- Patent Title: Mitigation against domain name system (DNS) amplification attack
-
Application No.: US15422638Application Date: 2017-02-02
-
Publication No.: US10284520B2Publication Date: 2019-05-07
- Inventor: K. Tirumaleswar Reddy
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/12

Abstract:
Presented herein are techniques for mitigating a domain name system (DNS) amplification attack. A methodology is provided including receiving, at a (DNS) server, a DNS request, determining whether the DNS request has a source IP address that matches a predetermined source IP address and a port number that falls within a predetermined port range. When the DNS request has a source IP address that matches the predetermined source IP address and a port number that falls within the predetermined port range, determining whether the DNS request includes validation information. Based on the presence or content of the validation information, determining whether the DNS request is a valid DNS request, and dropping the DNS request when it is determined that the DNS request is not a valid DNS request.
Public/Granted literature
- US20180219833A1 MITIGATION AGAINST DOMAIN NAME SYSTEM (DNS) AMPLIFICATION ATTACK Public/Granted day:2018-08-02
Information query