首页> 外国专利> METHOD, SYSTEM, AND COMPUTER PROGRAM FOR IDENTIFYING ROGUE DOMAIN NAME SERVICE (DNS) SERVER (SYSTEM FOR DETECTING PRESENCE OF ROGUE DOMAIN NAME SERVICE PROVIDERS THROUGH PASSIVE MONITORING)

METHOD, SYSTEM, AND COMPUTER PROGRAM FOR IDENTIFYING ROGUE DOMAIN NAME SERVICE (DNS) SERVER (SYSTEM FOR DETECTING PRESENCE OF ROGUE DOMAIN NAME SERVICE PROVIDERS THROUGH PASSIVE MONITORING)

机译:识别域名服务(DNS)服务器的方法,系统和计算机程序(用于通过被动监视检测域名服务商存在的系统)

摘要

PROBLEM TO BE SOLVED: To provide a method, system, and computer program product embodied in a computer readable storage medium for identifying a rogue domain name service (DNS) server.SOLUTION: Embodiments comprise: passively monitoring traffic on a target network; and identifying a DNS resolution response in the traffic on the network. The DNS resolution response includes a mapping of a domain to an Internet Protocol (IP) address. The DNS resolution response is compared with a preconfigured list of known mappings of domains to IP addresses. Based on results of the comparison, it can be determined whether the DNS resolution response is correct. In cases where the DNS resolution response is incorrect, the provider of the DNS resolution response is a rogue DNS server.
机译:解决的问题:提供一种体现在计算机可读存储介质中的用于识别恶意域名服务(DNS)服务器的方法,系统和计算机程序产品。在网络流量中识别DNS解析响应。 DNS解析响应包括域到Internet协议(IP)地址的映射。将DNS解析响应与域到IP地址的已知映射的预配置列表进行比较。根据比较结果,可以确定DNS解析响应是否正确。如果DNS解析响应不正确,则DNS解析响应的提供者是恶意DNS服务器。

著录项

  • 公开/公告号JP2013247674A

    专利类型

  • 公开/公告日2013-12-09

    原文格式PDF

  • 申请/专利权人 INTERNATL BUSINESS MACH CORP IBM;

    申请/专利号JP20130080924

  • 发明设计人 JEFFERY LAKE CRUME;

    申请日2013-04-09

  • 分类号H04L12/70;

  • 国家 JP

  • 入库时间 2022-08-21 16:14:03

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号