Roaming DNS Firewall

The roaming DNS firewall system addresses the vulnerability of mobile devices on unsecured networks by dynamically applying secure DNS profiles, ensuring secure connections and protecting against malicious servers without constant VPN usage.

JP7756154B2Active Publication Date: 2025-10-17FIELD EFFECT SOFTWARE INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023516818
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-09-15
Filing Date
2021-09-14
Publication Date
2025-10-17
Estimated Expiration
2041-09-14

AI Technical Summary

Technical Problem

Traditional firewalls are unable to distinguish potentially malicious DNS servers, and maintaining a constant VPN connection is problematic, leaving roaming users vulnerable to man-in-the-middle attacks when connecting to unsecured networks.

Method used

A roaming DNS firewall system that modifies DNS identifiers on mobile devices by characterizing network parameters, applying secure network profiles, and periodically verifying DNS settings to protect against malicious DNS servers.

Benefits of technology

Provides real-time protection against malicious DNS servers by ensuring secure DNS connections on untrusted networks without requiring constant VPN connections, thus enhancing user data security for mobile workers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007756154000001
    Figure 0007756154000001
  • Figure 0007756154000002
    Figure 0007756154000002
  • Figure 0007756154000003
    Figure 0007756154000003
Patent Text Reader

Abstract

A roaming Domain Name System (DNS) firewall is provided for execution by an endpoint agent provided on a mobile computing device. The growing mobile workforce presents security challenges because mobile computing devices regularly connect to unknown, untrusted, or unverified networks. These networks can pose a security risk to organizations by routing URL resolution requests to malicious DNS servers that can be exploited to redirect traffic to insecure hosts. The roaming DNS firewall on the mobile computing device monitors access to a network and determines whether the network is secure or unsecure based on associated network parameters. In response to a determination of an unsecure network, DNS identifiers are modified or relied upon to a trusted DNS server to ensure DNS requests are not processed by malicious DNS hosts.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims priority to U.S. Provisional Patent Application No. 63 / 078,848, filed September 15, 2020, which is incorporated herein by reference in its entirety.

[0002] FIELD OF THE INVENTION FIELD OF THE DISCLOSURE This disclosure relates to the domain name system (DNS), and more particularly to associating a client computer DNS with an insecure network. [Background technology]

[0003] The Domain Name System (DNS) relies on trusted sources of domain name addresses to ensure requested hosts are resolved to their intended destinations. Client computers rely on DNS servers to resolve Universal Resource Locators (URLs) to IP addresses and associated resources. While DNS servers are typically assumed to be trusted, the "work from home" transition, along with the increase in mobile workers outside of secure corporate networks, has resulted in employee devices roaming and accessing insecure external networks. Unsecured, unknown, or unverified networks can take the form of guest networks, such as free Wi-Fi networks offered at coffee shops, restaurants, hotels, etc., to perform work-related tasks. When a client computer connects to a new network, the Dynamic Host Control Protocol (DHCP) assigns an Internet Protocol (IP) address to the device and provides gateway and DNS routing information. The need to use DHCP means that the assigned DNS may be untrusted and could be used to redirect user data to malicious servers or websites, thus creating the potential for man-in-the-middle attacks. Traditional firewalls are unable to distinguish potentially malicious DNS servers because localhost IP addresses are commonly used as DNS servers, and lack the ability to identify malicious DNS servers based solely on IP addresses. Virtual private networks (VPNs) can mitigate this type of attack, but maintaining a constant VPN connection is problematic because protecting user data from potential exposure before establishing a connection to the VPN is problematic. Therefore, when roaming users connect to a new network, there is an opportunity for them to connect to a malicious DNS server.

[0004] Therefore, systems and methods that enable improved DNS firewall protection for roaming networked computing devices remain highly desirable. [Brief explanation of the drawings]

[0005] Further features and advantages of the present disclosure will become apparent from the following detailed description taken in conjunction with the accompanying drawings. [Figure 1] 1 illustrates a representation of one embodiment of a system including roaming DNS firewall functionality. [Figure 2] 1 illustrates an example of how an endpoint agent operates. [Figure 3] 1 illustrates an example of how secure DNS addresses can be enforced by an endpoint agent. [Figure 4] An example of how a roaming DNS firewall protects against DNS overrides is shown below. [Figure 5] An example of an alternative DNS override protection method is shown below. [Figure 6] An example of a method for managing DNS firewall deployment is shown.

[0006] It should be noted that throughout the accompanying drawings, like features are identified by like reference numerals. Summary of the Invention

[0007] In one embodiment, a method for initiating a roaming Domain Name System (DNS) firewall on a mobile computing device is provided, the method comprising: Detecting a network connection to a new network on a network interface of the mobile computing device; characterizing a plurality of network parameters associated with the new network; receiving a secure network profile based on a characterization of a plurality of network parameters; and modifying the DNS identifier associated with the network interface with the DNS identifier from the received secure network profile.

[0008] In a further embodiment of the method outlined above, the secure network profile identifies one or more trusted DNS identifiers, the secure network profile is received from a remote management server, and the roaming DNS firewall is provided by a security agent running on the mobile computing device.

[0009] In a further embodiment of the method outlined above, the DNS identifier is modified when a number of characterized network parameters are determined to be insecure.

[0010] In a further embodiment of the method outlined above, the characterization of the plurality of network parameters is insecure based on one or more parameters selected from the group including network type, network name, Wi-Fi BBSID, primary domain, search domain entries, current IPv4 DNS entries, and current IPv6 DNS entries.

[0011] In a further embodiment of the method outlined above, the method further comprises verifying that the DNS identifier has been successfully modified.

[0012] In a further embodiment of the method outlined above, the method further comprises sending a request to a remote server for a secure network profile based on the characterized plurality of network parameters.

[0013] In a further embodiment of the method outlined above, the roaming DNS firewall is provided by an endpoint agent running on the mobile computing device.

[0014] In a further embodiment of the method outlined above, modifying the DNS identifier comprises: Constructing DNS registry values ​​from a secure network profile; Applying a DNS registry value to a network interface card (NIC) Universally Unique Identifier (UUID); Disconnect from the new network and Shutting down the security agent; and Reconnecting the new network and starting the endpoint agent; and verifying that registry DNS values ​​are maintained.

[0015] In a further embodiment of the method outlined above, if the registry DNS value has been changed, the method further comprises reporting a failure.

[0016] In a further embodiment of the method outlined above, the method further comprises periodically polling the DNS identifier to determine that a secure DNS identifier is being maintained.

[0017] In a further embodiment of the method outlined above, the method comprises: monitoring a registry associated with a plurality of network parameters to identify parameter changes; receiving kernel change notifications or by polling for changes to specific registry data; verifying whether the kernel change notification is associated with a DNS identifier; and logging the DNS override when the kernel change is associated with a DNS identifier.

[0018] In a further embodiment of the method outlined above, the DNS identifier is associated with an authoritative DNS.

[0019] In a further embodiment of the method outlined above, the DNS roaming firewall is deactivated on trusted networks.

[0020] In a further embodiment of the method outlined above, the plurality of network parameters is received in a Dynamic Host Configuration Protocol (DHCP) message.

[0021] In a further embodiment of the method outlined above, modifying the DNS identifier associated with the network interface is defined in an associated registry key.

[0022] In yet a further embodiment, a mobile computing device is provided for performing a roaming Domain Name System (DNS) firewall of any one of the methods outlined herein.

[0023] In yet a further embodiment, a non-transitory computer readable memory is provided that includes instructions that, when executed by a processor, perform any one of the methods outlined herein.

[0024] In a further embodiment, a method for providing a roaming DNS firewall management server is provided, the method comprising: receiving a plurality of network characterizations observed by a plurality of endpoint agents executing on respective mobile computing devices; determining secure network parameters from the plurality of network characterizations; generating a secure network profile from a plurality of network parameters, the secure network profile identifying a trusted DNS identifier; and transmitting the secure network profile to the requesting mobile computing device. DETAILED DESCRIPTION OF THE INVENTION

[0025] Embodiments are described below, by way of example only, and with reference to Figures 1 to 6. All aspects, embodiments and examples disclosed herein are intended to be non-limiting.

[0026] A roaming DNS firewall feature is provided that protects or substantially protects a computer when it connects to an unsecured, unverified, or unknown network. This feature allows an operator (or customer) to define a set of safe networks whose DNS values ​​are considered safe, and a set of DNS information that is dynamically applied when a host connects to a network that is not on the safe network list.

[0027] According to one aspect of the present disclosure, a method for initiating a roaming Domain Name System (DNS) firewall on a mobile computing device is provided, the method including detecting a network connection to a new network on a network interface of the mobile computing device, characterizing a plurality of network parameters associated with the new network, receiving a secure network profile based on the characterization of the plurality of network parameters, and modifying a DNS identifier associated with the network interface with a DNS identifier from the received secure network profile.

[0028] According to yet another aspect of the present disclosure, a mobile computing device is provided for implementing the roaming Domain Name System (DNS) firewall of the disclosed method.

[0029] According to yet another aspect of the present disclosure, a non-transitory computer-readable memory is provided that includes instructions that, when executed by a processor, perform the disclosed methods.

[0030] According to another aspect of the present disclosure, there is provided a method for providing a roaming DNS firewall management server, the method including receiving a plurality of network characterizations observed by a plurality of endpoint agents executing on respective mobile computing devices, determining secure network parameters from the plurality of network characterizations, generating a secure network profile from the plurality of network parameters that identifies authoritative DNS identifiers, and transmitting the secure network profile to a requesting mobile computing device.

[0031] FIG. 1 shows a representation of a system including roaming DNS firewall functionality. In an enterprise network 110 environment, computing devices such as computers 112, 116, and 118 can operate in a controlled and validated configuration, utilizing secure DNS 114 (e.g., "192.1.99.43 192.1.99.44") to resolve URL identifiers. When a computing device such as computer 160 roams outside the office environment on an external, unsecured, unverified, or unknown network 150, the process of gaining access to the network via Dynamic Host Configuration Protocol (DHCP) allows bad actors to redirect or intercept user traffic by using a malicious or untrusted DNS 152. Computer 160 includes a processor for executing processing functions provided by memory 164. One or more network interfaces (NICs) 166 enable wired or wireless access to networks 150, 110 by configuring DHCP messages for NIC 172 when logging on to the respective networks. The endpoint agent function 170 executes on the computer 160, enabling monitoring of network connections and providing security functions to a management entity, such as the management server 120. The endpoint agent 170 identifies new network connections and characterizes parameters associated with the network connection to determine whether the network is secure. The network characterization enables a determination of whether the DNS IP 152 "192.168.1.1 192.168.1.2" provided to the device 160 is potentially unsafe and should be replaced with the verified secure DNS IP 132 "8.8.8.8 8.8.8.4." The characterization is defined by parameters associated with a secure network profile 180. The secure network profile is provided by the management server 120 and associated storage 122 and defines relative network parameters, network type, network identifier, location, user type, device type, or application type.The management server 120 can also provide audit 124 logs from the endpoint agents to determine if DNS values ​​were overwritten or not applied. The management server 120 may be hosted within a corporate or customer network, or may utilize a distributed or cloud-based architecture.

[0032] The following example is where the disclosed roaming DNS firewall functionality can provide protection in dynamic professional environments such as "work from home" distribution or those that travel frequently.

[0033] The first scenario involves daily "work from home" scenarios, where customer employees regularly connect their personal laptops to the company's VPN using their home Wi-Fi connection. When employees connect to the company's VPN, their laptops receive internal DNS information that provides a secure set of DNS information associated with the VPN. However, when a customer employee disconnects from the VPN, the roaming DNS firewall immediately turns on. This ensures that employee workstations are not victimized by bad websites or embedded website content that references DNS entries that point to malicious servers.

[0034] The second scenario in everyday "work from home" scenarios is one in which the corporate VPN does not exist. In some cases, an employee goes to the office one day a week with their work laptop, and while connected to the office network, the network information provides an internal set of DNS information. However, the other four days of the week, the customer works outside of their home or at a coffee shop. When the employee connects to a network other than the office network, the roaming DNS firewall applies an approved set of vetted DNS information, and the employee is therefore protected.

[0035] A third scenario where a roaming DNS firewall is very useful is with employees who travel frequently as part of their job, especially in other countries where the general security of the destination Internet is largely unknown. A roaming DNS firewall allows customer network administrators to configure an authorized set of DNS information that will be in effect when the customer is roaming.

[0036] In addition to the above scenarios, the Roaming DNS Firewall can be used with varying degrees of protection to best suit the customer network and distributed work environment. The Roaming DNS Firewall may also have additional features that improve the customer experience and provide additional protection, such as:

[0037] Each time an endpoint agent enables / disables the roaming DNS firewall for a given host, a detailed log is sent to the security appliance (on-site or cloud-based) that provides a complete audit trail of the changes made by the endpoint agent. This audit capability can facilitate additional levels of customer engagement.

[0038] Anti-tamper protection for the Roaming DNS Firewall is also provided by the endpoint agent, which means that if an employee attempts to disable the Roaming DNS Firewall settings, or if a potential cyber threat attempts to do the same, they will be blocked and a log can be sent to an internal security appliance or an external host.

[0039] Unlike existing solutions, the Roaming DNS Firewall does not require the deployment of additional network equipment or configuration across the customer infrastructure. The mechanism works by allowing operators (or back-end systems via automation) to describe networks that are considered safe networks (the safe network list) and a set of roaming DNS information (DNS overrides) that will be applied when a host connects to a network that is not on the safe network list. The mechanism has two descriptive sets of information: safe networks and DNS overrides.

[0040] Secure Network The first data object that needs to be defined is a secure network. Because there is no universal set of information that describes a network, a set of common or unique characteristics needs to be defined that can be used to describe a physical network (LAN or WAN), a Wi-Fi network, a cellular data network, a virtual private network (VPN), etc. In some cases, such as a wired LAN, the information available is that provided by a gateway when a device connects to the network; therefore, the characteristics are present rather than physical characteristics of the network itself.

[0041] For this exercise, the way a network is defined is by one or more characteristics that are combined into a data set that describes a secure network entity. To be considered a match, all specified fields must match, and only one field is required to identify a secure network. Network Type - The type of network, such as wired, Wi-Fi, or virtual. Network Name - The network name presented by the operating system, such as the SSID of a Wi-Fi network or the "LAN connection" reported when a network cable is plugged in. Wi-Fi BSSID - A unique MAC address that identifies a Wi-Fi network. Primary Domain - The primary domain string associated with the network provided when connecting. Search domain entries - One or more search domain prefixes associated with the network provided when connecting. Current IPv4 DNS Entries - One or more IPv4 DNS entries associated with the network provided upon connection. Current IPv6 DNS Entries - One or more IPv6 DNS entries associated with the network provided upon connection.

[0042] Below is an exemplary set of secure networks that may be defined for a particular customer topology.

[0043] Secure Network #1 This network, which is the customer's main physical network at headquarters, includes an administrative domain and an internal DNS server. Search Domain #1="AcmeNet" IPv4 DNS#1=192.1.99.43 IPv4 DNS#2=192.1.99.44

[0044] Secure Network #2 This network is a Wi-Fi network at a customer remote site. The most effective way to identify the Wi-Fi network is by BSSID, but any additional information, such as an internal DNS, can also help avoid BSSID spoofing. Wi-Fi BSSID=34:29:F3:23:55:25

[0045] DNS Override The messaging / processing also easily allows for support of primary domains, search prefixes, IPv4 and IPv6. Therefore, specifying DNS override information is simply a matter of specifying one or more IPv4 DNS values. For example, the following IPv4 DNS values ​​can be used (this is Google's IPv4 DNS value): DNS 1=8.8.8.8 DNS 2=8.8.4.4

[0046] As to what these DNS values ​​actually are, this is an operational decision: it could be, for example, a proxy that processes lookups and routes them to a DNS security authority within the local realm for validation.

[0047] FIG. 2 illustrates a method 200 of endpoint agent operation, such as that provided in a Windows™ operating environment. The roaming DNS firewall functions by characterizing a network (202) and cross-referencing it against a received safe network profile (206) to detect connections to a network (204) that do not match any of the defined safe networks. The safe network profile can be updated and received at any time. If the network is deemed safe (208, Yes), the connection is monitored for any changes, for example, according to the methods of FIGS. 4 and 5. If the network is not deemed safe (208, No), DNS settings on the network interface (NIC) that facilitate "unsafe" network connections are applied, which may be applied, for example, according to the method of FIG. 3. The profile application is verified (212) to ensure the correct values ​​are valid and then monitored for possible override events, for example, as in FIGS. 4 and 5.

[0048] Microsoft Windows uses registry data to store IPv4 DNS information for each NIC in the following location: \HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\

[0049] Each NIC is identified by a Universally Unique Identifier (UUID) subkey, which is present whether the NIC represents a physical network card or a virtual network adapter. Information specific to each NIC is stored as registry values ​​within that subkey, including two registry values ​​containing DNS information. These values ​​may or may not be present; their presence is dictated entirely by the DNS configuration for the NIC. These values, of type REG_SZ, are as follows: \HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\[NIC-UUID]\NameServer - Static DNS (manually configured) \HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\[NIC-UUID]\DhcpNameServer - Dynamic DNS (via DHCP)

[0050] The content of each registry value is a string containing a spatially separated list of IPv4 DNS values, for example: "8.8.8.8 8.8.4.4"

[0051] Referring to Figure 3, in a method 300 for changing the DNS configuration per NIC, the following steps are performed by the endpoint agent (which also performs the task of restoring the original DNS information when necessary): A new string of spatially separated DNS values ​​is constructed (302). Depending on whether static DNS is being used (NameServer value) or dynamic DNS assigned via DHCP (DhcpNameServer) is being used, the appropriate registry value for the NIC is changed (304). The DNS values ​​are activated by activating the new DNS settings (restoring the active DNS information from what is in the registry) (306): "ipconfig / flushdns".

[0052] When per-NIC DNS information is modified, the agent ensures that the original values ​​are restored if:

[0053] The host is disconnected from an insecure network whose associated NIC has overridden DNS information.

[0054] The agent is shut down (in case of an upgrade, uninstall, or general host shutdown).

[0055] The agent was started and realized that a previous DNS override was not reverted to its original value, which can happen if the agent or host crashes unexpectedly.

[0056] If the DNS value is correct (308 yes), override protection may be implemented, for example, as further described in Figures 4 and 5. If the value is incorrect (308 no), the failure may be reported to a management system (310) and additional remedial action may be taken.

[0057] The equivalent IPv6 information can be found in the following registry key (and subsequent per-NIC keys and values): \HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\[NIC-UUID]

[0058] Note that there is also IPv4 DNS information found at a higher level: \HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

[0059] DNS override is implemented per network, not host-wide. This ultimately allows routing tables to function as expected, and supports multiple networks being connected simultaneously. This has important implications for VPNs and potentially shared physical connections utilizing gateway hosts (although DNS queries to the gateway become significantly more complex if multiple networks are expected to provide DNS).

[0060] DNS Override Protection Registry keys that govern per-NIC DNS can be modified as part of normal Windows operating system tasks, but they can also be modified in a potentially malicious way if malware wishes to interfere with normal DNS servers. For example, a NIC configured to use DHCP has a lease expiration configured by the DHCP provider, which is typically every 30 days. When a renewal occurs, the host receives a full set of DHCP and DNS information (a typical configuration), which results in the DNS registry values ​​being reset to their original values. If this occurs while a roaming DNS firewall was active, it will disable the roaming DNS firewall.

[0061] For this reason, a protection mechanism was needed to ensure that the override value was reverted to the appropriate value if the registry value was modified. Because Windows does not have a mechanism to block access to specific registry keys / values ​​from user mode or a notification mechanism to monitor specific registry keys / values ​​and notify them of actual changes in the same callback context, two potential approaches are possible. Figure 4 shows a method 400 for DNS override protection. The expected value (i.e., the override DNS information) is cached (402) and periodically verified that the value is still appropriate, such as once per second, by polling for changes to the specific registry data (404). If the expected DNS value exists (yes in 404), the monitor polling process continues. If the expected value is not appropriate (no in 404), the value is identified against a known safe value (406). If the identified network is safe (408, yes), the monitor polling process continues, but if the value is not safe (408, no), an override event is logged (410) and provided to the management system, where the value is replaced with a modified value with the expected baseline. The roaming DNS firewall can then be restarted (412) to apply the safe DNS value.

[0062] Figure 5 shows an alternative method for DNS override protection 500. Expected values ​​(i.e., override DNS information) are cached (502). A system server process, NtNotifyChangeKey, is utilized to monitor (recursively) all registry value activity under the registry (504). key\HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces.

[0063] This mechanism still requires a thread to provide an alertable "landing pad" for notifications generated by the kernel (506), but avoids a polling hit. Although additional notifications are received for uninteresting keys / values, the benefit of not having to poll makes ignoring uninteresting callbacks an acceptable trade-off. When a notification callback is triggered, the changed registry value is verified to match the expected baseline (508). If the DNS values ​​have not changed (No in 508), monitoring continues (504) by registering a callback to receive further notifications. If the DNS values ​​have changed (Yes in 508), they are replaced with changed values ​​that have the expected baseline, and an override event is logged (510) and provided to the management system. The roaming DNS firewall can then be restarted (512) to apply the secure DNS values.

[0064] In Windows™ implementations, the kernel-only change notification API CmRegisterCallback / CmRegisterCallbackEx may be used. Alternatively, NtNotifyChangeKey can be used in both user and kernel mode, or manual polling may be used.

[0065] DNS Override Logging A logging mechanism can be implemented to give operators visibility when it takes actions related to the host DNS, for example as illustrated in Figures 4 and 5. There are three types of logs:

[0066] DNS Override - This log indicates that the agent detected that the host was connected to an insecure network and chose to override DNS for that network connection.

[0067] DNS Restore - This log indicates that the agent has chosen to restore its original DNS information due to a network connection, which could be caused by a network disconnection, the agent shutting down, or the agent initiating and cleaning up DNS state (possibly caused by an agent or host crash).

[0068] DNS Protection - This log indicates that the agent detected an unexpected external change to DNS information that was placed as an override, and that it restored the override value. This can happen if malware on the host attempts to make a change, or when a DHCP lease is restored (such as with the "ipconfig / renew" command).

[0069] FIG. 6 illustrates a method 600 for DNS firewall deployment management. The management system server can be hosted by the organization or provided by a distributed cloud computing environment. Some of the functionality can be configured or implemented depending on the configuration profile of the system associated with the organization. If an external authoritative DNS is not defined for the profile, the management server can request an authoritative DNS from a DNS security authority within the local domain for validation (602). To characterize secure networks, endpoint agent surveys can be provided to an analysis system that describes a common set of networks and network parameters currently observed by the endpoint agents (604). For example, if 1,000 endpoint agents deployed on a customer network (physical or virtual) indicate that two common networks are in use (possibly during normal work hours), a conclusion can be drawn that these two networks (perhaps identified by existing DNS information) represent secure networks associated with the organization, and a customer management interface can be used to request verification of these conclusions by the customer IT team. Creating this initial set is likely not overly difficult, but maintaining the accuracy of that secure network list as the customer network changes requires additional operational effort and the support of automated mechanisms. From the surveyed networks, safety parameters can be determined based on common or known characteristics (606). Alternatively, networks can be manually described by publishing their internal DNS information as safe network match criteria. Once provided, the management server can utilize endpoint agents to verify that the endpoint agents have seen one or more of the described safe networks. This allows for verification that most (if not all) of the hosts fit the provided safe network classification.

[0070] A secure network profile defining the verified DNS to be used on the unsecured network can then be generated (608) and sent to the endpoint agent as needed (610). As the endpoint agent operates, it can receive a DNS log identifying additional network profile parameters, network overrides, and execution errors (612). If the event is associated with a previously defined secure network profile (yes or 614), the network profile status can be modified (616) and device-specific software issues, such as possible malware, can be identified. If the event is not associated with a secure network (no 614), the associated parameters can be identified (618) and utilized in determining the additional secure network parameters for the secure network profile (606).

[0071] Each element in the embodiments of the present disclosure may be implemented as hardware, software / programs, or any combination thereof. The software code may be stored, in whole or in part, in a computer-readable medium or memory, or in a non-transitory memory (e.g., a ROM, e.g., a non-volatile memory such as a flash memory, a CD ROM, a DVD ROM, a Blu-ray (registered trademark), a semiconductor ROM, a USB, or a magnetic recording medium such as a hard disk). The program may be in the form of a code intermediate source and object code, such as a source code, an object code, a partially compiled form, or another form.

[0072] Those skilled in the art will appreciate that the systems and components shown in Figures 1-6 may include components not shown in the drawings. For simplicity and clarity of illustration, elements in the figures are not necessarily to scale and are merely schematic and are not intended to limit the structure of the elements. It will be apparent to those skilled in the art that certain variations and modifications can be made without departing from the scope of the invention as defined in the claims.

Claims

1. 1. A method for activating a roaming Domain Name System (DNS) firewall on a mobile computing device, comprising: Detecting a network connection to a new network on a network interface of the mobile computing device using an endpoint agent executing on the mobile computing device; characterizing, with the endpoint agent, a plurality of network parameters associated with the new network to determine whether the new network is secure; determining whether the new network is secure includes comparing the plurality of network parameters to at least one secure network profile received from a remote management server; determining that the new network is secure if the plurality of network parameters match the at least one secure network profile; characterizing the new network such that the new network is determined to be unsecure if the plurality of network parameters do not match the at least one secure network profile; modifying a DNS identifier associated with the network interface with a DNS identifier from the at least one secure network profile, the DNS identifier being modified if the plurality of network parameters is determined to be insecure; The method, wherein the plurality of network parameters are one or more of a network type, a network name, a Wi-Fi BBSID, a primary domain, a search domain entry, a current IPv4 DNS entry, and a current IPv6 DNS entry.

2. The method of claim 1 , wherein the at least one secure network profile identifies one or more trusted DNS identifiers.

3. The method of claim 1 or 2, further comprising verifying that the DNS identifier was successfully modified.

4. The method of any one of claims 1 to 3, further comprising sending a request for the at least one secure network profile to a remote server based on the characterized plurality of network parameters.

5. Modifying the DNS identifier comprises: constructing a DNS registry value from the at least one secure network profile; Applying the DNS registry value to a network interface card (NIC) universally unique identifier (UUID); disconnecting from the new network; Shutting down the security agent; and reconnecting to the new network; initiating the endpoint agent; The method of any one of claims 1 to 4, further comprising: verifying that the DNS registry values ​​are maintained.

6. The method of claim 5 , wherein if the DNS registry value is changed, the method further comprises reporting a failure.

7. A method described in any one of claims 1 to 6, further comprising periodically polling the DNS identifier from the at least one secure network profile to determine that the DNS identifier is maintained.

8. monitoring a registry associated with the plurality of network parameters to identify parameter changes; receiving kernel change notifications or by polling for changes to specific registry data; verifying whether the kernel change notification is associated with the DNS identifier; The method of any one of claims 1 to 7, further comprising: logging a DNS override when the kernel change is associated with the DNS identifier.

9. The method of any one of claims 1 to 8, wherein the DNS identifier is associated with an authoritative DNS.

10. The method of any one of claims 1 to 9, wherein the DNS roaming firewall is deactivated on trusted networks.

11. The method according to any one of claims 1 to 10, wherein the plurality of network parameters are received in a Dynamic Host Configuration Protocol (DHCP) message.

12. The method of any one of claims 1 to 11, wherein modifying a DNS identifier associated with the network interface is defined in an associated registry key.

13. A mobile computing device for implementing the roaming Domain Name System (DNS) firewall of the method of any one of claims 1 to 12.

14. A non-transitory computer readable memory comprising instructions which, when executed by a processor, perform the method of any one of claims 1 to 12.

15. 1. A method for providing a roaming DNS firewall management server, comprising: receiving, at the server, a plurality of network characterizations observed by a plurality of endpoint agents, each of the plurality of endpoint agents executing on a respective mobile computing device; determining, at the server, secure network parameters from the plurality of network characterizations, the secure network parameters being parameters of a secure network; generating a secure network profile from the secure network parameters, the secure network profile identifying trusted DNS identifiers; and transmitting the secure network profile to a requesting mobile computing device.

Citation Information

Patent Citations

  • Method and device for detecting and repairing malicious DNS setting

    CN103269389A

  • Method, system, and computer program for identifying rogue domain name service (DNS) server (system for detecting presence of rogue domain name service providers through passive monitoring)

    JP2013247674A

  • Using Aggregated DNS Information Originating from Multiple Sources to Detect Anomalous DNS Name Resolutions

    US20110191455A1

  • System for detecting the presence of rogue domain name service providers through passive monitoring

    US20130318170A1