IP Library Granted Patent US 11,206,265
Granted Patent B2
US 11,206,265 · App. 16/399,252 · Granted Dec 21, 2021

Smart whitelisting for DNS security

Inventor: Renee Carol Burton (Sykesville, MD)
Assignee: Infoblox Inc.
H04L63/101H04L47/70H04L61/1511H04L63/145H04L63/1466H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,206,265
App. No.
16/399,252
Granted
Dec 21, 2021
Kind
B2
Abstract

Techniques for smart whitelisting for Domain Name System (DNS) security are provided. In some embodiments, a system/process/computer program product for smart whitelisting for DNS security in accordance with some embodiments includes receiving a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related event data; receiving a set of network related threat data, wherein the set of network related threat data includes DNS related threat data; and generating a whitelist using the set of network related event data and the set of network related threat data, wherein the whitelist includes a subset of network domains included in the DNS related event data based on a data driven model of the DNS related event data and the DNS related threat data.

Claims (53)

1. A system, comprising:

a processor configured to:

receive a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related event data;

receive a set of network related threat data, wherein the set of network related threat data includes DNS related threat data, wherein the DNS related threat data includes a DNS threat feed that is automatically filtered to determine a popularity of network domains associated with malware, and wherein the DNS related threat data includes DNS related threat data for a first enterprise network; and

generate a whitelist using the set of network related event data and the set of network related threat data, wherein the whitelist includes a subset of network domains included in the DNS related event data based on a data driven model of the DNS related event data and the DNS related threat data; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the DNS related event data includes a set of popular network domains.

3. The system recited in claim 1 , wherein the subset of network domains included in the whitelist are selected using a classifier.

4. The system recited in claim 1 , wherein the subset of network domains included in the whitelist are selected using a statistical classifier.

5. The system recited in claim 1 , wherein the processor is further configured to:

filter the DNS related event data to generate a smart whitelist, wherein the DNS related event data is automatically filtered using a classifier to exclude one or more network domains associated with malware; and

output the smart whitelist to a network device for filtering DNS requests using the smart whitelist.

6. The system recited in claim 1 , wherein the processor is further configured to:

filter the DNS related event data to generate a smart whitelist,

wherein the DNS related event data is automatically filtered using a classifier to exclude one or more network domains associated with malware; and

periodically update the smart whitelist based on another set of network related event data and another set of network related threat data,

wherein the smart whitelist is automatically and dynamically adjusted to changes in a production data environment associated with the first enterprise network.

7. The system recited in claim 1 , wherein the processor is further configured to:

identify a network domain for further evaluation to determine whether the network domain is properly included on a blacklist.

8. A method, comprising:

receiving a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related event data;

receiving a set of network related threat data, wherein the set of network related threat data includes DNS related threat data, wherein the DNS related threat data includes a DNS threat feed that is automatically filtered to determine a popularity of network domains associated with malware, and wherein the DNS related threat data includes DNS related threat data for a first enterprise network; and

generating a whitelist using the set of network related event data and the set of network related threat data, wherein the whitelist includes a subset of network domains included in the DNS related event data based on a data driven model of the DNS related event data and the DNS related threat data.

9. The method of claim 8 , wherein the DNS related event data includes a set of popular network domains.

10. The method of claim 8 , wherein the subset of network domains included in the whitelist are selected using a classifier.

11. The method of claim 8 , wherein the subset of network domains included in the whitelist are selected using a statistical classifier.

12. The method of claim 8 , further comprising:

filtering the DNS related event data to generate a smart whitelist, wherein the DNS related event data is automatically filtered using a classifier to exclude one or more network domains associated with malware; and

outputting the smart whitelist to a network device for filtering DNS requests using the smart whitelist.

13. The method of claim 8 , further comprising:

filtering the DNS related event data to generate a smart whitelist,

wherein the DNS related event data is automatically filtered using a classifier to exclude one or more network domains associated with malware; and

periodically updating the smart whitelist based on another set of network related event data and another set of network related threat data,

wherein the smart whitelist is automatically and dynamically adjusted to changes in a production data environment associated with the first enterprise network.

14. The method of claim 8 , further comprising:

identifying a network domain for further evaluation to determine whether the network domain is properly included on a blacklist.

15. A non-transitory computer readable storage medium storing instructions that when executed by a computer processor performs the following:

receiving a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related event data;

receiving a set of network related threat data, wherein the set of network related threat data includes DNS related threat data, wherein the DNS related threat data includes a DNS threat feed that is automatically filtered to determine a popularity of network domains associated with malware, and wherein the DNS related threat data includes DNS related threat data for a first enterprise network; and

generating a whitelist using the set of network related event data and the set of network related threat data, wherein the whitelist includes a subset of network domains included in the DNS related event data based on a data driven model of the DNS related event data and the DNS related threat data.

16. The non-transitory computer readable storage medium recited in claim 15 , wherein the DNS related event data includes a set of popular network domains.

17. The non-transitory computer readable storage medium recited in claim 15 , wherein the subset of network domains included in the whitelist are selected using a classifier.

18. The non-transitory computer readable storage medium recited in claim 15 , wherein the subset of network domains included in the whitelist are selected using a statistical classifier.

19. The non-transitory computer readable storage medium recited in claim 15 , further storing instructions that when executed by the computer processor performs the following:

filtering the DNS related event data to generate a smart whitelist, wherein the DNS related event data is automatically filtered using a classifier to exclude one or more network domains associated with malware; and

outputting the smart whitelist to a network device for filtering DNS requests using the smart whitelist.

20. The non-transitory computer readable storage medium recited in claim 15 , further storing instructions that when executed by the computer processor performs the following:

filtering the DNS related event data to generate a smart whitelist,

wherein the DNS related event data is automatically filtered using a classifier to exclude one or more network domains associated with malware; and

periodically updating the smart whitelist based on another set of network related event data and another set of network related threat data,

wherein the smart whitelist is automatically and dynamically adjusted to changes in a production data environment associated with the first enterprise network.

21. The non-transitory computer readable storage medium recited in claim 15 , further storing instructions that when executed by the computer processor performs the following:

identifying a network domain for further evaluation to determine whether the network domain is properly included on a blacklist.

Assignments (3)
FIRST LIEN SECURITY AGREEMENT Recorded Dec 2, 2020
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054615/0317 →
SECOND LIEN SECURITY AGREEMENT Recorded Dec 2, 2020
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054615/0331 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2019
From: BURTON, RENEE CAROL
To: INFOBLOX INC.
Reel/Frame 049705/0186 →
Continuity (1)
Related Publication 20200351270A1 · Nov 5, 2020
Cited By (2)
US 12,206,644 US 12,641,085