Cisco Systems, Inc.
Identifying and using DNS contextual flows

Last updated:

Abstract:

In one embodiment, a device in a network captures domain name system (DNS) response data from a DNS response sent by a DNS service to a client in the network. The device captures session data for an encrypted session of the client. The device makes a determination that the encrypted session is malicious by using the captured DNS response data and the captured session data as input to a machine learning-based or rule-based classifier. The device performs a mediation action in response to the determination that the encrypted session is malicious.

Status:
Grant
Type:

Utility

Filling date:

31 Oct 2019

Issue date:

12 Apr 2022