IP Library Granted Patent US 11,652,792
Granted Patent B2
US 11,652,792 · App. 16/668,861 · Granted May 16, 2023

Endpoint security domain name server agent

Inventor: Gandhi Balasubramaniam (Shalimar, FL)
Assignee: Avast Software s.r.o.
H04L63/0236H04L61/4511H04L63/0263H04L63/1483H04L63/20H04L67/02H04L67/1036H04L61/59H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,652,792
App. No.
16/668,861
Granted
May 16, 2023
Kind
B2
Abstract

A network is secured by managing domain name requests such that client devices are restricted from visiting malicious or undesirable domains. An endpoint Domain Name Server (DNS) agent is installed on client devices on a local network, and the endpoint DNS agents intercept DNS requests from the client devices and process the received DNS request in the endpoint DNS agent based on a security policy set for the client device via the endpoint DNS agent. In a further example processing the received DNS request comprises identifying the client device, end user, and the DNS request to a cloud-based DNS server, and processing a response received from the cloud-based DNS server received in response to the DNS request. The endpoint DNS agent is further operable to distinguish between DNS requests for local domains and remote domains, and to redirect DNS requests for local domains to a local network DNS server.

Claims (26)

1. A method of securing network devices by managing Domain Name Server (DNS) requests, comprising:

installing an endpoint Domain Name Server (DNS) agent on a client device on a local network;

receiving a security policy from a cloud-based DNS server running endpoint DNS support software configured to communicate with the endpoint DNS agent;

receiving a DNS request from the client device in the endpoint DNS agent;

processing the received DNS request in the endpoint DNS agent based on the security policy set for the client device via the endpoint DNS agent, wherein processing the received DNS request comprises identifying the client device;

sending the identified client device and the DNS request to the cloud-based DNS server, wherein the cloud-based DNS server is operable to return a response to the DNS request to the endpoint DNS agent; and

wherein the endpoint DNS agent is operable to distinguish between DNS requests for systems behind a firewall or gateway and systems outside the firewall or gateway and to resolve local addresses behind the firewall or gateway and redirect DNS requests for systems behind the firewall or gateway to a local network DNS server.

2. The method of securing network devices by managing DNS requests of claim 1 , wherein the response to the DNS request comprises: an IP address for the requested domain itself or an IP address for a tunnel server configured to process material from the requested domain.

3. The method of securing network devices by managing DNS requests of claim 1 , wherein the returned response to the DNS request comprises an IP address associated with a domain name comprising part of the DNS request.

4. The method of securing network devices by managing DNS requests of claim 1 , further comprising allowing a user of the client device to override a DNS redirection returned in response to the DNS request.

5. The method of securing network devices by managing DNS requests of claim 1 , wherein the endpoint DNS agent is operable to process received DNS requests irrespective of whether the client device is behind a firewall or gateway.

6. A method of securing network client devices in a cloud-based DNS server, comprising:

receiving a DNS request from an endpoint Domain Name Server (DNS) agent on a client device on a local network, the DNS request comprising a domain name and a client identity;

running, on the cloud-based DNS server, endpoint DNS support software configured to communicate with the endpoint DNS agent;

processing the received DNS request in compliance with a security policy associated with the client identity to generate a result, wherein the security policy set via the DNS agent it received from a cloud-based DNS server;

sending a reply comprising the result to the endpoint DNS agent on the client device; and

wherein the endpoint DNS agent is operable to distinguish between DNS requests for systems behind a firewall or gateway and systems outside the firewall or gateway and to resolve local addresses behind the firewall or gateway and redirect DNS requests for systems behind the firewall or gateway to a local network DNS server.

7. The method of securing network client devices in a cloud-based DNS server of claim 6 , wherein the reply comprises at least one of an IP address associated with the domain name, and a response indicating the requested domain name is a security risk.

8. The method of securing network client devices in a cloud-based DNS server of claim 6 , wherein the client identity comprises at least one of an identity of the client device and an identity of a user of the client device.

9. The method of securing network client devices in a cloud-based DNS server of claim 6 , wherein the security policy is set via an administrator of the client device.

10. The method of securing network client devices in a cloud-based DNS server of claim 6 , wherein the cloud-based DNS server is operable to receive requests from the client device and respond to such requests irrespective of whether the client device is behind a firewall or gateway.

11. A network client device comprising an endpoint DNS agent, comprising:

a hardware processor and a hardware memory; and

an endpoint Domain Name Server (DNS) module comprising instructions executable on the hardware processor of the client device, the endpoint DNS module operable to receive a DNS request from the client device and process the received DNS request based on a security policy set for the client device via the endpoint DNS agent, wherein the security policy set via the DNS agent is received from a cloud-based DNS server and wherein processing the received DNS request comprises identifying the DNS request and at least one of a client device identity and a client device user identity to the cloud-based DNS server operable to return and response to the DNS request; and

wherein the endpoint DNS module is operable to distinguish between DNS requests for systems behind a firewall or gateway and systems outside the firewall or gateway and to resolve local addresses behind the firewall or gateway and redirect DNS requests for systems behind the firewall or gateway to a local network DNS server.

12. The network client device comprising an endpoint DNS agent of claim 11 , wherein the endpoint DNS agent is further operable to process received DNS requests irrespective of whether the client device is behind a firewall or gateway.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: GEN DIGITAL AMERICAS S.R.O.
To: GEN DIGITAL INC.
Reel/Frame 071771/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: AVAST SOFTWARE S.R.O.
To: GEN DIGITAL AMERICAS S.R.O.
Reel/Frame 071777/0341 →
RELEASE OF SECURITY INTEREST Recorded Mar 26, 2021
From: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
To: AVAST SOFTWARE, S.R.O.
Reel/Frame 055726/0435 →
SECURITY INTEREST Recorded May 6, 2020
From: AVAST SOFTWARE S.R.O.
To: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
Reel/Frame 052582/0285 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2019
From: BALASUBRAMANIAM, GANDHI
To: AVAST SOFTWARE S.R.O.
Reel/Frame 050970/0424 →
Continuity (1)
Related Publication 20210136037A1 · May 6, 2021