IP Library › Granted Patent US 12,238,065
Granted Patent B2
US 12,238,065 · App. 17/684,143 · Granted Feb 25, 2025

Managing traffic rules in association with fully qualified domain names (FQDNs) using posture information associated with DNS records

Inventors: David James Mitchell (Danville, CA); Paul Cornelius van Gool (Santa Barbara, CA)
Assignee: HYAS Infosec Inc.
H04L63/0236H04L61/4511H04L63/0263H04L63/029
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,065
App. No.
17/684,143
Granted
Feb 25, 2025
Kind
B2
Abstract

Systems, methods, and software described herein manage traffic rules in association with fully qualified domain names (FQDNs). In one implementation, a domain name system (DNS) security service obtains a FQDN associated with a DNS request by a computing device. The DNS security service determines a first score for the FQDN based on trust factors associated with the FQDN and determines whether the first score satisfies one or more criteria. When the first score satisfies the one or more criteria, the DNS security service evaluates host posture information associated with an IP address in the DNS response for the FQDN, updates the first score to a second score based on the host posture information, and determines a traffic rule for the FQDN based on the second score.

Claims (50)

1. A method comprising:

obtaining a fully qualified domain name (FQDN) associated with a domain name system (DNS) request by a computing device;

in response to the obtaining of the FQDN, determining a first score for the FQDN based on trust factors associated with the FQDN, wherein the first score is indicative of whether a connection should be allowed to a host associated with the FQDN;

in response to determining that the first score satisfies one or more criteria, evaluating host posture information for the host having an internet protocol (IP) address provided for the FQDN in a DNS response to the DNS request, wherein the host posture information comprises information about software status on the host;

updating the first score to a second score based on the host posture information, wherein the second score is more indicative than the first score that the connection should not be allowed when the host posture information indicates the host is likely suspicious or malicious; and

determining a traffic rule from a plurality of traffic rules for the FQDN based on the second score.

2. The method of claim 1 , wherein the second score remains the same as the first score when the host posture information does not indicate the host is likely suspicious or malicious.

3. The method of claim 1 , wherein the trust factors comprise at least time delta information between requests for the FQDN and a volume of queries for a period.

4. The method of claim 1 , wherein the trust factors comprise popularity information for the FQDN globally.

5. The method of claim 1 , wherein the trust factors comprise scores associated with infrastructure to which the A or AAAA records for the FQDN point, a risk score of an authoritative Name Server for the FQDN, or a quantity of record changes for the FQDN.

6. The method of claim 1 , wherein the plurality of traffic rules comprises a rule to allow traffic, a rule to redirect traffic, and a rule to block traffic.

7. The method of claim 1 , wherein the host posture information comprises software version information.

8. The method of claim 1 further comprising:

obtaining a second FQDN associated with a DNS request by a second computing device;

determining a third score for the second FQDN based on trust factors associated with the second FQDN;

in response to determining that the third score fails to satisfy the one or more criteria, determining a traffic rule for the second FQDN based on the third score; and

communicating the traffic rule for the second FQDN to a firewall.

9. The method of claim 1 further comprising communicating the traffic rule to a firewall associated with the computing device.

10. A computing apparatus comprising:

a storage system comprising one or more non-transitory computer readable storage media;

a processing system comprising at least one processor and operatively coupled to the storage system; and

program instructions stored on the storage system that, when executed by the processing system, direct the computing apparatus to:

obtain a fully qualified domain name (FQDN) associated with a domain name system (DNS) request by a computing device;

in response to the obtaining of the FQDN, determine a first score for the FQDN based on trust factors associated with the FQDN, wherein the first score is indicative of whether a connection should be allowed to a host associated with the FQDN;

in response to a determination that the first score satisfies one or more criteria, evaluate host posture information for the host having an internet protocol (IP) address provided for the FQDN in a DNS response to the DNS request, wherein the host posture information comprises information about software status on the host;

update the first score to a second score based on the host posture information, wherein the second score is more indicative than the first score that the connection should not be allowed when the host posture information indicates the host is likely suspicious or malicious; and

determine a traffic rule from a plurality of traffic rules for the FQDN based on the second score.

11. The computing apparatus of claim 10 , wherein the second score remains the same as the first score when the host posture information does not indicate the host is likely suspicious or malicious.

12. The computing apparatus of claim 10 , wherein the trust factors comprise at least time delta information between requests for the FQDN and a volume of queries for a period.

13. The computing apparatus of claim 10 , wherein the trust factors comprise popularity information for the FQDN globally.

14. The computing apparatus of claim 10 , wherein the trust factors comprise scores associated with infrastructure to which the A or AAAA records for the FQDN point, a risk score of an authoritative Name Server for the FQDN, or a quantity of record changes for the FQDN.

15. The computing apparatus of claim 10 , wherein the plurality of traffic rules comprises a rule to allow traffic, a rule to redirect traffic, and a rule to block traffic.

16. The computing apparatus of claim 10 , wherein the host posture information comprises software version information.

17. The computing apparatus of claim 10 , wherein the program instructions further direct the computing apparatus to:

obtain a second FQDN associated with a DNS request by a second computing device;

determine a third score for the second FQDN based on trust factors associated with the second FQDN;

in response to a determination that the third score fails to satisfy the one or more criteria, determine a traffic rule for the second FQDN based on the third score; and

communicate the traffic rule for the second FQDN to a firewall.

18. The computing apparatus of claim 10 , wherein the program instructions further direct the computing apparatus to communicate the traffic rule to a firewall associated with the computing device.

19. A system comprising:

a first computer configured to:

receive a fully qualified domain name (FQDN) as part of a domain name system (DNS) request by a computing device;

communicate the FQDN to a second computer; and

the second computer configured to:

obtain the FQDN from the first computer;

in response to the obtaining of the FQDN, determine a first score for the FQDN based on trust factors associated with the FQDN, wherein the first score is indicative of whether a connection should be allowed to a host associated with the FQDN;

in response to a determination that the first score satisfies one or more criteria, evaluate host posture information for the host having an internet protocol (IP) address provided for the FQDN in a DNS response to the DNS request, wherein the host posture information comprises information about software status on the host;

update the first score to a second score based on the host posture information, wherein the second score is more indicative than the first score that the connection should not be allowed when the host posture information indicates the host is likely suspicious or malicious; and

determine a traffic rule from a plurality of traffic rules for the FQDN based on the second score.

20. The system of claim 19 , wherein the plurality of traffic rules comprises a rule to allow traffic, a rule to redirect traffic, and a rule to block traffic.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2026
From: HYAS INFOSEC INC.
To: THREATER, INC.
Reel/Frame 074518/0777 →
SECURITY INTEREST Recorded Jul 28, 2023
From: HYAS INFOSEC INC.
To: COMMERCE, CANADIAN IMPERIAL BANK OF
Reel/Frame 064425/0663 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2022
From: MITCHELL, DAVID JAMES; VAN GOOL, PAUL CORNELIUS
To: HYAS INFOSEC INC.
Reel/Frame 059138/0511 →
Continuity (1)
Related Publication 20230283591A1 · Sep 7, 2023
References Cited (10)
US 20140150051A1 · Bharali · 2014 [cited by examiner]
US 20160065597A1 · Nguyen · 2016 [cited by examiner]
US 20160359917A1 · Rao · 2016 [cited by examiner]
US 20180343272A1 · Khalil · 2018 [cited by examiner]
US 20200314065A1 · Roy · 2020 [cited by examiner]
US 20200314107A1 · Joshi · 2020 [cited by examiner]
US 20210258325A1 · Meyer · 2021 [cited by examiner]
US 20220060498A1 · Head, Jr. · 2022 [cited by examiner]
US 20220278955A1 · Roy · 2022 [cited by examiner]
US 20230112092A1 · Tymchenko · 2023 [cited by examiner]
Cited By (1)
US 12,712,911