发明名称 METHOD, SYSTEM, AND COMPUTER PROGRAM FOR IDENTIFYING ROGUE DOMAIN NAME SERVICE (DNS) SERVER (SYSTEM FOR DETECTING PRESENCE OF ROGUE DOMAIN NAME SERVICE PROVIDERS THROUGH PASSIVE MONITORING)
摘要 PROBLEM TO BE SOLVED: To provide a method, system, and computer program product embodied in a computer readable storage medium for identifying a rogue domain name service (DNS) server.SOLUTION: Embodiments comprise: passively monitoring traffic on a target network; and identifying a DNS resolution response in the traffic on the network. The DNS resolution response includes a mapping of a domain to an Internet Protocol (IP) address. The DNS resolution response is compared with a preconfigured list of known mappings of domains to IP addresses. Based on results of the comparison, it can be determined whether the DNS resolution response is correct. In cases where the DNS resolution response is incorrect, the provider of the DNS resolution response is a rogue DNS server.
申请公布号 JP2013247674(A) 申请公布日期 2013.12.09
申请号 JP20130080924 申请日期 2013.04.09
申请人 INTERNATL BUSINESS MACH CORP <IBM> 发明人 JEFFERY LAKE CRUME
分类号 H04L12/70 主分类号 H04L12/70
代理机构 代理人
主权项
地址