IP Library › Granted Patent US 11,489,814
Granted Patent B1
US 11,489,814 · App. 17/198,162 · Granted Nov 1, 2022

Customized domain name resolution for virtual private clouds

Inventors: Matthew Engskow (Arlington, VA); Kiran Thunga (Ashburn, VA); Vikram Saurabh (Broadlands, VA); Yu Wang (Falls Church, VA); Huida Tao (Herndon, VA); Rishi Goel (Cerritos, CA); Kevis Tsao (Reston, VA); Abhay Raina (Herndon, VA); Alexander Thomas Herrick (Herndon, VA); Jeffrey J Damick (South Riding, VA); Hemakshi Sharma (Rancho Palos Verdes, CA)
Assignee: Amazon Technologies, Inc.
H04L63/0236H04L41/22H04L61/4511H04L63/0263H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,489,814
App. No.
17/198,162
Granted
Nov 1, 2022
Kind
B1
Abstract

Methods, systems, and computer-readable media for customized domain name resolution for virtual private clouds are disclosed. A domain name system (DNS) resolution service receives a DNS request from a computing resource associated with a virtual private cloud (VPC) in a cloud provider network. The service determines that the VPC is associated with one or more firewall rules. Responsive to determining that the VPC is associated with the firewall rule(s), the service determines whether the DNS request is allowed or blocked according to the one or more firewall rules. If the DNS request is allowed, the service resolves the DNS request using a DNS server and returns a response to the computing resource. If the DNS request is blocked, the service does not resolve the DNS request.

Claims (55)

1. A system, comprising:

a domain name system (DNS) resolution service comprising one or more processors and one or more memories to store computer-executable instructions that, when executed, cause the one or more processors to:

receive a DNS request from a virtual private cloud (VPC) comprising one or more computing resources, wherein the one or more computing resources are implemented using one or more resource pools of a cloud provider network, and wherein the DNS resolution service is implemented as a service of the cloud provider network;

determine that the VPC is associated with one or more firewall rules, wherein the one or more firewall rules comprise one or more domain names and one or more actions associated with the one or more domain names;

responsive to determining that the VPC is associated with the one or more firewall rules, use a firewall instance to determine whether the DNS request is allowed or blocked according to the one or more firewall rules;

if the DNS request is allowed, resolve the DNS request using a DNS server; and

if the DNS request is blocked, return a response to the VPC without resolving the DNS request.

2. The system as recited in claim 1 , further comprising:

a rule customizer comprising an additional one or more processors and an additional one or more memories to store additional computer-executable instructions that, when executed, cause the additional one or more processors to:

determine the one or more domain names and the one or more actions of the one or more firewall rules based at least in part on input to a user interface;

determine an association between the VPC and the one or more firewall rules based at least in part on additional input to the user interface;

deploy, to the DNS resolution service via one or more networks, the association between the VPC and the one or more firewall rules; and

deploy, to the firewall instance via one or more networks, the one or more firewall rules.

3. The system as recited in claim 1 , wherein the one or more memories store additional computer-executable instructions that, when executed, cause the one or more processors to:

store an association between the one or more firewall rules and a plurality of VPCs including the VPC; and

use the one or more firewall rules to determine whether to allow or block a plurality of additional DNS requests for the plurality of VPCs.

4. The system as recited in claim 3 , wherein the plurality of VPCs are implemented in a plurality of availability zones of the cloud provider network.

5. A method, comprising:

receiving, by a domain name system (DNS) resolution service, a DNS request from a computing resource associated with a virtual private cloud (VPC) in a cloud provider network;

determining, by the DNS resolution service, that the VPC is associated with one or more firewall rules;

responsive to determining that the VPC is associated with the one or more firewall rules, determining, by the DNS resolution service, the DNS request is allowed or blocked according to the one or more firewall rules; and

resolving, by the DNS resolution service, the DNS request using a DNS server and returning a response to the DNS request to the computing resource if the DNS request is allowed; and

wherein the DNS request is not resolved by the DNS resolution service if the DNS request is blocked.

6. The method as recited in claim 5 , wherein an individual one of the one or more firewall rules comprises one or more domain names and one or more allow actions associated with individual ones of the one or more domain names.

7. The method as recited in claim 5 , wherein an individual one of the one or more firewall rules comprises one or more domain names and one or more block actions associated with individual ones of the one or more domain names.

8. The method as recited in claim 5 , wherein firewall protection is selected and the one or more firewall rules are determined based at least in part on input from an administrator of the VPC.

9. The method as recited in claim 5 , wherein determining whether the DNS request is allowed or blocked according to the one or more firewall rules is performed using a firewall instance, wherein the DNS resolution service stores an association between the VPC and the one or more firewall rules, and wherein the firewall instance stores the one or more firewall rules.

10. The method as recited in claim 9 , further comprising:

determining, using a rule customizer, one or more domain names and one or more actions of the one or more firewall rules based at least in part on input to a user interface;

determining, using the rule customizer, the association between the VPC and the one or more firewall rules based at least in part on additional input to the user interface;

deploying, from the rule customizer to the DNS resolution service via one or more networks, the association between the VPC and the one or more firewall rules; and

deploying, from the rule customizer to the firewall instance via one or more networks, the one or more firewall rules.

11. The method as recited in claim 5 , further comprising:

storing an association between the one or more firewall rules and a plurality of VPCs including the VPC; and

using the one or more firewall rules to determine whether to allow or block a plurality of additional DNS requests for the plurality of VPCs.

12. The method as recited in claim 11 , wherein the plurality of VPCs are implemented in a plurality of availability zones of the provider network.

13. The method as recited in claim 5 , wherein the DNS resolution service is implemented as a service of the cloud provider network.

14. One or more non-transitory computer-readable storage media storing program instructions that, when executed on or across one or more processors, perform:

receiving, by a domain name system (DNS) resolver, a DNS request from a virtual private cloud (VPC) comprising one or more computing resources and implemented using one or more resource pools of a multi-tenant provider network, wherein the DNS resolver is implemented using a service of the multi-tenant provider network;

determining, by the DNS resolver, that the VPC is associated with one or more firewall rules, wherein the one or more firewall rules comprise one or more domain names and one or more actions associated with the one or more domain names;

determining, by the DNS resolver based at least in part on determining that the VPC is associated with the one or more firewall rules, whether the DNS request is allowed or blocked according to the one or more firewall rules;

if the DNS request is allowed, resolving, by the DNS resolver, the DNS request using a DNS server; and

if the DNS request is blocked, returning, by the DNS resolver, a response to the DNS request without resolving the DNS request.

15. The one or more non-transitory computer-readable storage media as recited in claim 13 , wherein an individual one of the one or more firewall rules comprises one or more domain names and one or more allow actions or block actions associated with individual ones of the one or more domain names.

16. The one or more non-transitory computer-readable storage media as recited in claim 13 , wherein firewall protection is selected and the one or more firewall rules are determined based at least in part on input from an administrator of the VPC.

17. The one or more non-transitory computer-readable storage media as recited in claim 13 , wherein determining whether the DNS request is allowed or blocked according to the one or more firewall rules is performed using a firewall instance, wherein the DNS resolver stores an association between the VPC and the one or more firewall rules, and wherein the firewall instance stores the one or more firewall rules.

18. The one or more non-transitory computer-readable storage media as recited in claim 17 , further comprising additional program instructions that, when executed on or across the one or more processors, perform:

determining, using a rule customizer, one or more domain names and one or more actions of the one or more firewall rules based at least in part on input to a user interface;

determining, using the rule customizer, the association between the VPC and the one or more firewall rules based at least in part on additional input to the user interface;

deploying, from the rule customizer to the DNS resolver via one or more networks, the association between the VPC and the one or more firewall rules; and

deploying, from the rule customizer to the firewall instance via one or more networks, the one or more firewall rules.

19. The one or more non-transitory computer-readable storage media as recited in claim 14 , further comprising additional program instructions that, when executed on or across the one or more processors, perform:

storing an association between the one or more firewall rules and a plurality of VPCs including the VPC; and

using the one or more firewall rules to determine whether to allow or block a plurality of additional DNS requests for the plurality of VPCs.

20. The one or more non-transitory computer-readable storage media as recited in claim 14 , wherein the one or more firewall rules are selected from a store offering a plurality of firewall rules published by a plurality of firewall rule publishers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2022
From: ENGSKOW, MATTHEW; THUNGA, KIRAN; SAURABH, VIKRAM; WANG, YU; TAO, HUIDA; GOEL, RISHI; RAINA, ABHAY; HERRICK, ALEXANDER THOMAS; DAMICK, JEFFREY J; SHARMA, HEMAKSHI
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 061227/0037 →
Cited By (4)
US 12,289,289 US 12,407,643 US 12,596,593 US 12,719,923