Palo Alto Networks, Inc.
REAL-TIME DETECTION OF DNS TUNNELING TRAFFIC

Last updated:

Abstract:

Detection of DNS tunneling traffic is disclosed. A DNS query comprising a subdomain portion and a root domain portion is received from a client device. A determination is made that the root domain portion received in the DNS query is associated with a malicious DNS tunneling root domain. A remedial action is taken in response to the determining.

Status:
Application
Type:

Utility

Filling date:

24 Feb 2020

Issue date:

26 Aug 2021