CN101854404B - 检测域名系统异常的方法和装置 - Google Patents
检测域名系统异常的方法和装置 Download PDFInfo
- Publication number
- CN101854404B CN101854404B CN201010198228.8A CN201010198228A CN101854404B CN 101854404 B CN101854404 B CN 101854404B CN 201010198228 A CN201010198228 A CN 201010198228A CN 101854404 B CN101854404 B CN 101854404B
- Authority
- CN
- China
- Prior art keywords
- entropy
- domain name
- name system
- data block
- data
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims abstract description 24
- 238000001514 detection method Methods 0.000 claims abstract description 25
- 238000004364 calculation method Methods 0.000 claims abstract description 4
- 230000002159 abnormal effect Effects 0.000 abstract description 5
- 230000005856 abnormality Effects 0.000 abstract description 5
- 230000008859 change Effects 0.000 description 6
- 230000006870 function Effects 0.000 description 5
- 238000010586 diagram Methods 0.000 description 4
- 239000000725 suspension Substances 0.000 description 3
- 206010033799 Paralysis Diseases 0.000 description 2
- 238000004458 analytical method Methods 0.000 description 2
- 230000000694 effects Effects 0.000 description 2
- 238000005516 engineering process Methods 0.000 description 2
- 230000005540 biological transmission Effects 0.000 description 1
- 238000004891 communication Methods 0.000 description 1
- 238000000205 computational method Methods 0.000 description 1
- 239000012467 final product Substances 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
- 230000008569 process Effects 0.000 description 1
- 230000035945 sensitivity Effects 0.000 description 1
- 230000009897 systematic effect Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/45—Network directories; Name-to-address mapping
- H04L61/4505—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
- H04L61/4511—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (8)
Priority Applications (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201010198228.8A CN101854404B (zh) | 2010-06-04 | 2010-06-04 | 检测域名系统异常的方法和装置 |
PCT/CN2010/074577 WO2011150579A1 (zh) | 2010-06-04 | 2010-06-28 | 检测域名系统异常的方法和装置 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201010198228.8A CN101854404B (zh) | 2010-06-04 | 2010-06-04 | 检测域名系统异常的方法和装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN101854404A CN101854404A (zh) | 2010-10-06 |
CN101854404B true CN101854404B (zh) | 2013-08-07 |
Family
ID=42805666
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201010198228.8A Active CN101854404B (zh) | 2010-06-04 | 2010-06-04 | 检测域名系统异常的方法和装置 |
Country Status (2)
Country | Link |
---|---|
CN (1) | CN101854404B (zh) |
WO (1) | WO2011150579A1 (zh) |
Families Citing this family (9)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN105745868B (zh) * | 2013-11-26 | 2019-04-26 | 爱立信(中国)通信有限公司 | 网络中异常检测的方法和装置 |
CN104268289B (zh) * | 2014-10-21 | 2017-12-12 | 中国建设银行股份有限公司 | 链接url的失效检测方法和装置 |
CN105471639B (zh) * | 2015-11-23 | 2018-07-27 | 清华大学 | 基于中位数的网络流量熵值估算方法及装置 |
CN106533829B (zh) * | 2016-11-04 | 2019-04-30 | 东南大学 | 一种基于比特熵的dns流量识别方法 |
CN106803824A (zh) * | 2016-12-19 | 2017-06-06 | 互联网域名系统北京市工程研究中心有限公司 | 一种针对随机域名查询攻击的防护方法 |
CN107707375B (zh) * | 2017-05-26 | 2018-07-20 | 贵州白山云科技有限公司 | 一种定位解析故障的方法和装置 |
SG10202002125QA (en) * | 2020-03-09 | 2020-07-29 | Flexxon Pte Ltd | System and method for detecting data anomalies by analysing morphologies of known and/or unknown cybersecurity threats |
CN111818037A (zh) * | 2020-07-02 | 2020-10-23 | 上海工业控制安全创新科技有限公司 | 基于信息熵的车载网络流量异常检测防御方法及防御系统 |
CN113676379B (zh) * | 2021-09-01 | 2022-08-09 | 上海观安信息技术股份有限公司 | 一种dns隧道检测方法、装置、系统及计算机存储介质 |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101051952A (zh) * | 2007-04-18 | 2007-10-10 | 东南大学 | 高速多链路逻辑信道环境下的自适应抽样流测量方法 |
CN101572701A (zh) * | 2009-02-10 | 2009-11-04 | 中科正阳信息安全技术有限公司 | 针对DNS服务的抗DDoS攻击安全网关系统 |
Family Cites Families (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
AU2005299317A1 (en) * | 2004-10-25 | 2006-05-04 | Security First Corp. | Secure data parser method and system |
CN101378394B (zh) * | 2008-09-26 | 2012-01-18 | 成都市华为赛门铁克科技有限公司 | 分布式拒绝服务检测方法及网络设备 |
CN101645884B (zh) * | 2009-08-26 | 2012-09-05 | 西安理工大学 | 基于相对熵理论的多测度网络异常检测方法 |
-
2010
- 2010-06-04 CN CN201010198228.8A patent/CN101854404B/zh active Active
- 2010-06-28 WO PCT/CN2010/074577 patent/WO2011150579A1/zh active Application Filing
Patent Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101051952A (zh) * | 2007-04-18 | 2007-10-10 | 东南大学 | 高速多链路逻辑信道环境下的自适应抽样流测量方法 |
CN101572701A (zh) * | 2009-02-10 | 2009-11-04 | 中科正阳信息安全技术有限公司 | 针对DNS服务的抗DDoS攻击安全网关系统 |
Non-Patent Citations (1)
Title |
---|
王垚.《域名系统安全性研究》.《域名系统安全性研究》.2008, * |
Also Published As
Publication number | Publication date |
---|---|
CN101854404A (zh) | 2010-10-06 |
WO2011150579A1 (zh) | 2011-12-08 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN101854404B (zh) | 检测域名系统异常的方法和装置 | |
US20240340304A1 (en) | Entity ip mapping | |
Sun et al. | Less is more: Compact matrix decomposition for large sparse graphs | |
CN101325520B (zh) | 基于日志的智能自适应网络故障定位和分析方法 | |
US20080229056A1 (en) | Method and apparatus for dual-hashing tables | |
CN107273267A (zh) | 基于elastic组件的日志分析方法 | |
CN103152442B (zh) | 一种僵尸网络域名的检测与处理方法及系统 | |
CN101826996A (zh) | 域名系统流量检测方法与域名服务器 | |
CN101615186A (zh) | 一种基于隐马尔科夫理论的bbs用户异常行为审计方法 | |
CN102722584B (zh) | 数据存储系统及方法 | |
Clifford et al. | A statistical analysis of probabilistic counting algorithms | |
EP4012980A1 (en) | Application identification method and apparatus, and storage medium | |
RU2010128169A (ru) | Поддержка асинхронной многоуровневой отмены в сетке javascript | |
CN102142983A (zh) | 告警相关性分析方法和装置 | |
CN111581202A (zh) | 大数据交换系统 | |
Deng et al. | New estimation algorithms for streaming data: Count-min can do more | |
CN106294468B (zh) | 处理业务数据的方法和装置 | |
US11170050B1 (en) | Method and device for graph data quality verification | |
CN107402957A (zh) | 用户行为模式库的构建及用户行为异常检测方法、系统 | |
CN110825817A (zh) | 一种企业疑似关联关系判定方法及系统 | |
CN110851758B (zh) | 一种网页访客数量统计方法及装置 | |
US20150220648A1 (en) | Systems and Methods for Performing Machine-Implemented Tasks | |
Chen et al. | Worst-input mutation approach to web services vulnerability testing based on SOAP messages | |
CN105554181A (zh) | 一种dns日志压缩方法和装置 | |
CN102915313A (zh) | 网络搜索中的纠错关系生成方法及系统 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C53 | Correction of patent of invention or patent application | ||
CB03 | Change of inventor or designer information |
Inventor after: Mao Wei Inventor after: Li Xiaodong Inventor after: Ding Senlin Inventor after: Wang Xin Inventor after: Wu Jun Inventor after: Jin Jian Inventor before: Mao Wei Inventor before: Li Xiaodong Inventor before: Ding Senlin Inventor before: Wang Xin Inventor before: Wu Jun Inventor before: Jin Jian Inventor before: Lu Wenzhe |
|
COR | Change of bibliographic data |
Free format text: CORRECT: INVENTOR; FROM: MAO WEI LI XIAODONG DING SENLIN WANG XIN WU JUN JIN JIAN LU WENZHE TO: MAO WEI LI XIAODONG DING SENLIN WANG XIN WU JUN JIN JIAN |
|
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right |
Effective date of registration: 20210207 Address after: 100190 room 506, building 2, courtyard 4, South 4th Street, Zhongguancun, Haidian District, Beijing Patentee after: CHINA INTERNET NETWORK INFORMATION CENTER Address before: 100190 No. four, four South Street, Haidian District, Beijing, Zhongguancun Patentee before: Computer Network Information Center, Chinese Academy of Sciences |
|
TR01 | Transfer of patent right |