US2022353293A1PendingUtilityA1
Identification of triggering events correlated with dns requests for increased security
Est. expiryMar 7, 2039(~12.6 yrs left)· nominal 20-yr term from priority
Inventors:Brian James Buck
H04L 61/4511H04L 63/1483H04L 61/59
63
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A triggering event correlated with domain name system (DNS) requests is identified. In response to the identification, DNS answers to the DNS requests are resolved. A determination is made that a part of the answers or the DNS requests is missing from a list of acceptable parts. In response to determining that the part is missing, an action is performed.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method, comprising:
identifying an occurrence of a triggering event correlated with one or more domain name system (DNS) requests; in response to identifying the occurrence of the triggering event, resolving one or more DNS answers to the one or more DNS requests; determining that a part of the one or more answers or the one or more DNS requests is missing from a list of acceptable parts of a DNS answer or a DNS request,
wherein the list comprises a list of allowable DNS servers to be used by a specific list of applications specified in a profile of a computing device or a profile of a computer network, and
wherein the part missing from the list is a particular DNS server; and
in response to the determining that the part is missing from the list, performing a particular action.
2 . The method of claim 1 , wherein the particular action comprises prohibiting use or creation of a network connection with the particular DNS server.
3 . The method of claim 1 , wherein the particular action comprises resolving one or more DNS answers using one or more predetermined DNS server addresses that does not comprise an address of the particular DNS server.
4 . The method of claim 1 , wherein the particular action comprises communicating a warning of the particular DNS server to a computing device making one of the one or more DNS requests.
5 . The method of claim 4 , wherein the particular action comprises communicating a warning of the particular DNS server to a computing device of a system administrator administrating a computing device making one of the one or more DNS requests.
6 . A method, comprising:
identifying an occurrence of a triggering event correlated with one or more domain name system (DNS) requests; in response to identifying the occurrence of the triggering event, resolving one or more DNS answers to the one or more DNS requests; determining that a part of the one or more answers or the one or more DNS requests is missing from a list of acceptable parts of a DNS answer or a DNS request,
wherein the list comprises a list of allowable applications to be used within a private network, and
wherein the part missing from the list is a particular application; and
in response to the determining that the part is missing from the list, performing a particular action.
7 . The method of claim 6 , wherein the list of allowable applications comprises a list of corresponding uniform resource locators, and wherein the list of corresponding uniform resource locators comprises complete uniform resource locators and partial uniform resource locators comprising domain name wildcards.
8 . The method of claim 6 , wherein the particular action comprises prohibiting resolution, by the particular application, of addresses internal to the private network.
9 . The method of claim 6 , wherein the particular action comprises terminating execution of the particular application.
10 . The method of claim 6 , wherein the particular action comprises tagging the particular application or a computing device running the particular application as being noncompliant with the list of allowable applications.
11 . The method of claim 10 , wherein the particular action further comprises communicating a warning of the tagging to a computing device of a system administrator administrating the computing device running the particular application and to a user interface device of or connected to the computing device running the particular application.
12 . The method of claim 6 , wherein the particular action comprises providing for a honeypot resolution, by the particular application, of addresses internal to the private network that are used for isolating and monitoring applications that are noncompliant with the list of allowable applications.
13 . The method of claim 6 , wherein the particular action comprises prohibiting the particular application from communicating with the private network.
14 . The method of claim 6 , wherein the particular action comprises prohibiting the particular application from performing DNS requests.
15 . A system comprising:
at least one processor; and a non-transitory computer-readable storage medium tangibly encoded with computer-executable instructions configured to instruct the at least one processor to: identify an occurrence of a triggering event correlated with one or more domain name system (DNS) requests; in response to identifying the occurrence of the triggering event, resolve one or more DNS answers to the one or more DNS requests; determine that a part of the one or more answers or the one or more DNS requests is missing from a list of acceptable parts of a DNS answer or a DNS request,
wherein the list comprises a list of allowable applications to be used within a private network, and
wherein the part missing from the list is a particular application; and
in response the determining that the part is missing from the list, perform a particular action.
16 . The system of claim 15 , wherein the particular action comprises prohibiting resolution, by the particular application, of addresses internal to the private network.
17 . The system of claim 15 , wherein the particular action comprises terminating execution of the particular application.
18 . The system of claim 15 , wherein the particular action comprises:
tagging the particular application or a computing device running the particular application as being noncompliant with the list of allowable applications; and communicating a warning of the tagging to a computing device of a system administrator administrating the computing device running the particular application and to a user interface device of or connected to the computing device running the particular application.
19 . The system of claim 15 , wherein the particular action comprises providing for a honeypot resolution, by the particular application, of addresses internal to the private network that are used for isolating and monitoring applications that are noncompliant with the list of allowable applications.
20 . The system of claim 15 , wherein the particular action comprises prohibiting the particular application from communicating with the private network.Join the waitlist — get patent alerts
Track US2022353293A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.