首页> 外国专利> Method for detecting DNS redirects or fraudulent local certificates for SSL sites in pharming/phishing schemes by remote validation and using a credential manager and recorded certificate attributes

Method for detecting DNS redirects or fraudulent local certificates for SSL sites in pharming/phishing schemes by remote validation and using a credential manager and recorded certificate attributes

机译:通过远程验证并使用凭据管理器和记录的证书属性来检测在域名欺诈/网络钓鱼方案中用于SSL站点的DNS重定向或欺诈性本地证书的方法

摘要

Certificate information associated with a received certificate, such as a Secure Sockets Layer (SSL) certificate is stored in a trusted local cache and/or in one or more remote trusted sources, such as a single remote trusted source and/or a trusted peer network. When a site certificate is received on a host computer system, certificate information associated with the received site certificate is obtained and compared with the stored certificate information to determine whether or not the site certificate indicates malicious activity, such as a malicious DNS redirection or a fraudulent local certificate. When a site certificate is not found indicative of malicious activity, the site certificate is released. Alternatively, when a site certificates is found indicative of malicious activity protective action is taken. In some embodiments, a user's log-in credentials are automatically obtained from a trusted local cache and automatically submitted to a web site.
机译:与接收到的证书相关联的证书信息(例如安全套接字层(SSL)证书)存储在受信任的本地缓存中和/或一个或多个远程受信任的源(例如单个远程受信任的源和/或受信任的对等网络)中。当在主机系统上接收到站点证书时,获取与接收到的站点证书关联的证书信息,并将其与存储的证书信息进行比较,以确定该站点证书是否指示恶意活动,例如恶意DNS重定向或欺诈性活动本地证书。当找不到表明恶意活动的站点证书时,将释放该站点证书。或者,当发现表明恶意活动的站点证书时,将采取保护措施。在某些实施例中,自动从受信任的本地缓存中获取用户的登录凭据,并自动将其提交给网站。

著录项

相似文献

  • 专利
  • 外文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号