IP Library Granted Patent US 7,984,493
Granted Patent B2
US 7,984,493 · App. 11/186,866 · Granted Jul 19, 2011

DNS based enforcement for confinement and detection of network malicious activities

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,984,493
App. No.
11/186,866
Granted
Jul 19, 2011
Kind
B2
Abstract

Malicious network activities do not make use of the Domain Name System (DNS) protocol to reach remote targets outside a local network. This DNS-based enforcement system for confinement and detection of network malicious activities requires that every connection toward a resource located outside the local network is blocked by default by the local enforcement box, e.g. a firewall or a proxy. Outbound connections are allowed to leave the local network only when authorized directly by an entity called the DNS Gatekeeper.

Claims (62)

1. A system for detection and confinement of network malicious activities originating from a local host on a local network to a remote host outside of said local network, comprising:

a local domain name system (DNS) server connected to said local network, configured to:

receive from said local host a request for an outbound connection to said remote host,

complete a DNS lookup to obtain an IP address of said remote host, and

generate a conformity indication when said request for said outbound connection refers to a legitimate connection;

a DNS policy repository configured to enable select requests from the local host to access specified remote resources without the DNS lookup;

a DNS gatekeeper to generate a connection authorization indication based on said conformity indication; and

a local enforcement unit connected between said local network and the remote host configured to block-establishment of said outbound connection by default, until it receives said connection authorization indication.

2. The system of claim 1 ,

wherein the DNS policy repository includes a list of specified exceptions, including at least local hosts allowed to access specified remote resources without the DNS lookup.

3. The system of claim 2 , wherein said specified exceptions further include at least:

connections carrying peer-to-peer traffic;

connections from a local host with an embedded IP address; and

remote administration tools.

4. The system of claim 1 , wherein said local enforcement unit comprises:

a controlling unit configured to:

block said connection until receipt of said connection authorization indication, and

finally reject said request in the absence of said connection authorization indication;

a connection monitoring unit configured to:

determine if said outbound connection is a legitimate connection, and

instruct said control unit to enable said outbound connection in the absence of said connection authorization indication when said outbound connection is a legitimate connection.

5. The system of claim 4 , wherein said outbound connection is a legitimate connection when said local host hosts legitimately uses a numeric IP address.

6. The system of claim 4 , wherein said controlling unit, to allow or block said outbound connection, controls a standard firewall configured to protect against non-authorized users.

7. The system of claim 1 , wherein said outbound connection is a legitimate connection when said local host transmits a web page to a remote server.

8. The system of claim 1 , wherein said local enforcement unit further comprises:

a proxy server configured to:

block said outbound connection, and

unblock said outbound connection when said outbound connection carries a valid domain name request based on said conformity indication; and

an alarm reporting unit to rise an alarm when said request is finally blocked by said controlling unit, wherein said proxy server allows said outbound connection when said domain name is valid.

9. The system of claim 1 further comprising:

means for:

logging blocked outbound connections, and

reporting all local hosts that requested the respective blocked connections.

10. A method for detection and confinement of network malicious activities originating from a local host on a local network to a remote host outside of said local network, comprising:

generating a conformity indication in response to a completed DNS lookup performed by a local domain name system (DNS) server connected to said local network in response to a request received from said local host for an outbound connection to said remote host, with a view to obtain an IP address of said remote host, wherein said conformity indication indicates that said request for said outbound connection refers to a legitimate connection;

generating a connection authorization indication using an enforcement unit based on said conformity indication and a list of specified exceptions, said list including at least local hosts allowed to access specified remote resources without the DNS lookup; and

blocking establishment of said outbound connection by default until receipt of said connection authorization indication.

11. The method of claim 10 , further comprising:

monitoring the connection establishment process for said outbound connection to determine if said outbound connection is a legitimate connection; and

establishing said outbound connection in the absence of said connection authorization indication when said outbound connection is a legitimate connection.

12. The method of claim 11 , wherein said outbound connection is a legitimate connection when said local host transmits a web page to a remote server.

13. The method of claim 12 , wherein said monitoring step comprises:

identifying an acknowledgement message received by said local host from said remote host after an exchange of SYN messages;

accessing the message in a first payload packet transmitted by said local host after receipt of said acknowledgement message; and

flagging said connection as a legitimate connection when the message in said first payload packet is a HTTP GET command.

14. The method of claim 13 , further comprising:

sending a TCP RESET message to said remote host to terminate said connection establishment process when the message in said first payload packet is not a HTTP GET command.

15. The method of claim 13 , further comprising:

monitoring said outbound connection once established to determine when the response to said HTTP GET command indicates that said remote host is web server.

16. The method of claim 10 , further comprising:

dividing said local network into cells; and

equipping each cell with a respective local DNS server and an enforcement unit to confine spreading of a malicious activity within a cell.

17. The method of claim 10 , further comprising:

finally blocking establishment of said outbound connection in the absence of said connection authorization indication; and

raising an alarm whenever said request is finally blocked.

18. The method of claim 17 further comprising:

logging all finally-blocked outbound connections; and

reporting all local hosts that requested the respective blocked connections.

19. The method of claim 10 , wherein said specified exceptions include:

at least connections carrying peer-to-peer traffic,

remote administration tools, and

connections from a local host with an embedded IP address.

Assignments (12)
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2014
From: CREDIT SUISSE AG
To: ALCATEL LUCENT
Reel/Frame 033868/0001 →
SECURITY AGREEMENT Recorded Jan 30, 2013
From: ALCATEL LUCENT
To: CREDIT SUISSE AG
Reel/Frame 029821/0001 →
CHANGE OF NAME Recorded May 18, 2011
From: ALCATEL
To: ALCATEL LUCENT
Reel/Frame 026304/0539 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2005
From: JONES, EMANUELE
To: ALCATEL
Reel/Frame 016803/0391 →