Method for detecting a malicious device in a communication network, corresponding communication device and computer program
A method for detecting a malicious device in a communication network, corresponding communication device and computer program. The method is implemented in a communication device configured with at least one name resolution server which is referred to as a legitimate name resolution server and associated with at least one network interface through which the communication device is able to communicate using at least one first identifier. The method includes: obtaining at least one second identifier, separate from the first identifier, for the communication device and the at least one network interface; obtaining configuration information from a name resolution service for the communication device using the at least one second identifier; and detecting presence of a malicious device in the event of an anomaly in the processing of a name resolution request sent by the communication device using the at least one second identifier and the obtained configuration information.
1 . A method comprising:
detecting a malicious device in a communication network, the detecting being implemented in a communication device configured with at least one legitimate name resolution server associated with at least one network interface, wherein the detecting comprises:
communicating through the at least one network interface using at least one first identifier for said communication device,
generating by the communication device at least one second identifier for said communication device and said at least one network interface, distinct from said at least one first identifier,
emulating a terminal of the communication network distinct from the communication device, and communicating through said at least one network interface using said at least one second identifier, the emulating comprising obtaining configuration information from a name resolution service for the emulated terminal using said at least one second identifier instead of said at least one first identifier, and said at least one network interface, and
detecting presence of a malicious device in the event of an anomaly in processing of a name resolution request sent by the emulated terminal using said at least one second identifier instead of said at least one first identifier, and the obtained configuration information.
2 . The method according to claim 1 , wherein said configuration information is obtained in a message received by said communication device, said message being a router advertisement message or a message according to the Dynamic Host Configuration Protocol (DHCP protocol) in response to a message sent by the communication device using said at least one second identifier, said name resolution service configuration message.
3 . The method according to claim 1 , further comprising detecting the presence of a malicious device in the event of usurpation, in a message received by said communication device, of an identity of a default router defined for said at least one network interface.
4 . The method according to claim 3 , wherein said communication device is the default router for said communication network, and said detecting implements:
comparing at least one identifier of a sender device of said message received by said communication device with said at least one first identifier of said communication device,
if said at least one identifier of the sender device of said received message is identical or correlated to said at least one first identifier of said communication device, deciding said sender device of said received message is a malicious device.
5 . The method according to claim 3 , wherein said communication device is not the default router defined for said communication network, and the detecting implements:
comparing at least one identifier of a sender device of said message received by said communication device with at least one identifier of a router defined by default,
if said at least one identifier of the sender device of said received message is not identical or correlated to said at least one identifier of the router defined by default, deciding said sender device of said received message is a malicious device.
6 . The method according to claim 1 , wherein said detecting implements:
obtaining, from the configuration information, at least one identifier of at least one name resolution server,
comparing said at least one identifier obtained with at least one identifier of said at least one legitimate name resolution server, and
if said at least one obtained identifier is not identical or correlated to said at least one identifier of said at least one legitimate name resolution server, deciding that a sender device of said configuration information is a malicious device.
7 . The method according to claim 1 , wherein the method comprises, prior to the detecting:
obtaining, from the configuration information, at least one identifier of at least one name resolution server,
sending, through a sender device of said configuration information, at least one name resolution request intended for said at least one identified name resolution server.
8 . The method according to claim 7 , wherein said communication device is a default router defined for said communication network, and said detecting further implements:
if said name resolution request transits after sending thereof by said communication device, verifying an integrity of said request,
deciding that said sender device of said configuration information is a malicious device if said communication device does not receive said request or if said request is not intact.
9 . The method according to claim 8 , wherein said verifying the integrity of the name resolution request comprises verifying whether said request transiting through said communication device has been modified compared to the original request and/or has been duplicated.
10 . The method according to claim 1 , wherein the method implements:
if a response to said name resolution request is received by the communication device, comparing said response, referred to as test response, with a response to the same request originating from said at least one legitimate name resolution server, referred to as legitimate response,
deciding that a sender device of said configuration information is a malicious device if said communication device does not receive said test response or if said test response is not identical or correlated to said legitimate response.
11 . The method according to claim 1 , wherein the method implements at least one action following the detection of the presence of a malicious device, said at least one action belonging to the group consisting of:
notifying an incident,
blocking said malicious device.
12 . The method according to claim 11 , wherein said blocking implements filtering messages intended for or received by said malicious device.
13 . The method according to claim 11 , wherein the at least one action comprises notifying an incident, which belongs to the group consisting of:
a direct notification of a user of said communication device,
a notification of a user of said communication device through an operator of said network,
a URL redirection to ask for an explicit authorization of a user of said communication device.
14 . The method according to claim 1 , wherein at least one of the generating at least one second identifier for said communication device, the obtaining configuration information from a name resolution service, or the detecting the presence of a malicious device, is implemented when a new device connects to said network.
15 . The method according to claim 1 , wherein said at least one second identifier belongs to the group consisting of:
a MAC address,
a link-local IP address,
a unicast IP address,
a unique local address,
an application identifier.
16 . The method according to claim 1 , wherein detecting presence of a malicious device in the event of an anomaly comprises comparing an identifier of a sender device responding to said name resolution request sent by the emulated terminal, with said at least first identifier.
17 . A communication device configured with at least one so-called legitimate name resolution server associated with at least one network interface, wherein the communication device comprises:
the at least one network interface;
at least one processor; and
at least one non-transitory computer readable medium comprising instructions stored thereon which when executed by the at least one processor configure the communication device to:
communicate through the at least one network interface using at least one first identifier for said communication device,
generate by the communication device at least one second identifier for said communication device and said at least one network interface, distinct from said at least one first identifier,
emulate a terminal of the communication network distinct from the communication device, and communicating through said at least one network interface using said at least second identifier instead of said at least one first identifier, said emulating comprising obtaining configuration information from a name resolution service for the emulated terminal using said at least one second identifier instead of said at least one first identifier, and said at least one network interface, and
detect presence of a malicious device in the event of an anomaly in processing of a name resolution request sent by the emulated terminal of said communication device using said at least one second identifier instead of said at least one first identifier and the obtained configuration information.
18 . A non-transitory computer readable medium comprising instructions stored thereon which when executed by at least one processor of a communication device configure the communication device to implement a method for detecting a malicious device in a communication network, the communication device being configured with at least one legitimate name resolution server associated with at least one network interface, and the method comprising:
communicating through the at least one network interface using at least one first identifier for said communication device,
generating by the communication device at least one second identifier for said communication device and said at least one network interface, distinct from said at least one first identifier,
emulating a terminal of the communication network distinct from the communication device, and communicating through said at least one network interface using said at least second identifier, instead of said at least one first identifier, said emulating comprising obtaining configuration information from a name resolution service for the emulated terminal, using said at least one second identifier instead of said at least one first identifier, and said at least one network interface, and
detecting presence of a malicious device in the event of an anomaly in processing of a name resolution request sent by the emulated terminal of said communication device using said at least one second identifier instead of said at least one first identifier, and the obtained configuration information.
19 . A method comprising:
detecting a malicious device in a communication network, the detecting being implemented in a communication device configured with at least one legitimate name resolution server associated with at least one network, wherein the detecting comprises:
communicating through the at least one network interface using at least one first identifier for said communication device,
generating by the communication device at least one second identifier for said communication device and said at least one network interface, distinct from said at least one first identifier,
emulating a terminal of the communication network distinct from the communication device, and communicating through said at least one network interface using said at least one second identifier instead of said at least one first identifier, said emulating comprising obtaining configuration information from a name resolution service for the emulated terminal using said at least one second identifier, instead of said at least one first identifier, and said at least one network interface, and
detecting presence of a malicious device in the event of an anomaly in processing of a name resolution request sent by the emulated terminal of said communication device using said at least one second identifier, instead of said at least one first identifier, and the obtained configuration information, wherein said detecting presence of a malicious device comprises detecting in a message received by said communication device usurpation of an identity of a default router defined for said at least one network interface by:
when said communication device is the default router for said communication network, comparing at least one identifier of a sender device of said message received by said communication device with said at least one first identifier of said communication device, and if said at least one identifier of the sender device of said received message is identical or correlated to said at least one first identifier of said communication device, deciding said sender device of said received message is a malicious device, and
when said communication device is not the default router defined for said communication network comparing at least one identifier of a sender device of said message received by said communication device with at least one identifier of a router defined by default, and if said at least one identifier of the sender device of said received message is not identical or correlated to said at least one identifier of the router defined by default, deciding said sender device of said received message is a malicious device.