Collecting passive DNS traffic to generate a virtual authoritative DNS server
The present application describes a system and method for passively collecting DNS traffic data as that data is passed between a recursive DNS resolver and an authoritative DNS server. The information contained in the collected DNS traffic data is used to generate a virtual authoritative DNS server, or a zone associated with the authoritative DNS server, when it is determined that the authoritative DNS server has been compromised.
1 . A method, comprising:
passively capturing domain name system (DNS) data;
detecting a trigger event associated with an authoritative DNS server;
in response to detecting the trigger event:
causing a recursive DNS resolver to retrieve last known valid information associated with a zone from an observer system, the last known valid information being associated with the passively captured DNS data; and
causing the recursive DNS resolver to use the passively captured DNS data to provide an answer to a query received from a remote computing device;
generating a virtual authoritative DNS server using the passively captured DNS data; and
causing the recursive DNS resolver to host the virtual authoritative DNS server.
2 . The method of claim 1 , further comprising storing the passively captured DNS data at the observer system.
3 . The method of claim 1 , wherein detecting the trigger event comprises detecting a change in an address record associated with the authoritative DNS server.
4 . The method of claim 1 , wherein detecting the trigger event comprises receiving a notification from an entity associated with the authoritative DNS server.
5 . The method of claim 1 , wherein detecting the trigger event comprises determining that an internet protocol (IP) address associated with an answer to a received query is identified in a database of known IP address threats.
6 . The method of claim 1 , wherein the passively captured DNS data is associated with a geographic area.