Lock-free updates to a domain name blacklist

Active Publication Date: 2017-02-23
FARSIGHT SECURITY
View PDF0 Cites 8 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Benefits of technology

This patent describes a way to update a blacklist of domain names in a computer-implemented method. The method involves reading an entry of the blacklist from a DNS resolver and creating a new version of the blacklist if an updated entry is received. This new version is assigned to the DNS resolver when the reading is complete. The technical effect of this invention is that it allows for a secure and efficient way to update a blacklist of domain names without causing any race conditions or delays in the system.

Problems solved by technology

These addresses are often numerical, difficult to remember, and may frequently change.
But not all domains are registered for legitimate purposes.
One malicious purpose is to bring down a network service.
Other network abuses may not be trying to bring down a service, but may instead be making network requests, including application-level requests, for other improper purposes.
In these abuses, an automated system may be making application requests that, for example, set up fake user accounts and try to entice a user to devolve confidential information, such as her password, credit card information, or Social Security number, or run other scams.
If multiple DNS resolvers are trying to access the RPZ database, they all may be blocked.
Blocking read requests can slow a DNS resolver's response time when it receives requests to resolve a domain name into an IP address.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Lock-free updates to a domain name blacklist
  • Lock-free updates to a domain name blacklist
  • Lock-free updates to a domain name blacklist

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0028]Embodiments enable updates to a response policy zone database without acquiring a lock. They enable data to be written to an RPZ database concurrent with RPZ resolvers reading from the RPZ database. To achieve concurrent reading and writing, when the RPZ information is updated, entries in the RPZ database are not immediately overwritten or deleted. Instead, they are designated as garbage. That designation remains until all reads are complete. When all reads are complete, the garbage is deleted. In this way, embodiments enable lock free updates to a response policy zone database.

[0029]While examples are provided for DNS RPZ data for illustrative purposes, persons of skill in the art would recognize that the lock free updating technique described herein would apply to other types of data as well. An example environment in which the lock-free updating of the present disclosure may be applied is illustrated in FIG. 1.

[0030]FIG. 1 illustrates a system 100 for updating a domain name...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

A computer-implemented method updates a domain name system blacklist in a lock-free manner is disclosed. In the method, an entry of the domain name blacklist is read at a DNS resolver in a plurality of DNS resolvers. The entry specifies a policy for the DNS resolver to execute when the DNS resolver receives a request to resolve a domain name. Before the reading is complete, an updated entry of the domain name blacklist is received, a new record to the domain name blacklist is added, and the entry being read is placed into a garbage pool having a current version number. Independently from the reading of the entry, the current version number is incremented and a new garbage pool is created for the incremented version number. When the reading is complete, the current version number is assigned to the DNS resolver.

Description

BACKGROUND[0001]Field[0002]This field is generally related to network security, and more specifically updating Domain Name System (DNS) blacklist records.[0003]Related Art[0004]A communication network may, for example, allow data to be transferred between two geographically remote locations. To transmit data over a network, the data is often divided into pieces, known as packets or blocks. Each packet or block may have a destination network address, such as an IP address, that indicates a destination of the packet and tells forwarding devices how the packet should be routed. These addresses are often numerical, difficult to remember, and may frequently change.[0005]To identify a destination, domain names are frequently used. Domain names identify a destination host, or server, and may map to a corresponding network address. For example, the domain name www.example.com may map to the network address 93.184.216.119. To map domain names to network addresses, a domain name system (DNS) ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
IPC IPC(8): H04L29/06G06F17/30H04L29/12
CPCH04L63/205H04L61/1511G06F17/30345G06F17/30117H04L63/101H04L63/1466G06F16/2379H04L61/4511
InventorSCHRYVER, VERNON
OwnerFARSIGHT SECURITY