The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Feb. 05, 2019

Filed:

Aug. 22, 2014
Applicant:

Mcafee, Inc., Santa Clara, CA (US);

Inventors:

Neeraj Thakar, Pune, IN;

Praveen Kumar Amritaluru, Chennai, IN;

Vikas Taneja, Sonepat, IN;

Assignee:

MCAFEE, LLC, Santa Clara, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); H04L 29/06 (2006.01); G06F 21/55 (2013.01); H04L 29/12 (2006.01);
U.S. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/554 (2013.01); H04L 61/1511 (2013.01); H04L 63/1408 (2013.01); H04L 63/1425 (2013.01); H04L 2463/144 (2013.01);
Abstract

Systems and methods for detection of domain generated algorithms (DGA) and their command and control (C&C) servers are disclosed. In one embodiment, such an approach includes examining DNS queries for DNS resolution failures, and monitoring certain set of parameters such as number of levels, length of domain name, lexical complexity, and the like for each failed domain. These parameters may then be compared against certain thresholds to determine if the domain name is likely to be part of a DGA malware. Domain names identified as being part of a DGA malware may then be grouped together. Once a DGA domain name has been identified, activity from that domain name can be monitored to detect successful resolutions from the same source to see if any of the successful domain resolutions match these parameters. If they match specific thresholds, then the domain is determined to be a C&C server of the DGA malware and may be identified as such.


Find Patent Forward Citations

Loading…