IP Library Granted Patent US 11,818,167
Granted Patent B2
US 11,818,167 · App. 17/509,829 · Granted Nov 14, 2023

Authoritative domain name system (DNS) server responding to DNS requests with IP addresses selected from a larger pool of IP addresses

Inventors: Lee Hahn Holloway (Santa Cruz, CA); Srikanth N. Rao (San Francisco, CA); Matthew Browning Prince (San Francisco, CA); Matthieu Philippe François Tourne (San Francisco, CA); Ian Gerald Pye (Santa Cruz, CA); Ray Raymond Bejjani (San Francisco, CA); Terry Paul Rodery, Jr. (Millbrae, CA)
Assignee: CLOUDFLARE, INC.
H04L63/1458G06F21/552G06F21/577H04L63/0281H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1466H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,818,167
App. No.
17/509,829
Granted
Nov 14, 2023
Kind
B2
Abstract

An authoritative DNS server receives DNS requests for domains. The authoritative DNS server responds to the requests with address records that include IP addresses that are selected from a larger pool of IP addresses, where a first response to a DNS query for a domain can include IP addresses different from IP addresses included in a second response for the same domain. Also, the same IP addresses may be returned for a first domain and a different, second domain. The authoritative DNS server may randomly select the IP addresses to include in responses to the requests regardless of the domain.

Claims (44)

1. A method, comprising:

receiving, at an authoritative domain name system (DNS) server from a first requester, a first DNS request for a first domain;

responding to the first DNS request to the first requester with a first plurality of address resource records, wherein the first plurality of address resource records respectively includes a first plurality of IP addresses that are selected randomly from a second plurality of IP addresses, wherein a second number of the second plurality of IP addresses is greater than a first number of the first plurality of IP addresses;

receiving, at the authoritative DNS server from a second requester, a second DNS request for the first domain; and

responding to the second DNS request to the second requester with a second plurality of address resource records, wherein the second plurality of address resource records respectively includes a third plurality of IP addresses that are selected randomly from the second plurality of IP addresses, wherein the second number of the second plurality of IP addresses is greater than a third number of the third plurality of IP addresses, and wherein the first plurality of IP addresses and the third plurality of IP addresses are different.

2. The method of claim 1 , wherein the second number of the second plurality of IP addresses is over one thousand.

3. The method of claim 1 , wherein the first plurality of address resource records is less than six address resource records, and wherein the second plurality of address resource records is less than six address resource records.

4. The method of claim 1 , further comprising:

receiving, at the authoritative DNS server from a third requester, a third DNS request for a second domain, wherein the first domain and the second domain are different; and

responding to the third DNS request to the third requester with a third plurality of address resource records, wherein the third plurality of address resource records respectively includes a fourth plurality of IP addresses that are selected from the second plurality of IP addresses, wherein the second number of the second plurality of IP addresses is greater than a fourth number of the fourth plurality of IP addresses, and wherein the fourth plurality of IP addresses includes at least some overlapping IP addresses with the first plurality of IP addresses.

5. The method of claim 1 , further comprising:

determining that there is traffic indicative of a denial-of-service (DoS) attack directed to one of the second plurality of IP addresses, and responsive to this determination, rate limiting or blocking traffic directed to that one of the second plurality of IP addresses.

6. The method of claim 1 , further comprising:

determining that there is traffic indicative of a denial-of-service (DoS) attack directed o the first domain, and responsive to this determination, rate limiting a number of connections to the second plurality of IP addresses for the domain to a historical normal traffic level of the domain divided by the number of second plurality of IP addresses.

7. A non-transitory computer-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to perform operations comprising:

receiving, at an authoritative domain name system (DNS) server from a first requester, a first DNS request for a first domain;

responding to the first DNS request to the first requester with a first plurality of address resource records, wherein the first plurality of address resource records respectively includes a first plurality of IP addresses that are selected randomly from a second plurality of IP addresses, wherein a second number of the second plurality of IP addresses is greater than a first number of the first plurality of IP addresses;

receiving, at the authoritative DNS server from a second requester, a second DNS request for the first domain; and

responding to the second DNS request to the second requester with a second plurality of address resource records, wherein the second plurality of address resource records respectively includes a third plurality of IP addresses that are selected randomly from the second plurality of IP addresses, wherein the second number of the second plurality of IP addresses is greater than a third number of the third plurality of IP addresses, and wherein the first plurality of IP addresses and the third plurality of IP addresses are different.

8. The non-transitory computer-readable storage medium of claim 7 , wherein the second number of the second plurality of IP addresses is over one thousand.

9. The non-transitory computer-readable storage medium of claim 7 , wherein the first plurality of address resource records is less than six address resource records, and wherein the second plurality of address resource records is less than six address resource records.

10. The non-transitory computer-readable storage medium of claim 7 , wherein the operations further comprise:

receiving, at the authoritative DNS server from a third requester, a third DNS request for a second domain, wherein the first domain and the second domain are different; and

responding to the third DNS request to the third requester with a third plurality of address resource records, wherein the third plurality of address resource records respectively includes a fourth plurality of IP addresses that are selected from the second plurality of IP addresses, wherein the second number of the second plurality of IP addresses is greater than a fourth number of the fourth plurality of IP addresses, and wherein the fourth plurality of IP addresses includes at least some overlapping IP addresses with the first plurality of IP addresses.

11. The non-transitory computer-readable storage medium of claim 7 , wherein the operations further comprise:

determining that there is traffic indicative of a denial-of-service (DoS) attack directed to one of the second plurality of IP addresses, and responsive to this determination, rate limiting or blocking traffic directed to that one of the second plurality of IP addresses.

12. The non-transitory computer-readable storage medium of claim 7 , wherein the operations further comprise:

determining that there is traffic indicative of a denial-of-service (DoS) attack directed o the first domain, and responsive to this determination, rate limiting a number of connections to the second plurality of IP addresses for the domain to a historical normal traffic level of the domain divided by the number of second plurality of IP addresses.

13. An authoritative domain name system (DNS) server, comprising:

a processor; and

a non-transitory machine-readable storage medium that provides instructions that, if executed by the processor, will cause the authoritative DNS server to carry out operations including:

receiving, from a first requester, a first DNS request for a first domain;

responding to the first DNS request to the first requester with a first plurality of address resource records, wherein the first plurality of address resource records respectively includes a first plurality of IP addresses that are selected randomly from a second plurality of IP addresses, wherein a second number of the second plurality of IP addresses is greater than a first number of the first plurality of IP addresses;

receiving, from a second requester, a second DNS request for the first domain; and

responding to the second DNS request to the second requester with a second plurality of address resource records, wherein the second plurality of address resource records respectively includes a third plurality of IP addresses that are selected randomly from the second plurality of IP addresses, wherein the second number of the second plurality of IP addresses is greater than a third number of the third plurality of IP addresses, and wherein the first plurality of IP addresses and the third plurality of IP addresses are different.

14. The authoritative DNS server of claim 13 , wherein the second number of the second plurality of IP addresses is over one thousand.

15. The authoritative DNS server of claim 13 , wherein the first plurality of address resource records is less than six address resource records, and wherein the second plurality of address resource records is less than six address resource records.

16. The authoritative DNS server of claim 13 , wherein the operations further comprise:

receiving, at the authoritative DNS server from a third requester, a third DNS request for a second domain, wherein the first domain and the second domain are different; and

responding to the third DNS request to the third requester with a third plurality of address resource records, wherein the third plurality of address resource records respectively includes a fourth plurality of IP addresses that are selected from the second plurality of IP addresses, wherein the second number of the second plurality of IP addresses is greater than a fourth number of the fourth plurality of IP addresses, and wherein the fourth plurality of IP addresses includes at least some overlapping IP addresses with the first plurality of IP addresses.

17. The authoritative DNS server of claim 13 , wherein the operations further comprise:

determining that there is traffic indicative of a denial-of-service (DoS) attack directed to one of the second plurality of IP addresses, and responsive to this determination, rate limiting or blocking traffic directed to that one of the second plurality of IP addresses.

18. The authoritative DNS server of claim 13 , wherein the operations further comprise:

determining that there is traffic indicative of a denial-of-service (DoS) attack directed o the first domain, and responsive to this determination, rate limiting a number of connections to the second plurality of IP addresses for the domain to a historical normal traffic level of the domain divided by the number of second plurality of IP addresses.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2021
From: HOLLOWAY, LEE HAHN; RAO, SRIKANTH N.; PRINCE, MATTHEW BROWNING; TOURNE, MATTHIEU PHILIPPE FRANÇOIS; PYE, IAN GERALD; BEJJANI, RAY RAYMOND; RODERY, TERRY PAUL, JR
To: CLOUDFLARE, INC.
Reel/Frame 057903/0492 →
Continuity (7)
Continuation 16800175 · Feb 25, 2020
Continuation 15489421 · Apr 17, 2017
Continuation 14109815 · Dec 17, 2013
Continuation 13665802 · Oct 31, 2012
Provisional Application 61719116 · Oct 26, 2012
Provisional Application 61680684 · Aug 7, 2012
Related Publication 20220217176A1 · Jul 7, 2022