A method of preventing unauthorized user access to a computer network has
been developed. The method includes receiving a domain name server
resolution request at the computer network from a requesting user. Next a
reply to the requesting user is generated with a domain name server
resolution and internet protocol address of a target device within the
computer network. The reply is inspected with a network security device,
where the network security device does not have an assigned internet
protocol address so that it remains undetected by the requesting user.
The network security device then monitors data traffic to the computer
network to detect a reply from the requesting user. Once detected, the
reply to the internet protocol address is intercepted with the network
security device. Finally, the network security device verifies that the
requesting user is authorized to access the computer network with the
network security device.