Invention Grant
- Patent Title: System for detecting the presence of rogue domain name service providers through passive monitoring
-
Application No.: US14884899Application Date: 2015-10-16
-
Publication No.: US09648033B2Publication Date: 2017-05-09
- Inventor: Jeffery L. Crume
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Hoffman Warnick LLC
- Agent Daniel Simek
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/12 ; H04L12/26

Abstract:
A method, system, computer program product embodied in a computer readable storage medium, and computer system are disclosed for identifying a rogue domain name service (DNS) server. Embodiments include passively monitoring traffic on a target network; and identifying a DNS resolution response in the traffic on the network. The DNS resolution response includes a mapping of a domain to an internet protocol (IP) address. The DNS resolution response is compared with a preconfigured list of known mappings of domains to IP addresses. Based on the results of the comparison, it can be determined whether the DNS resolution response is correct. In cases where the DNS resolution response is incorrect, the provider of the DNS resolution response is a rogue DNS server.
Public/Granted literature
- US20160036845A1 SYSTEM FOR DETECTING THE PRESENCE OF ROGUE DOMAIN NAME SERVICE PROVIDERS THROUGH PASSIVE MONITORING Public/Granted day:2016-02-04
Information query