The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 08, 2023

Filed:

Dec. 26, 2020
Applicant:

Nozomi Networks Sagl, Mendrisio, CH;

Inventors:

Alessandro Di Pinto, Malnate, IT;

Moreno Carullo, Gavirate, IT;

Andrea Carcano, San Francisco, CA (US);

Mario Marchese, Genoa, IT;

Fabio Patrone, Genoa, IT;

Alessandro Fausto, Savignona, IT;

Giovanni Battista Gaggero, Genoa, IT;

Assignee:

Nozomi Networks Sagl, Mendrisio, CH;

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 61/4511 (2022.01); H04L 9/40 (2022.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); H04L 61/4511 (2022.05); H04L 63/1416 (2013.01); H04L 63/1441 (2013.01);
Abstract

The present invention relates to a method and an apparatus for detecting anomalies of a DNS traffic in a network comprising analysing, through a network analyser connected to said network, each data packets exchanged in the network, isolating, through the network analyser, from each of the analysed data packets the related DNS packet, evaluating, through a computerized data processing unit, each of the DNS packets generating a DNS packet status, signaling, through the computerized data processing unit, an anomaly of the DNS traffic when the DNS packet status defines a critical state, wherein the evaluating further comprises assessing, through the computerized data processing unit, each of the DNS packet by a plurality of evaluating algorithms generating a DNS packet classification for each of the evaluating algorithms, aggregating, through the computerized data processing unit, the DNS packet classifications generating the DNS packet status, and wherein the critical state is identified when the DNS packet status is comprised in a critical state database stored in a storage medium.


Find Patent Forward Citations

Loading…