DISTRIBUTED FREQUENCY DATA COLLECTION VIA INDICATOR EMBEDDED WITH DNS REQUEST
First Claim
1. A method of monitoring data traffic comprising:
- detecting occurrence of a transfer of a block of data with respect to a network node;
generating an indicator that is specifically related to contents of said block of data; and
reporting said transfer, including utilizing said indicator in a Domain Name Service (DNS) request.
11 Assignments
0 Petitions
Accused Products
Abstract
Domain Name Service (DNS) requests are used as the reporting vehicle for ensuring that security-related information can be transferred from a network. As one possibility, a central facility for a security provider may maintain a data collection capability that is based upon receiving the DNS requests containing the information being reported. In an email application, if a data block is embedded within or attached to an email message, an algorithm is applied to the data block to generate an indicator that is specifically related to the contents of the data block. As one possibility, the algorithm may generate a hash that provides a “digital fingerprint” having a reasonable likelihood that the hash is unique to the data block. By embedding the hash within a DNS request, the request becomes a report that the data block has been accessed.
-
Citations
20 Claims
-
1. A method of monitoring data traffic comprising:
-
detecting occurrence of a transfer of a block of data with respect to a network node; generating an indicator that is specifically related to contents of said block of data; and reporting said transfer, including utilizing said indicator in a Domain Name Service (DNS) request. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. An apparatus for monitoring data traffic comprising:
a detection circuit coupled to a network to detect occurrence of a transfer of a block of data with respect to a network node;
coupled to an indicator generation circuit to generate an indicator that is specifically related to contents of said block of data;
coupled to a communication circuit to report said transfer, by incorporation of said indicator in a Domain Name Service (DNS) request.- View Dependent Claims (17, 18, 19, 20)
Specification