IP Library Granted Patent US 10,185,761
Granted Patent B2
US 10,185,761 · App. 15/226,250 · Granted Jan 22, 2019

Domain classification based on domain name system (DNS) traffic

Inventors: Dhia Mahjoub (San Francisco, CA); Thomas M. Mathew (Sunnyvale, CA)
Assignee: Cisco Technology, Inc.
G06F17/30598G06F17/30864H04L43/04H04L43/0876H04L61/1511H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,185,761
App. No.
15/226,250
Granted
Jan 22, 2019
Kind
B2
Abstract

Techniques are provided herein for classifying domains based on DNS traffic so that domains that are malicious or associated with malicious activity can be identified. Traffic between one or more domain name system (DNS) resolvers and one or more authoritative name servers hosted on the Internet is analyzed analyzing at a server having network connectivity. A mismatch between a hostname and Internet Protocol (IP) information for the hostname is detected in the traffic and domains included in the traffic are classified based on the detecting.

Claims (65)

1. A method comprising:

analyzing, at a server having network connectivity, traffic between one or more domain name system (DNS) resolvers and one or more authoritative name servers hosted on the Internet;

detecting, in the traffic, an Autonomous System Number (ASN) mismatch between a hostname and a second level domain name for the hostname;

extracting an Internet Protocol (IP) address from at least one of the second level domain name and the hostname;

determining a location of the IP address in a topology of ASNs based on at least one of ASN-based routing information and allocation information determined with WHOIS information;

classifying one or more domains included in the traffic as malicious based on the detecting and the location in the topology; and

blocking traffic from the one or more domains classified as malicious.

2. The method of claim 1 , further comprising:

accessing authoritative logs that contain the traffic; and

retrieving an ASN for the hostname and an ASN for the second level domain name based on the traffic included in the authoritative logs.

3. The method of claim 1 , further comprising:

extracting an IP address range associated with the hostname;

determining that the IP address range associated with the hostname is a sub-allocated IP address range; and

classifying the hostname as associated with malicious activity based on the sub-allocated IP address range.

4. The method of claim 3 , further comprising:

fingerprinting at least a portion of the IP address range; and

classifying the IP address range based on the fingerprinting.

5. The method of claim 1 , further comprising:

analyzing traffic between the one or more DNS resolvers and one or more clients; and

wherein the classifying of the one or more domains as malicious is based on the detecting of the ASN mismatch and the analyzing of the DNS traffic between the one or more DNS resolvers and one or more clients.

6. The method of claim 1 , wherein the server operates in a recursive DNS cluster.

7. An apparatus comprising:

one or more network interface units configured to enable network connectivity to the Internet;

a processor configured to:

analyze traffic between one or more domain name system (DNS) resolvers and one or more authoritative name servers hosted on the Internet;

detect, in the traffic, an Autonomous System Number (ASN) mismatch between a hostname and a second level domain name for the hostname;

extract an Internet Protocol (IP) address from at least one of the second level domain name and the hostname;

determine a location of the IP address in a topology of ASNs based on at least one of ASN-based routing information and allocation information determined with WHOIS information;

classify one or more domains included in the traffic as malicious based on detection of the mismatch and the location in the topology; and

block traffic from the one or more domains classified as malicious.

8. The apparatus of claim 7 , wherein the processor is further configured to:

access authoritative logs that contain the traffic; and

retrieve an ASN for the hostname and an ASN for the second level domain name based on the traffic included in the authoritative logs.

9. The apparatus of claim 7 , wherein the processor is further configured to:

extract an IP address range associated with the hostname;

determine that the IP address range associated with the hostname is a sub-allocated IP address range; and

classify the hostname as associated with malicious activity based on the sub-allocated IP address range.

10. The apparatus of claim 9 , wherein the processor is further configured to:

fingerprint at least a portion of the IP address range; and

classify the IP address range based on the fingerprinting.

11. The apparatus of claim 7 , wherein the processor is further configured to:

analyze traffic between the one or more DNS resolvers and one or more clients; and

classify the one or more domains as malicious based on the detection of the ASN mismatch and the analyzing of the DNS traffic between the one or more DNS resolvers and one or more clients.

12. The apparatus of claim 7 , wherein the apparatus operates in a recursive DNS cluster.

13. A non-transitory computer-readable storage media encoded with software comprising computer executable instructions and when the software is executed operable to:

analyze traffic between one or more domain name system (DNS) resolvers and one or more authoritative name servers hosted on the Internet;

detect, in the traffic, an Autonomous System Number (ASN) mismatch between a hostname and a second level domain name for the hostname;

extract an Internet Protocol (IP) address of at least one of the second level domain name and the hostname;

determine a location of the IP address in a topology of ASNs based on at least one of ASN-based routing information and allocation information determined with WHOIS information;

classify one or more domains included in the traffic as malicious based on detection of the mismatch and the location in the topology; and

block traffic from the one or more domains classified as malicious.

14. The non-transitory computer-readable storage media of claim 13 , wherein the instructions are further operable to:

access authoritative logs that contain the traffic; and

retrieve an ASN for the hostname and an ASN for the second level domain based on the traffic included in the authoritative logs.

15. The non-transitory computer-readable storage media of claim 13 , wherein the instructions are further operable to:

extract an IP address range associated with the hostname;

determine that the IP address range associated with the hostname is a sub-allocated IP address range; and

classify the hostname as associated with malicious activity based on the sub-allocated IP address range.

16. The non-transitory computer-readable storage media of claim 15 , wherein the instructions are further operable to:

fingerprint at least a portion of the IP address range; and

classify the IP address range based on the fingerprinting.

17. The non-transitory computer-readable storage media of claim 13 , wherein the instructions are further operable to:

analyze traffic between the one or more DNS resolvers and one or more clients; and

classify the one or more domains as malicious based on the detection of the mismatch and the analyzing of the DNS traffic between the one or more DNS resolvers and one or more clients.

18. The non-transitory computer-readable storage media of claim 13 , wherein the software is executed in a recursive DNS cluster.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2016
From: MAHJOUB, DHIA; MATHEW, THOMAS M.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 039316/0889 →
Continuity (3)
Provisional Application 62239661 · Oct 9, 2015
Provisional Application 62202662 · Aug 7, 2015
Related Publication 20170041333A1 · Feb 9, 2017
Cited By (2)
US 12,455,936 US 12,455,937