MALWARE DETECTION FOR PROXY SERVER NETWORKS
This specification generally relates to methods and systems for applying network policies to devices based on their current access network. One example method includes identifying a proxy connection request sent from a particular client device to a proxy server over a network, the proxy connection request including a hostname and configured to direct the proxy server to establish communication with the computer identified by the hostname on behalf of the client device; determining an identity of the client device based on the proxy connection request; identifying a domain name system (DNS) response to a DNS request including the hostname from the proxy connection request; and updating DNS usage information for the particular client based on the identified DNS response including the hostname from the proxy connection request.
1 . A computer-implemented method executed by one or more processors, the method comprising:
identifying, by a monitoring device, a proxy connection request sent from a particular client device to a proxy server over a network, the proxy connection request including a hostname and configured to direct the proxy server to establish communication with a computer identified by the hostname on behalf of the client device, wherein the monitoring device is separate from the client device and the proxy server, and wherein the monitoring device receives the proxy connection request from the network;
identifying, by the monitoring device, a domain name system (DNS) response to a DNS request including the hostname from the proxy connection request, wherein the DNS request is sent by the proxy server in response to the proxy connection request from the particular client device, and wherein the monitoring device receives the DNS response from the network;
determining, by the monitoring device, that the DNS response is associated with the particular client device based on the DNS response including the hostname from the proxy connection request; and
in response to determining that the DNS response is associated with the particular client device, updating, by the monitoring device, DNS usage information for the particular client device based on the identified DNS response.
2 . The method of claim 1 , wherein identifying the DNS response including the hostname includes:
sending the DNS request including the hostname from the proxy connection request; and
receiving the DNS response.
3 . The method of claim 1 , wherein the DNS usage information includes a DNS request rate for the particular client device, a DNS request failure rate for the particular client device, and hostnames included in DNS requests associated with the particular client device.
4 . The method of claim 1 , wherein the hostname is included in a Uniform Resource Locator (URL).
5 . The method of claim 1 , wherein the DNS request is sent by the proxy server on behalf of the client device and in response to the proxy connection request.
6 . The method of claim 1 , further comprising:
determining that the particular client device is exhibiting anomalous behavior based on the updated DNS usage information; and
performing a corrective action to the particular client device based on the determination.
7 . The method of claim 6 , wherein the anomalous behavior is associated with a malicious software program, and the corrective action includes removing the particular client device from the network.
8 . A non-transitory, computer-readable medium storing instructions operable when executed to cause at least one processor to perform operations comprising:
identifying, by a monitoring device, a proxy connection request sent from a particular client device to a proxy server over a network, the proxy connection request including a hostname and configured to direct the proxy server to establish communication with a computer identified by the hostname on behalf of the client device, wherein the monitoring device is separate from the client device and the proxy server, and wherein the monitoring device receives the proxy connection request from the network;
identifying, by the monitoring device, a domain name system (DNS) response to a DNS request including the hostname from the proxy connection request, wherein the DNS request is sent by the proxy server in response to the proxy connection request from the particular client device, and wherein the monitoring device receives the DNS response from the network;
determining, by the monitoring device, that the DNS response is associated with the particular client device based on the DNS response including the hostname from the proxy connection request; and
in response to determining that the DNS response is associated with the particular client device, updating, by the monitoring device, DNS usage information for the particular client device based on the identified DNS response.
9 . The non-transitory, computer-readable medium of claim 8 , the operations further comprising:
determining that the particular client device is exhibiting anomalous behavior based on the updated DNS usage information; and
performing a corrective action to the particular client device based on the determination.
10 . The non-transitory, computer-readable medium of claim 9 , wherein the anomalous behavior is associated with a malicious software program, and the corrective action includes removing the particular client device from the network.
11 . The non-transitory, computer-readable medium of claim 8 , wherein the DNS usage information includes a DNS request rate for the particular client device, a DNS request failure rate for the particular client device, and hostnames included in DNS requests associated with the particular client device.
12 . The non-transitory, computer-readable medium of claim 8 , wherein the hostname is included in a Uniform Resource Locator (URL).
13 . The non-transitory, computer-readable medium of claim 8 , wherein the DNS request is sent by the proxy server on behalf of the client device and in response to the proxy connection request.
14 . The non-transitory, computer-readable medium of claim 8 , wherein identifying the DNS response including the hostname includes:
sending the DNS request including the hostname from the proxy connection request; and
receiving the DNS response.
15 . A system comprising:
memory for storing data; and
one or more processors operable to perform operations comprising:
identifying, by a monitoring device, a proxy connection request sent from a particular client device to a proxy server over a network, the proxy connection request including a hostname and configured to direct the proxy server to establish communication with a computer identified by the hostname on behalf of the client device, wherein the monitoring device is separate from the client device and the proxy server, and wherein the monitoring device receives the proxy connection request from the network;
identifying, by the monitoring device, a domain name system (DNS) response to a DNS request including the hostname from the proxy connection request, wherein the DNS request is sent by the proxy server in response to the proxy connection request from the particular client device, and wherein the monitoring device receives the DNS response from the network;
determining, by the monitoring device, that the DNS response is associated with the particular client device based on the DNS response including the hostname from the proxy connection request; and
in response to determining that the DNS response is associated with the particular client device, updating, by the monitoring device, DNS usage information for the particular client device based on the identified DNS response.
16 . The system of claim 15 , the operations further comprising:
determining that the particular client device is exhibiting anomalous behavior based on the updated DNS usage information; and
performing a corrective action to the particular client device based on the determination.
17 . The system of claim 16 , wherein the anomalous behavior is associated with a malicious software program, and the corrective action includes removing the particular client device from the network.
18 . The system of claim 15 , wherein the DNS usage information includes a DNS request rate for the particular client device, a DNS request failure rate for the particular client device, and hostnames included in DNS requests associated with the particular client device.
19 . The system of claim 15 , wherein the hostname is included in a Uniform Resource Locator (URL).
20 . The system of claim 15 , wherein the DNS request is sent by the proxy server on behalf of the client device and in response to the proxy connection request.