IP Library Granted Patent US 8,843,612
Granted Patent B2
US 8,843,612 · App. 12/610,505 · Granted Sep 23, 2014

Distributed frequency data collection via DNS networking

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,843,612
App. No.
12/610,505
Granted
Sep 23, 2014
Kind
B2
Abstract

Domain Name Service (DNS) requests are used as the reporting vehicle for ensuring that security-related information can be transferred from a network. As one possibility, a central facility for a security provider may maintain a data collection capability that is based upon receiving the DNS requests containing the information being reported. In an email application, if a data block is embedded within or attached to an email message, an algorithm is applied to the data block to generate an indicator that is specifically related to the contents of the data block. As one possibility, the algorithm may generate a hash that provides a “digital fingerprint” having a reasonable likelihood that the hash is unique to the data block. By embedding the hash within a DNS request, the request becomes a report that the data block has been accessed.

Claims (25)

1. A method for operating a network email security device, the email security device coupled to a network comprising a plurality of user devices; a network email server configured to enable email exchanges to and from said user devices; a network firewall connected along a path from the Internet and each of said user devices and said network email security devices, and a central security provider server; the method comprising:

receiving an email message;

hashing content of one or more data blocks that are transmitted in said email exchanges to provide a hash, said data blocks including images and file attachments,

counting each reoccurrence of each data block in subsequent email exchanges to provide a count,

handling said hash and counts as the first portion of a domain name of a DNS request utilized as a reporting vehicle and

transmitting said domain name that includes said hashes and counts via a Domain Name System (DNS) request to said central security provider server configured as a DNS server.

2. The method of claim 1 further comprising

being responsive to security updates received from said central security provider server in the form of a DNS reply; and

disposing an email message according to said security update in the form of a DNS reply received from said central security provider server.

3. A software program product, tangibly embodied as machine readable instructions encoded on non-transitory computer readable media, to adapt a processor within a network email security device to filter email exchanges by generating digital signatures for components of email messages based on contents of components of email messages to be transmitted, forming domain names that include said digital signatures for each occurrence of an identical component and a hash for the content of the data blocks including images and attached files, and transmitting said domain names as DNS requests to a central security provider server.

4. The software program product of claim 3 further comprising instructions encoded on non-transitory computer readable media to respond to security updates received from said central security provider and dispose of email exchanges according to DNS replies received from said central security provider server.

5. A network email server apparatus comprising a processor configured to enable email exchanges to and from user devices; coupled to a network email security device configured to filter said email exchanges, said network email security device having

a reporting component specific to forming and transmitting a domain name which includes a count of occurrences of each block of data embedded within or attached to an email message but not a count of entire email messages,

and said reporting component configured to transmit said domain name as a Domain Name System(DNS) request to a central security provider server configured as a DNS server.

6. The network email security device of claim 5 wherein said domain name comprises a digital signature for each block of data embedded within or attached to an email message but not an entire email message and a count of occurrences of each block of data embedded within or attached to an email message but not a count of entire email messages and said reporting component is configured to receive a DNS reply causing transmission or suppression of an email.

7. A network email server apparatus comprising a processor configured to enable email exchanges to and from user devices; coupled to a network email security device configured to filter said email exchanges, said network email security device adapted to generate digital signatures for components of email messages and to report a count of occurrences of said components via Domain Name System (DNS) requests as the reporting vehicle, and adapted to generate a hash for content of data blocks and a count of each occurrence of said data blocks that are transferred in said email exchanges, to form a domain name that includes said digital signatures and the hash for the content of the data blocks, and to transmit said domain name as DNS requests to a central security provider server.

8. The email security device of claim 7 wherein said data blocks comprises images.

9. The email security device of claim 7 wherein said data blocks comprises file attachments.

10. A network comprising:

a plurality of user devices;

a network email server configured to enable email exchanges to and from said user devices;

a network email security device configured to filter said email exchanges, said network email security device including an algorithm component specific to generating digital signatures for contents of components of email messages and incrementing a count for each additional reception of an identical component, said network email security device having a reporting component specific to forming a domain name that includes said digital signatures for the contents of the components of the email messages and said count as a first portion of a Domain Name System(DNS) query used as a reporting vehicle whereby each query is distinguished as a unique DNS request; and

a network firewall connected along a path from the Internet and each of said user devices and said network email security devices.

11. The network of claim 10 wherein said network email security device is configured to generate a hash for data blocks that are transferred in said email exchanges, said data blocks including images and file attachments and further include a signature for verification; and

a central security provider configured as a DNS server accepting DNS requests as a reporting vehicle and transmitting security updates in the syntax of a DNS response to said DNS request.

Assignments (12)
SECURITY INTEREST Recorded Mar 17, 2025
From: BARRACUDA NETWORKS, INC.
To: OAKTREE FUND ADMINISTRATION, LLC, AS COLLATERAL AGENT
Reel/Frame 070529/0123 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 061377/0208 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 061377/0231 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN IP RECORDED AT R/F 045327/0877 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061179/0602 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN IP RECORDED AT R/F 054260/0746 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061521/0086 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 30, 2020
From: BARRAUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 054260/0746 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 045327/0934 Recorded Apr 15, 2019
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 048895/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 14, 2018
From: BARRACUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045327/0934 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 14, 2018
From: BARRACUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045327/0877 →
RELEASE OF SECURITY INTEREST Recorded Jan 8, 2018
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 045027/0870 →
SECURITY INTEREST Recorded Oct 12, 2012
From: BARRACUDA NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 029218/0107 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2009
From: LEVOW, ZACHARY; EVANS, JOSEPH WILSON
To: BARRACUDA NETWORKS, INC.
Reel/Frame 023479/0370 →