SERVER CONNECTION RESETS BASED ON DOMAIN NAME SERVER (DNS) INFORMATION
Systems, methods, and software described herein manage server connection resets based on domain name server (DNS) information. In one implementation, a firewall may receive a reverse DNS request from a computing system and communicate a request to a DNS security service to determine whether a destination associated with the reverse DNS request is malicious. The firewall further receives a response from the DNS security service that indicates that the destination is malicious and, when the response indicates that the destination is malicious, communicates a reset command to the destination to reset a connection between the destination and the computing system.
1 . A method comprising:
identifying a reverse Domain Name System (DNS) request for a computing system, wherein the reverse DNS request comprises an internet protocol (IP) address associated with a server;
in response to identifying the reverse DNS request, communicating a reset command to the server associated with the IP address to reset a connection between the server and the computing system.
2 . The method of claim 1 , wherein identifying the reverse DNS request comprises receiving the reverse DNS request at a firewall.
3 . The method of claim 1 further comprising:
determining that the IP address is malicious; and
wherein communicating the reset command further occurs in response to determining that the IP address is malicious.
4 . The method of claim 3 , wherein determining that the IP address is malicious comprises determining that the IP address, the uniform resource locator associated with the IP address, or a Name Server associated with the IP address is on a blacklist.
5 . The method of claim 3 , wherein determining that the IP address is malicious comprises querying a DNS security service to determine that the IP address is malicious.
6 . The method of claim 1 , wherein the reset command comprises an RST packet.
7 . The method of claim 1 further comprising:
determining whether the IP address is malicious;
when the IP address is malicious, communicating one or more additional reset commands to the server; and
when the IP address is not malicious, permitting the communication between the server and the computing system.
8 . The method of claim 7 , wherein determining whether the IP address is malicious comprises determining whether the IP address, the uniform resource locator associated with the IP address, or a Name Server associated with the IP address is on a blacklist.
9 . The method of claim 1 further comprising communicating one or more additional reset commands to the server.
10 . A computing apparatus:
a storage system;
a processing system operatively coupled to the storage system; and
program instructions stored on the storage system that, when executed by the processing system, direct the computing apparatus:
identify a reverse Domain Name System (DNS) request for a computing system, wherein the reverse DNS request comprises an internet protocol (IP) address associated with a server;
in response to identifying the reverse DNS request, communicate a reset command to the server associated with the IP address to reset a connection between the server and the computing system.
11 . The computing apparatus of claim 10 , wherein identifying the reverse DNS request comprises receiving the reverse DNS request at a firewall.
12 . The computing apparatus of claim 10 , wherein the program instructions further direct the computing apparatus to:
determine that the IP address is malicious; and
wherein communicating the reset command further occurs in response to determining that the IP address is malicious.
13 . The computing apparatus of claim 12 , wherein determining that the IP address is malicious comprises determining that the IP address, the uniform resource locator associated with the IP address, or a Name Server associated with the IP address is on a blacklist.
14 . The computing apparatus of claim 12 , wherein determining that the IP address is malicious comprises querying a DNS security service to determine that the IP address is malicious.
15 . The computing apparatus of claim 10 , wherein the reset command comprises an RST packet.
16 . The computing apparatus of claim 10 , wherein the program instructions further direct the computing apparatus to:
determine whether the IP address is malicious;
when the IP address is malicious, communicate one or more additional reset commands to the server; and
when the IP address is not malicious, permit the communication between the server and the computing system.
17 . The computing apparatus of claim 16 , wherein determining whether the IP address is malicious comprises determining whether the IP address, the uniform resource locator associated with the IP address, or a Name Server associated with the IP address is on a blacklist.
18 . The computing apparatus of claim 16 , wherein the program instructions further direct the computing apparatus to communicate one or more additional reset commands to the server.
19 . A method of operating a firewall comprising:
receiving a reverse Domain Name System (DNS) request from a computing system, wherein the reverse DNS request comprises an internet protocol (IP) address associated with a server;
in response to the reverse DNS request, communicate a reset command to the server associated with the IP address to reset a connection between the server and the computing system;
determining whether the IP address is malicious;
when the IP address is malicious, communicating one or more additional reset commands to the server; and
when the IP address is not malicious, permitting the communication between the server and the computing system.
20 . The system of claim 19 , wherein determining whether the IP address is malicious comprises querying a DNS security service to determine whether the IP address is malicious.