首页> 外国专利> System for detecting the presence of rogue domain name service providers through passive monitoring

System for detecting the presence of rogue domain name service providers through passive monitoring

机译:通过被动监视检测恶意域名服务提供商的存在的系统

摘要

A method, system, and computer program product embodied in a computer readable storage medium are disclosed for identifying a rogue domain name service (DNS) server. Embodiments include passively monitoring traffic on a target network; and identifying a DNS resolution response in the traffic on the network. The DNS resolution response includes a mapping of a domain to an internet protocol (IP) address. The DNS resolution response is compared with a preconfigured list of known mappings of domains to IP addresses. Based on the results of the comparison, it can be determined whether the DNS resolution response is correct. In cases where the DNS resolution response is incorrect, the provider of the DNS resolution response is a rogue DNS server.
机译:公开了一种体现在计算机可读存储介质中的方法,系统和计算机程序产品,用于识别恶意域名服务(DNS)服务器。实施例包括被动地监视目标网络上的流量。在网络流量中识别DNS解析响应。 DNS解析响应包括域到互联网协议(IP)地址的映射。将DNS解析响应与域到IP地址的已知映射的预配置列表进行比较。根据比较结果,可以确定DNS解析响应是否正确。如果DNS解析响应不正确,则DNS解析响应的提供者是恶意DNS服务器。

著录项

  • 公开/公告号US9225731B2

    专利类型

  • 公开/公告日2015-12-29

    原文格式PDF

  • 申请/专利权人 JEFFERY L. CRUME;

    申请/专利号US201213479412

  • 发明设计人 JEFFERY L. CRUME;

    申请日2012-05-24

  • 分类号H04L29/12;H04L29/06;H04L12/26;

  • 国家 US

  • 入库时间 2022-08-21 14:28:15

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号