IP Library Granted Patent US 11,750,562
Granted Patent B2
US 11,750,562 · App. 17/344,400 · Granted Sep 5, 2023

System and method for leak prevention for domain name system requests

Inventor: Jonathan Alexander Thorold Barnett (Lafayette, CO)
Assignee: WEBROOT INC.
H04L63/0236H04L61/4511H04L63/10H04L63/20H04L67/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,750,562
App. No.
17/344,400
Granted
Sep 5, 2023
Kind
B2
Abstract

Embodiments of systems and methods for DNS leak prevention and protection are disclosed herein. In particular, certain embodiments include a local DNS protection agent installed on a system and an associated trusted external DNS protection server. The DNS protection agent prevents DNS leaks from applications on the system such that all DNS requests from the system are confined to requests from the DNS protection agent to the associated DNS protection server. As the DNS leak prevention provided by the DNS protection agent stops applications on the system from circumventing the DNS protection server, all DNS requests originating from the system remain under the control of the DNS protection server and thus desired DNS protection (e.g., as implemented on the DNS protection server) may be maintained. Certain embodiments prevent applications from using certain DNS security protocols, such as DoH and DoT, without going through the DNS protection agent.

Claims (45)

1. A method for DNS resolution, the method comprising:

on a client device, disabling access at a client operating system on the client device to a DNS resolver external to the client device;

enabling access at the client operating system by a DNS protection agent at the client device to the DNS protection agent for resolving DNS server addresses using a DNS protection server, wherein the DNS protection agent is locally installed at the client device;

generating an outbound initial DNS request by an application executing on the client device, the outbound initial DNS request designating an Internet address for an Internet resource and specifying the DNS resolver;

detecting, by the DNS protection agent at a port of the client device associated with a DNS security protocol, the outbound initial DNS request from the application;

blocking the outbound initial DNS request to the DNS resolver from the application;

receiving, at the DNS protection agent, a redirected DNS request from the application, wherein the redirected DNS request was redirected to the DNS protection agent by the operating system of the client device;

transmitting, using the DNS protection agent, the redirected DNS request to the DNS protection server to resolve the Internet address; and

receiving a response from the DNS protection server at the DNS protection agent and forwarding the response to the application on the client device.

2. The method of claim 1 , wherein the response from the DNS protection server comprises either the Internet address for the Internet resource or a denial message.

3. The method of claim 2 , wherein the response from the DNS protection server is determined based on an evaluation of a security policy associated with the client device.

4. The method of claim 3 , wherein the security policy specifies reputation scores or categories associated with domains.

5. The method of claim 1 , further comprising managing, by the DNS protection agent, a port associated with the DNS security protocol.

6. The method of claim 5 , wherein the DNS protection agent is coupled to a DNS resolver database, the DNS resolver database storing addresses of known DNS resolvers associated with the DNS security protocol.

7. The method of claim 6 , further comprising comparing, by the DNS protection agent, an address associated with an attempted communication with the addresses stored in the DNS resolver database.

8. The method of claim 7 , further comprising blocking communications with the address associated with the attempted communication if the address is associated with a known DNS resolver.

9. A system for DNS resolution, comprising:

a processor;

a computer storage device in electronic communication with the processor, the computer storage device storing instructions that, when executed by the processor, perform a method of:

on a client device, disabling access at an operating system on the client device to a DNS resolver external to the client device;

enabling access at the client operating system by a DNS protection agent at the client device to the DNS protection agent for resolving DNS server addresses using a DNS protection server, wherein the DNS protection agent is locally installed at the client device;

generating an outbound initial DNS request by an application executing on the client device, the outbound initial DNS request designating an Internet address for an Internet resource and specifying the DNS resolver;

detecting, by the DNS protection agent at a port of the client device associated with a DNS security protocol, the outbound initial DNS request from the application;

blocking the outbound initial DNS request to the DNS resolver from the application;

receiving, at the DNS protection agent, a redirected DNS request from the application, wherein the redirected DNS request was redirected to the DNS protection agent by the operating system of the client device;

transmitting, using the DNS protection agent, the redirected DNS request to the DNS protection server to resolve the Internet address; and

receiving a response from the DNS protection server at the DNS protection agent and forwarding the response to the application on the client device.

10. The system of claim 9 , wherein the response from the DNS protection server comprises either the Internet address for the Internet resource or a denial message.

11. The system of claim 10 , wherein the response from the DNS protection server is determined based on an evaluation of a security policy associated with the client device.

12. The system of claim 11 , wherein the security policy specifies reputation scores or categories associated with domains.

13. The system of claim 9 , further comprising monitoring, by the DNS protection agent, ports associated with DNS security protocols.

14. The system of claim 13 , wherein the DNS protection agent is coupled to a DNS resolver database, the DNS resolver database storing addresses of known DNS resolvers associated with the DNS security protocol.

15. The system of claim 14 , further comprising comparing, by the DNS protection agent, an address associated with an attempted connection with the addresses stored in the DNS resolver database.

16. The system of claim 15 , further comprising blocking connections with the address associated with a known DNS resolver of the known DNS resolvers.

17. A computer program product for DNS resolution, the computer program product comprising a non-transitory computer-readable medium storing instructions executable by a processor for:

on a client device, disabling access at an operating system on the client device to a DNS resolver external to the client device;

enabling access at the client operating system by a DNS protection agent at the client device to the DNS protection agent for resolving DNS server addresses using a DNS protection server, wherein the DNS protection agent is locally installed at the client device;

detecting, by the DNS protection agent at a port of the client device associated with a DNS security protocol, the outbound initial DNS request from the application;

blocking the outbound initial DNS request to the DNS resolver from the application;

receiving, at the DNS protection agent, a redirected DNS request from the application, wherein the redirected DNS request was redirected to the DNS protection agent by the operating system of the client device;

transmitting, using the DNS protection agent, the redirected DNS request to the DNS protection server to resolve the Internet address; and

receiving a response from the DNS protection server at the DNS protection agent and forwarding the response to the application on the client device.

18. The computer program product of claim 17 , wherein the instructions are further executable by the processor to cause the processor to perform managing, by the DNS protection agent, a port associated with the DNS security protocol.

19. The computer program product of claim 17 , wherein the DNS protection agent is coupled to a DNS resolver database, the DNS resolver database storing addresses of known DNS resolvers associated with the DNS security protocol.

20. The computer program product of claim 19 , further comprising comparing, by the DNS protection agent, an address associated with an attempted communication with the addresses stored in the DNS resolver database.

Assignments (4)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2021
From: BARNETT, JONATHAN ALEXANDER THOROLD
To: WEBROOT INC.
Reel/Frame 056709/0681 →
Continuity (2)
Provisional Application 63037425 · Jun 10, 2020
Related Publication 20210392110A1 · Dec 16, 2021
Cited By (2)
US 12,309,117 US 12,483,532