IP Library Granted Patent US 9,467,461
Granted Patent B2
US 9,467,461 · App. 14/138,025 · Granted Oct 11, 2016

Countering security threats with the domain name system

Inventor: Manuel A. Balderas (Arlington, MA)
Assignee: Akamai Technologies Inc.
H04L63/1416H04L61/1511H04L63/1441H04L63/0218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,467,461
App. No.
14/138,025
Granted
Oct 11, 2016
Kind
B2
Abstract

Described herein are methods, systems, and apparatus in which the functionality of a DNS server is modified to take into account security intelligence when determining an answer to return in response to a requesting client. Such a DNS server may consider a variety of security characteristics about the client and/or the client's request, as described more fully herein. Such a DNS server can react to clients in a variety of ways based on the threat assessment, preferably in a way that proactively counters or mitigates the perceived threat.

Claims (30)

1. A method operative in a domain name system (DNS) server, the method comprising:

receiving a request to resolve a domain name from a client, the client being a recursive DNS server or an end-user device, and the request including an internet protocol (IP) address of the client;

determining a threat score for the request, based at least in part on the IP address;

upon a determination that the threat score does not exceed a threshold, responding to the client's domain name resolution request with a first set of one or more IP addresses, wherein the first set of IP addresses is associated with a first set of one or more servers in a first point of presence (PoP) of a content delivery network;

upon a determination that the threat score exceeds a threshold, responding to the client's domain name resolution request with a second set of one or more IP addresses, wherein the second set of IP addresses is associated with a second set of one or more servers in a second point of presence (PoP) of the content delivery network, the second PoP being remote from the first PoP;

wherein the second set of one or more IP addresses is selected for inclusion in the response at least in part because the second set of one or more servers in the second PoP are known to have a higher latency for the client than the first set of one or more servers in the first PoP, due to relative locations of the first and the second PoPs.

2. The method of claim 1 , wherein the IP address is truncated in accordance with a netmask included in the request.

3. The method of claim 1 , wherein the client is a recursive DNS server and the IP address is associated with (i) the recursive DNS server, or (ii) an end-user device that originated the request to the recursive DNS server.

4. The method of claim 1 , wherein the client is an end-user device and the IP address is associated with the end-user device.

5. The method of claim 1 , wherein determining the threat score comprises sending the IP address to an IP address reputation service and receiving a score therefrom.

6. An apparatus, comprising:

circuitry forming one or more processors and memory holding program instructions for execution by the one or more processors, an a network interface for communicating with remote machines, the program instructions including instructions for:

receiving a request to resolve a domain name from a client, the client being a recursive DNS server or an end-user device, and the request including an IP address for the client;

determining a threat score for the request, based at least in part on the IP address;

upon a determination that the threat score does not exceed a threshold, responding to the client's domain name resolution request with a first set of one or more IP addresses, wherein the first set of IP addresses is associated with a first set of one or more servers in a first point of presence (PoP) of a content delivery network;

upon a determination that the threat score exceeds a threshold, responding to the client's domain name resolution request with a second set of one or more IP addresses, wherein the second set of IP addresses is associated with a second set of one or more servers in a second point of presence (PoP) of the content delivery network, the second PoP being remote from the first PoP

wherein the second set of one or more IP addresses is selected for inclusion in the response at least in part because the second set of one or more servers in the second PoP are known to have a higher latency for the client than the first set of one or more servers in the first PoP, due to relative locations of the first and the second PoPs.

7. The apparatus of claim 6 , wherein the IP address is truncated in accordance with a netmask included in the request.

8. The apparatus of claim 6 , wherein the client is a recursive DNS server and the IP address is associated with (i) the recursive DNS server, or (ii) an end-user device that originated the request to the recursive DNS server.

9. The apparatus of claim 6 , wherein the client is an end-user device and the IP address is associated with the end-user device.

10. The apparatus of claim 6 , wherein determining the threat score comprises sending the IP address to an IP address reputation service and receiving a score therefrom.

11. A non-transitory computer readable storage medium, storing one or more programs for execution by one or more processors of a computer apparatus, wherein the one or more programs include instructions for:

receiving a request to resolve a domain name from a client, the client being a recursive DNS server or an end-user device, and the request including an IP address for the client;

determining a threat score for the request, based at least in part on the IP address;

upon a determination that the threat score does not exceed a threshold, responding to the client's domain name resolution request with a first set of one or more IP addresses, wherein the first set of IP addresses is associated with a first set of one or more servers in a first point of presence (PoP) of a content delivery network;

upon a determination that the threat score exceeds a threshold, responding to the client's domain name resolution request with a second set of one or more IP addresses, wherein the second set of IP addresses is associated with a second set of one or more servers in a second point of presence (PoP) of the content delivery network, the second PoP being remote from the first PoP

wherein the second set of one or more IP addresses is selected for inclusion in the response at least in part because the second set of one or more servers in the second PoP will have a higher latency for the client than the first set of one or more servers in the first PoP, due to relative locations of the first and the second PoPs.

12. The computer readable storage medium of claim 11 , wherein the client is a recursive DNS server and the IP address is associated with (i) the recursive DNS server, or (ii) an end-user device that originated the request to the recursive DNS server.

13. The computer readable storage medium of claim 11 , wherein the client is an end-user device and the IP address is associated with the end-user device.

14. The computer readable storage medium of claim 11 , wherein determining the threat score comprises sending the IP address to an IP address reputation service and receiving a score therefrom.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2014
From: BALDERAS, MANUEL A.
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 032261/0883 →
Continuity (1)
Related Publication 20150180892A1 · Jun 25, 2015