Invention Grant
- Patent Title: Detecting and blocking domain name system cache poisoning attacks
- Patent Title (中): 检测和阻止域名系统缓存中毒攻击
-
Application No.: US13460110Application Date: 2012-04-30
-
Publication No.: US08910280B2Publication Date: 2014-12-09
- Inventor: Anestis Karasaridis
- Applicant: Anestis Karasaridis
- Applicant Address: US GA Atlanta
- Assignee: AT&T Intellectual Property I, L.P.
- Current Assignee: AT&T Intellectual Property I, L.P.
- Current Assignee Address: US GA Atlanta
- Agency: Hartman & Citrin LLC
- Main IPC: G06F21/00
- IPC: G06F21/00 ; H04L29/06 ; G06F21/57

Abstract:
Concepts and technologies for detecting and blocking Domain Name System (“DNS”) cache poisoning attacks are provided. An inline detector and blocker apparatus implements a detection algorithm to monitor DNS response packets and detects a DNS cache poisoning attack utilizing the detection algorithm. The inline detector and blocker apparatus detects the DNS cache poisoning attack by receiving a DNS response packet and determining that the response packet includes poison data. The poison data may be included within an additional section of the response packet and/or an answer section of the response packet. As appropriate, the inline detector and blocker apparatus removes the additional section and/or the answer section of the response packet to effectively block the poison data from being cached by a DNS caching resolver.
Public/Granted literature
- US20130291101A1 DETECTING AND BLOCKING DOMAIN NAME SYSTEM CACHE POISONING ATTACKS Public/Granted day:2013-10-31
Information query