首页> 外国专利> SYSTEM FOR DETECTING THE PRESENCE OF ROGUE DOMAIN NAME SERVICE PROVIDERS THROUGH PASSIVE MONITORING

SYSTEM FOR DETECTING THE PRESENCE OF ROGUE DOMAIN NAME SERVICE PROVIDERS THROUGH PASSIVE MONITORING

机译:通过被动监视检测域名服务提供商存在的系统

摘要

A method, system, computer program product embodied in a computer readable storage medium, and computer system are disclosed for identifying a rogue domain name service (DNS) server. Embodiments include passively monitoring traffic on a target network; and identifying a DNS resolution response in the traffic on the network. The DNS resolution response includes a mapping of a domain to an internet protocol (IP) address. The DNS resolution response is compared with a preconfigured list of known mappings of domains to IP addresses. Based on the results of the comparison, it can be determined whether the DNS resolution response is correct. In cases where the DNS resolution response is incorrect, the provider of the DNS resolution response is a rogue DNS server.
机译:公开了一种在计算机可读存储介质中体现的方法,系统,计算机程序产品和计算机系统,用于识别恶意域名服务(DNS)服务器。实施例包括被动地监视目标网络上的流量。在网络流量中识别DNS解析响应。 DNS解析响应包括域到互联网协议(IP)地址的映射。将DNS解析响应与域到IP地址的已知映射的预配置列表进行比较。根据比较结果,可以确定DNS解析响应是否正确。如果DNS解析响应不正确,则DNS解析响应的提供者是恶意DNS服务器。

著录项

  • 公开/公告号US2016036845A1

    专利类型

  • 公开/公告日2016-02-04

    原文格式PDF

  • 申请/专利权人 INTERNATIONAL BUSINESS MACHINES CORPORATION;

    申请/专利号US201514884899

  • 发明设计人 JEFFERY L. CRUME;

    申请日2015-10-16

  • 分类号H04L29/06;H04L29/12;

  • 国家 US

  • 入库时间 2022-08-21 14:32:04

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号