SYSTEMS AND METHODS FOR USING DNS MESSAGES FOR SELECTIVE COLLECTION OF COMPUTER FORENSIC DATA Russian patent published in 2022 - IPC H04L65/60 

Abstract RU 2776349 C1

FIELD: data processing.

SUBSTANCE: invention relates to the field of data processing. This effect is achieved by intercepting a Domain Name Service (DNS) response message received on a computer system, wherein the DNS response message contains a target Internet Protocol (IP) address indicating the network location of the remote resource, wherein the DNS response message further comprises an activation flag services, determining, according to the value of the service activation flag, whether the forensic data collection service is active, in response, if the service activation flag indicates that the forensic data collection service is active, modifying the DNS response message by replacing the target IP address with a dummy IP address, intercepting electronic communication directed to the destination IP address, determining whether the destination IP address matches the bogus IP address, in response to determining whether the destination IP address matches the bogus IP address if the destination IP address matches the bogus IP address IP address, a forensic data collection procedure is performed to characterize the emerging malicious code, wherein the forensic data collection procedure comprises transmitting a set of metadata characterizing electronic communication to a remote security server.

EFFECT: enabling the collection of computer security data from client devices.

20 cl, 13 dwg

Similar patents RU2776349C1

Title Year Author Number
SYSTEM AND METHOD FOR AUTOMATIC DEVICE DETECTION, DEVICE CONTROL AND REMOTE ASSISTANCE 2015
  • Chebere Bogdan-Konstantin
  • Akim Joan-Aleksandru
  • Stan Kozmin-Klaudiu
  • Rusu Andrej
RU2691858C2
SYSTEMS AND METHODS FOR AUTOMATIC DEVICE DETECTION, DEVICE CONTROL AND REMOTE ASSISTANCE 2015
  • Chebere Bogdan-Konstantin
  • Mirchesku Danel-Aleksandru
RU2694022C2
ENDPOINT SECURITY SYSTEM AND METHOD 2015
  • Chebere Bogdan-Konstantin
  • Akim Joan-Aleksandru
  • Stan Kozmin-Klaudiu
  • Rusu Andrej
RU2693922C2
SYSTEM AND METHOD OF AUTOGENERATION OF DECISION RULES FOR INTRUSION DETECTION SYSTEMS WITH FEEDBACK 2016
  • Kislitsin Nikita Igorevich
RU2634209C1
METHOD FOR REMOTE MONITORING AND CONTROL OF NETWORKING INFORMATION SECURITY BASED ON USE OF DOMAIN NAME SYSTEM 2012
  • Markin Dmitrij Olegovich
  • Aksamentov Maksim Sergeevich
RU2503059C1
SYSTEM AND METHODS FOR DETECTING NETWORK FRAUD 2017
  • Damian Alin-Octavian
RU2744671C2
METHOD FOR PROTECTING COMPUTER NETWORK AGAINST INTRUSION 2021
  • Chajkovskij Sergej Stanislavovich
RU2758997C1
SYSTEM AND METHOD FOR DETECTION OF TARGET ATTACKS 2014
  • Yablokov Viktor Vladimirovich
RU2601147C2
CLOUD SERVICE SECURITY BROKER AND PROXY 2014
  • Koem Aviram
  • Mojsi Liran
  • Lyuttvak Ami
  • Reznik Roj
  • Vishnepolski Greg
RU2679549C2
DOUBLE SELF-TEST OF MEMORY FOR PROTECTION OF MULTIPLE NETWORK ENDPOINTS 2016
  • Lutas Dan-Horea
  • Lukacs Sandor
  • Ticle Daniel-Ioan
  • Ciocas Radu-Ioan
  • Anichitei Ionel-Cristinel
RU2714607C2

RU 2 776 349 C1

Authors

Mircescu Daniel-Alexandru

Dates

2022-07-19Published

2020-07-02Filed