Zscaler, Inc.
Systems and methods to detect and monitor DNS tunneling

Last updated:

Abstract:

Systems and methods of detecting Domain Name System (DNS) tunnels for monitoring thereof include obtaining data related to DNS traffic between DNS nameservers and clients; determining a score for each DNS nameserver based on the data to characterize DNS queries over a period of time for each DNS nameserver, wherein the score incorporates all DNS queries associated with the associated DNS nameserver over the period of time; determining one or more DNS nameservers likely operating DNS tunnels based on the score; and performing one or more actions on the one or more DNS nameservers related to the DNS tunnels.

Status:
Grant
Type:

Utility

Filling date:

17 Aug 2017

Issue date:

1 Oct 2019