IP Library Patent Application 15226242
Patent Application
App. No. 15/226,242

DOMAIN CLASSIFICATION BASED ON DOMAIN NAME SYSTEM (DNS) TRAFFIC

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/226,242
Abstract

Techniques are provided herein for classifying domains based on DNS traffic so that domains that are malicious or associated with malicious activity can be identified. Malicious domains are identified by analyzing, at a server having network connectivity, traffic between one or more clients and one or more Domain Name System (DNS) resolvers, detecting a spike in the traffic for a particular domain, and categorizing queries in the spike based on one or more query features. The particular domain is classified based on the categorizing.

Claims (62)

1 . A method comprising:

analyzing, at a server having network connectivity, traffic between one or more clients and one or more domain name system (DNS) resolvers;

detecting a spike in the traffic for a particular domain;

categorizing queries in the spike based on one or more query features; and

classifying the particular domain based on the categorizing.

2 . The method of claim 1 , further comprising:

accessing query logs that contain the traffic, wherein the query logs include Internet Protocol (IP) addresses of the one more clients issuing the queries and hostnames requested by the queries.

3 . The method of claim 1 , wherein classifying comprises classifying the particular domain as malicious based on the categorizing, and further comprising:

blocking traffic to the one or more clients from the particular domain.

4 . The method of claim 1 , wherein categorizing is based on at least one of:

a number of client Internet Protocol (IP) addresses queried by the queries in the spike;

a number or resolvers that received the queries in the spike; and

a query type of the queries in the spike.

5 . The method of claim 1 , wherein detecting a spike further comprises:

determining a moving average in a volume of the traffic; and

detecting a deviation from the moving average that is above a predetermined threshold.

6 . The method of claim 1 , wherein categorizing further comprises:

analyzing the queries in the spike in view of historical traffic for the particular domain.

7 . The method of claim 1 , further comprising:

pivoting around hosting structures associated with the particular domain to locate additional malicious domains when the particular domain is classified as malicious.

8 . An apparatus comprising:

one or more network interface units configured to enable network connectivity to the Internet; and

a processor configured to:

analyze traffic between one or more clients and one or more domain name system (DNS) resolvers;

detect a spike in the traffic for a particular domain;

categorize queries in the spike based on one or more query features; and

classify the particular domain based on categorized queries.

9 . The apparatus of claim 8 , wherein the processor is further configured to:

access query logs that contain the traffic, wherein the query logs include Internet Protocol (IP) addresses of the one more clients issuing the queries and hostnames requested by the queries.

10 . The apparatus of claim 8 , wherein the processor is further configured to:

classify the particular domain as malicious based on categorized queries, and block traffic from the particular domain.

11 . The apparatus of claim 8 , wherein the processor is configured to categorize queries based on at least one of:

a number of client Internet Protocol (IP) addresses queried by the queries in the spike;

a number or resolvers that received the queries in the spike; and

a query type of the queries in the spike.

12 . The apparatus of claim 8 , wherein, the processor is configured to detect a spike by:

determining a moving average in a volume of the traffic; and

detecting a deviation from the moving average that is above a predetermined threshold.

13 . The apparatus of claim 8 , wherein the processor is further configured to categorize queries by:

analyzing the queries in the spike in view of historical traffic for the particular domain.

14 . The apparatus of claim 8 , wherein the processor is further configured to:

pivot around hosting structures associated with the particular domain to locate additional malicious domains when the particular domain is classified as malicious.

15 . A non-transitory computer-readable storage media encoded with software comprising computer executable instructions and when the software is executed operable to:

analyze traffic between one or more clients and one or more domain name system (DNS) resolvers;

detect a spike in the traffic for a particular domain;

categorize queries in the spike based on one or more query features; and

classify the particular domain based on categorized queries.

16 . The non-transitory computer-readable storage media of claim 15 , wherein the instructions are further operable to:

access query logs that contain the traffic, wherein the query logs include Internet Protocol (IP) addresses of the one more clients issuing the queries and hostnames requested by the queries.

17 . The non-transitory computer-readable storage media of claim 15 , wherein the instructions are further operable to:

classify the particular domain as malicious based on categorized queries;

block traffic from the particular domain; and

pivot around hosting structures associated with the particular domain to locate additional malicious domains.

18 . The non-transitory computer-readable storage media of claim 15 , wherein the instructions operable to categorize are based on at least one of:

a number of client Internet Protocol (IP) addresses queried by the queries in the spike;

a number or resolvers that received the queries in the spike; and

a query type of the queries in the spike.

19 . The non-transitory computer-readable storage media of claim 15 , wherein the instructions operable to detect a spike further comprise instructions operable to:

determine a moving average in a volume of the traffic; and

detect a deviation from the moving average that is above a predetermined threshold.

20 . The non-transitory computer-readable storage media of claim 15 , wherein the instructions operable to categorize further comprise instructions operable to:

analyze the queries in the spike in view of historical traffic for the particular domain.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2016
From: MAHJOUB, DHIA; MATHEW, THOMAS M.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 039316/0972 →