| CPC H04L 63/0263 (2013.01) | 18 Claims |

|
1. A method comprising:
obtaining a fully qualified domain name (FQDN) associated with a domain name system (DNS) request by a computing device;
in response to obtaining the FQDN, generating a first score for the FQDN based on trust factors associated with the FQDN, wherein generating the first score comprises determining factor scores for respective ones of the trust factors, combining the factor scores to create the first score, updating the first score upon receiving subsequent DNS requests for the FQDN, and resetting the first score when a timeout time is satisfied;
determining the first score satisfies a first action threshold of a plurality of action thresholds corresponding to different rules of a plurality of traffic rules for a firewall;
determining the first action threshold corresponds to a traffic rule of the plurality of traffic rules; and
implementing the traffic rule for the FQDN in the firewall.
|