device in a network captures domain name system (DNS) response data from a DNS response sent by a DNS service to a client in the network. The device captures session data for an encrypted session of the client. The device makes a determination that the encrypted session is malicious by using the captured DNS response data and the captured session data as input to a machine learning-based or rule-based classifier. The device performs a mediation action in response to the determination that the encrypted session is malicious.
Status:
Grant
Type:
Utility
Filling date:
31 Oct 2019
Issue date:
12 Apr 2022