IP Library › Granted Patent US 12,021,891
Granted Patent B2
US 12,021,891 · App. 17/110,791 · Granted Jun 25, 2024

Server connection resets based on domain name server (DNS) information

Inventors: Christopher Michael Davis (Nanaimo, CA); Steven Mark Heyns (Nanaimo, CA); Paul Cornelius van Gool (Santa Barbara, CA)
Assignee: HYAS Infosec Inc.
H04L63/1441H04L61/4511H04L63/0236H04L63/0263H04L63/101H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,021,891
App. No.
17/110,791
Granted
Jun 25, 2024
Kind
B2
Abstract

Systems, methods, and software described herein manage server connection resets based on domain name server (DNS) information. In one implementation, a firewall may receive a reverse DNS request from a computing system and communicate a request to a DNS security service to determine whether a destination associated with the reverse DNS request is malicious. The firewall further receives a response from the DNS security service that indicates that the destination is malicious and, when the response indicates that the destination is malicious, communicates a reset command to the destination to reset a connection between the destination and the computing system.

Claims (31)

1. A computing apparatus:

a storage system;

a processing system operatively coupled to the storage system; and

program instructions stored on the storage system that, when executed by the processing system, direct the computing apparatus:

identify a reverse Domain Name System (DNS) request for a computing system, wherein the reverse DNS request comprises an internet protocol (IP) address associated with a server;

in response to identifying the reverse DNS request;

communicate a reset command at intervals to the server associated with the IP address to reset a connection between the server and the computing system; and

determine whether the IP address is malicious;

when the IP address is determined to be malicious, continue the communication of the reset command at intervals to the server; and

when the IP address is determined to not be malicious, stop the communication of the reset command at intervals to the server.

2. The computing apparatus of claim 1 , wherein identifying the reverse DNS request comprises receiving the reverse DNS request at a firewall.

3. The computing apparatus of claim 1 , wherein determining that the IP address is malicious comprises determining that the IP address, a uniform resource locator associated with the IP address, or a Name Server associated with the IP address is on a blacklist.

4. The computing apparatus of claim 1 , wherein determining that the IP address is malicious comprises querying a DNS security service to determine that the IP address is malicious.

5. The computing apparatus of claim 1 , wherein the reset command comprises a reset packet.

6. A method of operating a firewall comprising:

receiving a reverse Domain Name System (DNS) request from a computing system, wherein the reverse DNS request comprises an internet protocol (IP) address associated with a server;

in response to identifying the reverse DNS request:

communicating a reset command at intervals to the server associated with the IP address to reset a connection between the server and the computing system; and

querying a DNS security service to determine whether the IP address is malicious;

when the IP address is indicated to be malicious by the DNS security service, continuing the communication of the reset command at intervals to the server; and

when the IP address is indicated not to be malicious by the DNS security service, stopping the communication of the reset command at intervals to the server.

7. The method of claim 6 , wherein the reset command comprises a reset packet.

8. A method of operating a firewall comprising:

identifying a reverse Domain Name System (DNS) request from a computing system, wherein the reverse DNS request comprises an internet protocol (IP) address associated with a server;

in response to the reverse DNS request, communicating a reset command at intervals to the server associated with the IP address to reset a connection between the server and the computing system until a determination is made as to whether the IP address is malicious; and

based on the determination indicating that the IP address is not malicious, stopping the communication of the reset command at intervals to the server.

9. The method of claim 8 further comprising:

making the determination based on whether the IP address, the uniform resource locator associated with the IP address, or a Name Server associated with the IP address is on a blacklist.

10. The method of claim 8 further comprising:

making the determination based on a query to a DNS security service that provides an indication of whether the IP address is malicious.

11. The method of claim 8 , wherein the reset command comprises a reset packet.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2026
From: HYAS INFOSEC INC.
To: THREATER, INC.
Reel/Frame 074518/0777 →
SECURITY INTEREST Recorded Jul 28, 2023
From: HYAS INFOSEC INC.
To: COMMERCE, CANADIAN IMPERIAL BANK OF
Reel/Frame 064425/0663 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2022
From: DAVIS, CHRISTOPHER MICHAEL; HEYNS, STEVEN MARK; VAN GOOL, PAUL CORNELIUS
To: HYAS INFOSEC INC.
Reel/Frame 058879/0929 →
Continuity (1)
Related Publication 20220182353A1 · Jun 9, 2022