CPC G06F 16/9536 (2019.01) [G06F 16/24578 (2019.01); H04L 61/4511 (2022.05)] | 9 Claims |
1. A system, comprising:
a processor configured to:
receive a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related event data;
generate a top N rank list for ranking popularity over the period of time for a set of domains, wherein the period of time includes a T number of days;
determine rank intervals to generate a most likely rank and an interval range for a set of domains, comprising to:
determine T daily ranks for the T number of days for a domain of the set of domains based on the top N rank list, wherein the determining operation relates to one sample of the domain;
determine an average rank for the T daily ranks for the one sample; and
determine a rank interval based on average ranks for M samples of the domain; and
output, based on the most likely rank and the interval range, a rank interval list for the set of domains that is used by a network device to enforce a network security policy using the rank interval list; and
a memory coupled to the processor and configured to provide the processor with instructions.
|