Zscaler, Inc.
Systems and methods to detect and monitor DNS tunneling
Last updated:
Abstract:
Systems and methods of detecting Domain Name System (DNS) tunnels for monitoring thereof include obtaining data related to DNS traffic between DNS nameservers and clients; determining a score for each DNS nameserver based on the data to characterize DNS queries over a period of time for each DNS nameserver, wherein the score incorporates all DNS queries associated with the associated DNS nameserver over the period of time; determining one or more DNS nameservers likely operating DNS tunnels based on the score; and performing one or more actions on the one or more DNS nameservers related to the DNS tunnels.
Status:
Grant
Type:
Utility
Filling date:
17 Aug 2017
Issue date:
1 Oct 2019