The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 19, 2019

Filed:

Jul. 18, 2017
Applicant:

Palo Alto Networks, Inc., Santa Clara, CA (US);

Inventors:

Yanxin Zhang, San Ramon, CA (US);

Xinran Wang, San Ramon, CA (US);

Huagang Xie, Pleasanton, CA (US);

Wei Xu, Santa Clara, CA (US);

Assignee:

Palo Alto Networks, Inc., Santa Clara, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 29/12 (2006.01); G06F 17/30 (2006.01);
U.S. Cl.
CPC ...
H04L 63/14 (2013.01); H04L 63/0236 (2013.01); H04L 63/1416 (2013.01); H04L 63/1441 (2013.01); G06F 17/30958 (2013.01); H04L 29/12066 (2013.01); H04L 61/1511 (2013.01); H04L 61/6009 (2013.01);
Abstract

Techniques for malware domain detection using passive Domain Name Service (DNS) are disclosed. In some embodiments, malware domain detection using passive DNS includes generating a malware association graph that associates a plurality of malware samples with malware source information, in which the malware source information includes a first domain; generating a reputation score for the first domain using the malware association graph and passive DNS information; and determining whether the first domain is a malware domain based on the reputation score for the first domain.


Find Patent Forward Citations

Loading…