Methods and systems for prevention of attacks associated with the domain name system
US11012414B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Nov 22, 2019 |
| Grant date | May 18, 2021 |
| Priority date | — |
| Expiry date | Nov 22, 2039 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L2463/142
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
The attack vectors for some denial-of-service cyber attacks on the Internet's Domain Name System (DNS) are bad, bogus, or unregistered domain name DNS requests to resolve domain names that are not registered in the DNS. Some other cyber attacks steal sensitive data by encoding the data in bogus domain names, or domain names otherwise not registered in the DNS, that are transferred across networks in bogus DNS requests. A DNS gatekeeper may filter in-transit packets containing DNS requests and may efficiently determine if a request's domain name is registered in the DNS. When the domain name is not registered in the DNS, the DNS gatekeeper may take one of a plurality of protective actions. The DNS gatekeeper drops requests determined not to be legitimate, which may prevent an attack.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.