Invention Grant
- Patent Title: Detecting potential domain name system (DNS) hijacking by identifying anomalous changes to DNS records
-
Application No.: US16572813Application Date: 2019-09-17
-
Publication No.: US11343275B2Publication Date: 2022-05-24
- Inventor: Oleksii Mandrychenko
- Applicant: Fortinet, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Fortinet, Inc.
- Current Assignee: Fortinet, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: HDC Intellectual Property Law, LLP
- Main IPC: H04L61/4511
- IPC: H04L61/4511 ; H04L29/06 ; G06N20/00

Abstract:
Systems and methods are described for scanning or monitoring of Domain Name System (DNS) records of an entity for identifying anomalous changes to the DNS records that may be indicative of possible DNS hijacking. According to one embodiment, DNS monitoring engine running on a network security appliance protecting a private network, or implemented as a cloud-based service can be used for monitoring DNS records of the entity. Any modification in the monitored DNS record(s) can be detected within a pre-defined or configurable time-frame. The detected modification can be determined to be anomalous or not, by assigning a criticality value based on current value and previous value of one or more fields of the DNS record, one or more attributes of the DNS record and one or more derived attributes based on the DNS record.
Public/Granted literature
- US20210084071A1 DETECTING POTENTIAL DOMAIN NAME SYSTEM (DNS) HIJACKING BY IDENTIFYING ANOMALOUS CHANGES TO DNS RECORDS Public/Granted day:2021-03-18
Information query