The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 10, 2023

Filed:

Jul. 31, 2019
Applicant:

Arbor Networks, Inc., Westford, MA (US);

Inventors:

Sean O'Hara, Ypsilanti, MI (US);

Andrew David Mortensen, Ann Arbor, MI (US);

Brian St. Pierre, Acworth, NH (US);

Assignee:

Netscout Systems, Inc., Westford, MA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 9/40 (2022.01); H04L 43/12 (2022.01); H04L 61/4511 (2022.01); H04L 61/5007 (2022.01);
U.S. Cl.
CPC ...
H04L 63/1458 (2013.01); H04L 43/12 (2013.01); H04L 61/4511 (2022.05); H04L 61/5007 (2022.05); H04L 63/1416 (2013.01); H04L 2463/143 (2013.01); H04L 2463/144 (2013.01);
Abstract

A system and computer-implemented method of managing botnet attacks to a computer network is provided. The system and method includes receiving a DNS request included in network traffic, each DNS request included in the network traffic and including a domain name of a target host and identifying a source address of a source host, wherein the translation of the domain name, if translated, provides an IP address to the source host that requested the translation. The domain name of the DNS request is compared to a botnet domain repository, wherein the botnet domain repository includes one or more entries, each entry having a confirmation indicator that indicates whether the entry corresponds to a confirmed botnet. If determined by the comparison that the domain name of the DNS request is included in the botnet domain repository, then the source address of the DNS request is stored or updated in an infected host repository and a control signal is output to cause any future network traffic from the source address to be diverted to an administrator configured address. Each source address stored in the infected host repository identifies a host known to be infected.


Find Patent Forward Citations

Loading…