METHODS OF DETECTING DNS FLOODING ATTACK ACCORDING TO CHARACTERISTICS OF TYPE OF ATTACK TRAFFIC
Patent №
US 8,943,586
Granted
2015-01-27
Filed 2012
Owner
ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
Lab
—
AI components
1
hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
13529961
Disclosed are methods of detecting a domain name server (DNS) flooding attack according to characteristics of a type of attack traffic. A method of detecting an attack by checking a DNS packet transmitted over a network in a computer device connected to the network, includes determining whether the number of DNS packets previously generated within a threshold time with the same type of message, the same specific address and the same field value as in the transmitted packet is greater than or equal to a given number, and determining the transmitted DNS packet as a packet related to the attack if the number of DNS packets previously generated within the threshold time is greater than or equal to the given number.
AI classification
Ownership
ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
assignment · 284610667
Assignors
KIM, BYOUNG KOO
On an employer assignment, the assignors are typically the inventors.