IP Library Granted Patent US 11,916,942
Granted Patent B2
US 11,916,942 · App. 17/366,813 · Granted Feb 27, 2024

Automated identification of false positives in DNS tunneling detectors

Inventor: Peter Boord (Puyallup, WA)
Assignee: Infoblox Inc.
H04L63/1425H04L63/1441H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,916,942
App. No.
17/366,813
Granted
Feb 27, 2024
Kind
B2
Abstract

Techniques for automated identification of false positives in DNS tunneling detectors are disclosed. In some embodiments, a system, process, and/or computer program product for automated identification of false positives in DNS tunneling detectors includes receiving a set of passive DNS data, wherein the set of passive DNS data includes a DNS query and a DNS response for resolution of the DNS query for each of a plurality of DNS queries; extracting a plurality of features associated with each domain in the set of passive DNS data; and classifying DNS tunneling activities and performing false positive reduction using the plurality of features associated with each domain in the set of passive DNS data to reduce false positive detections.

Claims (36)

1. A system, comprising:

a processor configured to:

receive a set of passive DNS data, wherein the set of passive DNS data includes a DNS query and a DNS response for resolution of the DNS query for each of a plurality of DNS queries;

extract a plurality of features associated with each domain in the set of passive DNS; data, wherein the plurality of features includes a number of unique sub-prefixes for a domain, a total number of queries for the domain, and a time span between an earliest observation and a latest observation of a sub-prefix in the domain; and

classify DNS tunneling activities and perform false positive reduction using the plurality of features associated with each domain in the set of passive DNS data to reduce false positive; detections, wherein the classifying of the DNS tunneling activities and the performing of the false positive reduction comprises to:

classify, using a model, the DNS tunneling activities into a DNS tunnel or a non-tunnel, wherein the model is trained using sets of known tunnel domains and known domains that are not DNS tunnels; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the set of passive DNS data is preprocessed to automatically filter a set of domains included in the set of passive DNS data.

3. The system recited in claim 1 , wherein one or more of the plurality of features are based on name server information.

4. The system recited in claim 1 , wherein one or more of the plurality of features are based on a retransmission rate of queries and/or responses associated with a domain.

5. The system recited in claim 1 , wherein the processor is further configured to:

perform a mitigation action in response to detecting a malicious DNS tunneling activity.

6. The system recited in claim 1 , wherein the processor is further configured to:

detect a malicious DNS tunneling activity; and

perform a mitigation action in response to detecting the malicious DNS tunneling activity.

7. A method, comprising:

receiving a set of passive DNS data, wherein the set of passive DNS data includes a DNS query and a DNS response for resolution of the DNS query for each of a plurality of DNS queries;

extracting a plurality of features associated with each domain in the set of passive DNS; data, wherein the plurality of features includes a number of unique sub-prefixes for a domain, a total number of queries for the domain, and a time span between an earliest observation and a latest observation of a sub-prefix in the domain; and

classifying DNS tunneling activities and performing false positive reduction using the plurality of features associated with each domain in the set of passive DNS data to reduce false positive detections, wherein the classifying of the DNS tunneling activities and the performing of the false positive reduction comprises:

classifying, using a model, the DNS tunneling activities into a DNS tunnel or a non-tunnel, wherein the model is trained using sets of known tunnel domains and known domains that are not DNS tunnels.

8. The method of claim 7 , wherein the set of passive DNS data is preprocessed to automatically filter a set of domains included in the set of passive DNS data.

9. The method of claim 7 , wherein one or more of the plurality of features are based on name server information.

10. The method of claim 7 , wherein one or more of the plurality of features are based on a retransmission rate of queries and/or responses associated with a domain.

11. The method of claim 7 , further comprising:

performing a mitigation action in response to detecting a malicious DNS tunneling activity.

12. The method of claim 7 , further comprising:

detecting a malicious DNS tunneling activity; and

performing a mitigation action in response to detecting the malicious DNS tunneling activity.

13. A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

receiving a set of passive DNS data, wherein the set of passive DNS data includes a DNS query and a DNS response for resolution of the DNS query for each of a plurality of DNS queries;

extracting a plurality of features associated with each domain in the set of passive DNS data, wherein the plurality of features includes a number of unique sub-prefixes for a domain, a total number of queries for the domain, and a time span between an earliest observation and a latest observation of a sub-prefix in the domain; and

classifying DNS tunneling activities and performing false positive reduction using the plurality of features associated with each domain in the set of passive DNS data to reduce false positive detections, wherein the classifying of the DNS tunneling activities and the performing of the false positive reduction comprises:

classifying, using a model, the DNS tunneling activities into a DNS tunnel or a non-tunnel, wherein the model is trained using sets of known tunnel domains and known domains that are not DNS tunnels.

14. The computer program product recited in claim 13 , wherein the set of passive DNS data is preprocessed to automatically filter a set of domains included in the set of passive DNS data.

15. The computer program product recited in claim 13 , wherein one or more of the plurality of features are based on name server information.

16. The computer program product recited in claim 13 , wherein one or more of the plurality of features are based on a retransmission rate of queries and/or responses associated with a domain.

Assignments (3)
SECURITY AGREEMENT (FIRST LIEN) Recorded Dec 23, 2021
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 058574/0672 →
SECURITY AGREEMENT (SECOND LIEN) Recorded Dec 23, 2021
From: INFOBLOX INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS SECOND LIEN COLLATERAL AGENT
Reel/Frame 058574/0709 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2021
From: BOORD, PETER
To: INFOBLOX INC.
Reel/Frame 057675/0066 →
Continuity (2)
Provisional Application 63121756 · Dec 4, 2020
Related Publication 20220182401A1 · Jun 9, 2022