FIELD: data processing.
SUBSTANCE: invention relates to the field of data processing. This effect is achieved by intercepting a Domain Name Service (DNS) response message received on a computer system, wherein the DNS response message contains a target Internet Protocol (IP) address indicating the network location of the remote resource, wherein the DNS response message further comprises an activation flag services, determining, according to the value of the service activation flag, whether the forensic data collection service is active, in response, if the service activation flag indicates that the forensic data collection service is active, modifying the DNS response message by replacing the target IP address with a dummy IP address, intercepting electronic communication directed to the destination IP address, determining whether the destination IP address matches the bogus IP address, in response to determining whether the destination IP address matches the bogus IP address if the destination IP address matches the bogus IP address IP address, a forensic data collection procedure is performed to characterize the emerging malicious code, wherein the forensic data collection procedure comprises transmitting a set of metadata characterizing electronic communication to a remote security server.
EFFECT: enabling the collection of computer security data from client devices.
20 cl, 13 dwg
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD FOR AUTOMATIC DEVICE DETECTION, DEVICE CONTROL AND REMOTE ASSISTANCE | 2015 |
|
RU2691858C2 |
SYSTEMS AND METHODS FOR AUTOMATIC DEVICE DETECTION, DEVICE CONTROL AND REMOTE ASSISTANCE | 2015 |
|
RU2694022C2 |
ENDPOINT SECURITY SYSTEM AND METHOD | 2015 |
|
RU2693922C2 |
SYSTEM AND METHOD OF AUTOGENERATION OF DECISION RULES FOR INTRUSION DETECTION SYSTEMS WITH FEEDBACK | 2016 |
|
RU2634209C1 |
METHOD FOR REMOTE MONITORING AND CONTROL OF NETWORKING INFORMATION SECURITY BASED ON USE OF DOMAIN NAME SYSTEM | 2012 |
|
RU2503059C1 |
SYSTEM AND METHODS FOR DETECTING NETWORK FRAUD | 2017 |
|
RU2744671C2 |
METHOD FOR PROTECTING COMPUTER NETWORK AGAINST INTRUSION | 2021 |
|
RU2758997C1 |
SYSTEM AND METHOD FOR DETECTION OF TARGET ATTACKS | 2014 |
|
RU2601147C2 |
CLOUD SERVICE SECURITY BROKER AND PROXY | 2014 |
|
RU2679549C2 |
DOUBLE SELF-TEST OF MEMORY FOR PROTECTION OF MULTIPLE NETWORK ENDPOINTS | 2016 |
|
RU2714607C2 |
Authors
Dates
2022-07-19—Published
2020-07-02—Filed