×

Method, device and system for processing DNS behavior

  • US 9,967,269 B2
  • Filed: 03/19/2015
  • Issued: 05/08/2018
  • Est. Priority Date: 04/04/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method for processing Domain Name System (DNS) behavior, comprising:

  • parsing a received network data packet;

    determining a DNS behavior type corresponding to the network data packet according to a parse result;

    determining a processing body according to the DNS behavior type, wherein the processing body comprises at least one of a kernel and an application layer;

    transferring the network data packet to the determined processing body;

    processing the network data packet by the determined processing body, wherein the processing the network data packet by the determined processing body further comprises;

    when the determined processing body is the kernel,detecting the network data packet and filtering a DNS attack behavior carried in the network data packet by the kernel, andtransferring the filtered network data packet to the application layer for processing;

    wherein the method further comprises following steps to determine that the DNS attack behavior is carried in the network data packet;

    calculating a feature code of the network data packet;

    judging whether the feature code is a feature code of the DNS attack behavior;

    if yes, then determining that the DNS attack behavior is carried in the network data packet; and

    if not, then determining that the DNS attack behavior is not carried in the network data packet.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×