Palo Alto Networks, Inc.
FINDING MALICIOUS DOMAINS WITH DNS QUERY PATTERN ANALYSIS

Last updated:

Abstract:

Malicious domain finding using DNS query pattern analysis is disclosed. A first DNS query signature and a second DNS query signature are generated, using a set of DNS query records. The first and second DNS query signatures are compared, and the second DNS query signature is identified as malicious based on a detected match between the first and second DNS query signatures.

Status:
Application
Type:

Utility

Filling date:

16 Feb 2021

Issue date:

3 Jun 2021