IP Library › Granted Patent US 11,943,196
Granted Patent B2
US 11,943,196 · App. 17/108,585 · Granted Mar 26, 2024

Detection of domain hijacking during DNS lookup

Inventors: Christopher Michael Davis (Nanaimo, CA); Steven Mark Heyns (Nanaimo, CA); Paul Cornelius van Gool (Santa Barbara, CA)
Assignee: HYAS Infosec Inc.
H04L61/4511H04L63/101H04L63/126H04L63/1483H04L2101/69
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,943,196
App. No.
17/108,585
Granted
Mar 26, 2024
Kind
B2
Abstract

The technology disclosed herein enables detection of domain hijacking when a DNS resolver is performing a DNS lookup. In a particular embodiment, a method provides, in response to a request to resolve a network address corresponding to a domain name, determining that a nameserver for the domain name is suspect based on satisfaction of nameserver criteria associated with the domain name. The method further includes preventing the nameserver from being used to resolve the request in response to determining that the nameserver is suspect.

Claims (55)

1. A method for operating a Domain Name System (DNS) resolver, comprising:

determining first characteristics of nameservers properly associated with a domain name;

generating a first hash of the nameservers;

generating nameserver criteria associated with the domain name based on the first characteristics, wherein the nameserver criteria defines whether the first characteristics are those of a suspect nameserver for the domain name;

receiving a request to resolve a network address corresponding to the domain name included in the request by a requesting system;

in response to receiving the request:

identifying current nameservers for the domain name;

generating a second hash of the current nameservers;

in response to determining the first hash does not match the second hash,

determining second characteristics of the current nameservers;

determining that at least one of the current nameservers is suspect based on application of the nameserver criteria to the second characteristics; and

preventing the at least one of the current nameservers from being used to resolve the request in response to determining that the at least one of the current nameservers is suspect.

2. The method of claim 1 , wherein the second characteristics include geographic locations of the current nameservers.

3. The method of claim 1 , wherein the second characteristics include a host associated with the current nameservers.

4. The method of claim 1 , wherein determining the second characteristics comprises:

performing a WHOIS lookup for the current nameservers.

5. The method of claim 1 , further comprising:

before the request, determining other characteristics of other nameservers properly associated with other domain names; and

generating the nameserver criteria based on the other characteristics.

6. The method of claim 1 , wherein a whitelist of domain names includes the domain name and wherein each domain name in the whitelist has corresponding nameserver criteria, wherein second nameserver criteria associated with a second domain name in the whitelist, when applied to the second characteristics, indicates that the at least one of the current nameservers is not suspect for the second domain name.

7. The method of claim 6 , further comprising:

setting a lookup cache time-to-live for the whitelist of domain names to a predetermined value that is lower than a time-to-live value for other domain names.

8. An apparatus for a Domain Name System (DNS) resolver, the apparatus comprising:

one or more computer readable storage media;

a processing system operatively coupled with the one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media that, when read and executed by the processing system, direct the processing system to:

determine first characteristics of nameservers properly associated with a domain name;

generate a first hash of the nameservers;

generate nameserver criteria associated with the domain name based on the first characteristics, wherein the nameserver criteria defines whether the first characteristics are those of a suspect nameserver for the domain name;

receive a request to resolve a network address corresponding to the domain name included in the request by a requesting system;

in response to receiving the request:

identify current nameservers for the domain name;

generate a second hash of the current nameservers;

in response to determining the first hash does not match the second hash, determine second characteristics of the current nameservers;

determine that at least one of the current nameservers is suspect based on application of the nameserver criteria to the second characteristics; and

prevent the at least one of the current nameservers from being used to resolve the request in response to determining that the at least one of the current nameservers is suspect.

9. The apparatus of claim 8 , wherein the second characteristics include geographic locations of the current nameservers.

10. The apparatus of claim 8 , wherein the second characteristics include a host associated with the current nameservers.

11. The apparatus of claim 8 , wherein to determine the second characteristics, the program instructions direct the processing system to:

perform a WHOIS lookup for the current nameservers.

12. The apparatus of claim 8 , wherein the program instructions further direct the processing system to:

before the request, determine other characteristics of other nameservers properly associated with other domain names; and

generate the nameserver criteria based on the other characteristics.

13. The apparatus of claim 8 , wherein a whitelist of domain names includes the domain name and wherein each domain name in the whitelist has corresponding nameserver criteria.

14. One or more non-transitory computer readable storage media having program instructions stored thereon for a Domain Name System (DNS) resolver, the program instructions, when read and executed by a processing system, direct the processing system to:

determine first characteristics of nameservers properly associated with a domain name;

generate a first hash of the nameservers;

generate nameserver criteria associated with the domain name based on the first characteristics, wherein the nameserver criteria defines whether the first characteristics are those of a suspect nameserver for the domain name;

receive a request to resolve a network address corresponding to the domain name included in the request by a requesting system;

in response to receiving the request:

identify current nameservers for the domain name;

generate a second hash of the current nameservers;

in response to determining the first hash does not match the second hash, determine second characteristics of the current nameservers;

determine that at least one of the current nameservers is suspect based on application of the nameserver criteria to the second characteristics; and

prevent the at least one of the current nameservers from being used to resolve the request in response to determining that the at least one of the current nameservers is suspect.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2026
From: HYAS INFOSEC INC.
To: THREATER, INC.
Reel/Frame 074518/0777 →
SECURITY INTEREST Recorded Jul 28, 2023
From: HYAS INFOSEC INC.
To: COMMERCE, CANADIAN IMPERIAL BANK OF
Reel/Frame 064425/0663 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2020
From: DAVIS, CHRISTOPHER MICHAEL; HEYNS, STEVEN MARK; VAN GOOL, PAUL CORNELIUS
To: HYAS INFOSEC INC.
Reel/Frame 054507/0337 →
Continuity (1)
Related Publication 20220174031A1 · Jun 2, 2022