IP Library Granted Patent US 8,806,626
Granted Patent B2
US 8,806,626 · App. 13/663,271 · Granted Aug 12, 2014

Using aggregated DNS information originating from multiple sources to detect anomalous DNS name resolutions

Inventor: Patrick Gardner (El Segundo, CA)
Assignee: Symantec Corporation
H04L29/12066H04L61/1511H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,806,626
App. No.
13/663,271
Granted
Aug 12, 2014
Kind
B2
Abstract

A DNS security system collects and uses aggregated DNS information originating from a plurality of client computers to detect anomalous DNS name resolutions. A server DNS security component receives multiple transmissions of DNS information from a plurality of client computers, each transmission of DNS information concerning a specific instance of a resolution of a specific DNS name. The server component aggregates the DNS information from the multiple client computers. The server component compares DNS information received from a specific client computer concerning a specific DNS name to aggregated DNS information received from multiple client computers concerning the same DNS name to identify anomalous DNS name resolutions. Where an anomaly concerning received DNS information is identified, a warning can be transmitted to the specific client computer from which the anomalous DNS information was received.

Claims (41)

1. A computer implemented method for providing DNS information to a server computer to detect anomalous DNS name resolutions, the method comprising the steps of:

identifying, by a DNS security component running on a computer, attempts to resolve DNS names by at least one specific computer;

gleaning, by the DNS security component running on the computer, DNS information concerning identified attempts to resolve DNS names by the at least one specific computer;

transmitting, by the DNS security component running on the computer, gleaned DNS information concerning each identified resolution of a DNS name by the at least one specific computer, to a server DNS security component running on a remote computer;

receiving, by the DNS security component running on the at least one specific computer, an indication that the DNS information concerning a specific attempt to resolve a specific DNS name by the at least one specific computer is anomalous, from the server DNS security component running on the remote computer to which gleaned DNS information is transmitted; and

responsive to the receiving step, modifying, by the DNS security component running on the at least one specific computer, a resolution of the specific DNS name indicated as being anomalous.

2. The method of claim 1 wherein:

the DNS security component running on a computer further comprises a client DNS security component running on a client computer; and

gleaning, by the DNS security component running on the computer, DNS information concerning identified attempts to resolve DNS names by the computer further comprises:

checking, by the client DNS security component running on the client computer, DNS settings local to the client computer; and

gleaning, by the client DNS security component running on the client computer, DNS information concerning at least one local resolution of at least one DNS name.

3. The method of claim 1 wherein gleaning, by the DNS security component running on the computer, DNS information concerning identified attempts to resolve DNS names by the computer further comprises:

monitoring, by the DNS security component running on the computer, outbound data transmission originating from client computers;

identifying, by the DNS security component running on the computer, at least one outbound DNS query and inbound resulting response; and

gleaning, by the DNS security component running on the computer, DNS information concerning at least one DNS name associated with the at least one outbound DNS query and the resulting inbound response.

4. At least one non-transitory computer readable-storage medium for providing DNS information to a server computer to detect anomalous DNS name resolutions, the at least one non-transitory computer readable-storage medium storing computer executable instructions that, when loaded into computer memory and executed by at least one processor of a computing device, cause the computing device to perform the following steps:

identifying, by a DNS security component running on a computer, attempts to resolve DNS names by at least one specific computer;

gleaning, by the DNS security component running on the computer, DNS information concerning identified attempts to resolve DNS names by the at least one specific computer;

transmitting, by the DNS security component running on the computer, gleaned DNS information concerning each identified resolution of a DNS name by the at least one specific computer, to a server DNS security component running on a remote computer;

receiving, by the DNS security component running on the at least one specific computer, an indication that the DNS information concerning a specific attempt to resolve a specific DNS name by the at least one specific computer is anomalous, from the server DNS security component running on the remote computer to which gleaned DNS information is transmitted; and

responsive to the receiving step, modifying, by the DNS security component running on the at least one specific computer, a resolution of the specific DNS name indicated as being anomalous.

5. The at least one non-transitory computer readable-storage medium of claim 4 wherein:

the DNS security component running on a computer further comprises a client DNS security component running on a client computer; and

gleaning, by the DNS security component running on the computer, DNS information concerning identified attempts to resolve DNS names by the computer further comprises:

checking, by the client DNS security component running on the client computer, DNS settings local to the client computer; and

gleaning, by the client DNS security component running on the client computer, DNS information concerning at least one local resolution of at least one DNS name.

6. The at least one non-transitory computer readable-storage medium of claim 4 wherein gleaning, by the DNS security component running on the computer, DNS information concerning identified attempts to resolve DNS names by the computer further comprises:

monitoring, by the DNS security component running on the computer, outbound data transmission originating from client computers;

identifying, by the DNS security component running on the computer, at least one outbound DNS query and inbound resulting response; and

gleaning, by the DNS security component running on the computer, DNS information concerning at least one DNS name associated with the at least one outbound DNS query and the resulting inbound response.

7. A computer system for providing DNS information to a server computer to detect anomalous DNS name resolutions, the computer system comprising:

system memory;

a DNS resolution identifying module residing in the system memory, the DNS resolution identifying module being programmed to identify attempts to resolve DNS names by the computer system;

a DNS local information gleaning module and a DNS remote information gleaning module residing in the system memory, the DNS local information gleaning module and the DNS remote information gleaning module being programmed to glean DNS information concerning identified attempts to resolve DNS names by the computer system; and

a DNS information transmitting module residing in the system memory, the DNS information transmitting module being programmed to transmit gleaned DNS information concerning each identified resolution of a DNS name by the computer system, to a server DNS security component running on a remote computer;

wherein the DNS remote information gleaning module is further programmed to receive an indication that the DNS information concerning a specific attempt to resolve a specific DNS name by the computer system is anomalous, from the server DNS security component running on the remote computer to which gleaned DNS information is transmitted, and in response to modify a resolution of the specific DNS name indicated as being anomalous.

8. The computer system of claim 7 wherein the computer system further comprises a client computer, and wherein the DNS local information gleaning module is further programmed to:

check DNS settings local to the client computer, and to glean DNS information concerning at least one local resolution of at least one DNS name.

9. The computer system of claim 7 further comprising:

a network traffic monitoring module residing in the system memory, the network traffic monitoring module being programmed to monitor outbound data transmission originating from the computer system; and

wherein the DNS remote information gleaning module is further programmed to identify at least one outbound DNS query and inbound resulting response, and to glean DNS information concerning at least one DNS name associated with the at least one outbound DNS query and the resulting inbound response.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2012
From: GARDNER, PATRICK
To: SYMANTEC CORPORATION
Reel/Frame 029207/0123 →
Continuity (2)
Division 12698745 · Feb 2, 2010
Related Publication 20130061321A1 · Mar 7, 2013