IP Library Granted Patent US 8,631,489
Granted Patent B2
US 8,631,489 · App. 13/358,303 · Granted Jan 14, 2014

Method and system for detecting malicious domain names at an upper DNS hierarchy

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,631,489
App. No.
13/358,303
Granted
Jan 14, 2014
Kind
B2
Abstract

A method and system for detecting a malicious domain name, comprising: collecting domain name statistical information from a non-recursive domain name system name server (RDNS NS); and utilizing the collected domain name statistical information to determine if a domain name is malicious or benign.

Claims (31)

1. A method for detecting a malicious domain name, comprising:

performing processing associated with collecting domain name statistical information from a non-recursive domain name system name server (non-RDNS NS), the domain name statistical information based on first order statistical features, the first order statistical features comprising: mean, standard deviation, variance of requesters for a domain name, domain name statistical information on diversity of IP addresses associated with a recursive device that queries a domain name d, a relative volume of queries from a set of a querying recursive device and historic information related to a IP space pointed to by the domain d; and

performing processing associated with utilizing the collected domain name statistical information to determine query patterns at an upper domain name system hierarchy to determine if a domain name is malicious or benign, the upper domain name system hierarchy comprising: an authoritative name server level, a top-level domain name server level, a root name server level, or any combination thereof.

2. The method of claim 1 , wherein the domain name statistical information comprises requester diversity information, or requester profile information, or both.

3. The method of claim 2 , wherein the domain name statistical information also comprises reputation information.

4. The method of claim 3 , wherein the reputation information classifies a domain name as malignant or benign utilizing historic information about domain name resolution.

5. The method of claim 2 , wherein the requester diversity information comprises diversity in terms of a network location of the recursive device that queries a domain name.

6. The method of claim 2 , wherein the requester profile information comprises a level of popularity of the querying recursive device that queries a domain name.

7. The method of claim 1 , further comprising:

performing processing associated with determining whether an additional domain name is malicious based on how close the additional domain name's statistical information is to the known malicious domain name's statistical information.

8. The method of claim 7 , wherein the additional domain name is a new domain name.

9. The method of claim 1 , wherein collecting domain name information from the non-RDNS NS comprises monitoring DNS traffic flowing towards the non-RDNS NS.

10. The method of claim 9 , wherein monitoring DNS traffic flowing towards the non-RDNS NS allows monitoring of DNS queries from servers around the Internet that attempt to resolve a domain name for which the non-RDNS NS has authority or is a point of delegation.

11. The method of claim 1 , wherein a sensor is attached to or by the non-RDNS NS.

12. The method of claim 1 , wherein a DNS operator is able to detect and remediate a malicious domain name within his or her name space.

13. A system for detecting a malicious domain name, comprising:

a processing device configured for:

performing processing associated with collecting domain name statistical information from a non-recursive domain name system name server (non-RDNS NS) in communication with the processing device, the domain name statistical information based on first order statistical features, the first order statistical features comprising: mean, standard deviation, variance of requesters for a domain name, domain name statistical information on diversity of IP addresses associated with a recursive device that queries a domain name d, a relative volume of queries from a set of a querying recursive devices, and historic information related to a IP space pointed to by the domain d; and

performing processing associated with utilizing the collected domain name statistical information to determine query patterns at an upper domain name system hierarchy to determine if a domain name is malicious or benign, the upper domain name system hierarchy comprising: an authoritative name server level, a top-level domain name server level, a root name server level, or any combination thereof.

14. The system of claim 13 , wherein the domain name statistical information comprises requester diversity information, or requester profile information, or both.

15. The system of claim 14 , wherein the domain name statistical information also comprises reputation information.

16. The system of claim 15 , wherein the reputation information classifies a domain name as malignant or benign utilizing historic information about domain name resolution.

17. The system of claim 14 , wherein the requester diversity information comprises diversity in terms of network location of the recursive device that queries a domain name.

18. The system of claim 14 , wherein the requester profile information comprises a level of popularity of the querying recursive devices that queries a domain name.

19. The system of claim 13 , further comprising:

performing processing associated with determining whether an additional domain name is malicious based on how close the additional domain name's statistical information is to the known malicious domain name's statistical information.

20. The system of claim 19 , wherein the additional domain name is a new domain name.

21. The system of claim 13 , wherein collecting domain name information from the non-RDNS NS comprises monitoring DNS traffic flowing towards the non-RDNS NS.

22. The system of claim 21 , wherein monitoring DNS traffic flowing towards the non-RDNS NS allows monitoring of DNS queries from servers around the Internet that attempt to resolve a domain name for which the non-RDNS NS has authority or is a point of delegation.

23. The system of claim 13 , wherein a sensor is attached to or by the non-RDNS NS.

24. The system of claim 13 , wherein a DNS operator is able to detect and remediate a malicious domain name within his or her name space.

Assignments (20)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0861 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: FORTRA, LLC (FORMERLY KNOWN AS HELP/SYSTEMS, LLC)
Reel/Frame 073783/0406 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0911 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERV ICES LLC
To: FORTRA, LLC (F/K/A HELP/SYSTEMS, LLC)
Reel/Frame 073662/0442 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: DAMBALLA, INC.
Reel/Frame 070086/0189 →
CHANGE OF NAME Recorded Dec 15, 2022
From: HELP/SYSTEMS, LLC
To: FORTRA, LLC
Reel/Frame 062136/0777 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0861 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0911 →
RELEASE OF SECURITY INTEREST Recorded Nov 13, 2019
From: PNC BANK, NATIONAL ASSOCIATION
To: DAMBALLA, INC.
Reel/Frame 050993/0035 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2019
From: DAMBALLA, INC.
To: HELP/SYSTEMS, LLC
Reel/Frame 048386/0329 →
RELEASE OF SECURITY INTEREST Recorded Jan 4, 2018
From: SARATOGA INVESTMENT CORP. SBIC LP
To: DAMBALLA, INC.
Reel/Frame 044535/0907 →
SECURITY INTEREST Recorded Dec 27, 2017
From: DAMBALLA, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 044492/0654 →
PATENT SECURITY AGREEMENT Recorded Oct 10, 2016
From: DAMBALLA, INC.
To: SARATOGA INVESTMENT CORP. SBIC LP, AS ADMINISTRATIVE AGENT
Reel/Frame 040297/0988 →
RELEASE OF SECURITY INTEREST Recorded Sep 8, 2016
From: SILICON VALLEY BANK
To: DAMBALLA, INC.
Reel/Frame 039678/0960 →
SECURITY INTEREST Recorded May 14, 2015
From: DAMBALLA, INC.
To: SILICON VALLEY BANK
Reel/Frame 035639/0136 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2012
From: ANTONAKAKIS, MANOS; PERDISCI, ROBERTO; LEE, WENKE; VASILOGLOU, NIKOLAOS, II
To: DAMBALLA, INC.
Reel/Frame 027990/0095 →