IP Library › Granted Patent US 12,432,237
Granted Patent B2
US 12,432,237 · App. 18/173,024 · Granted Sep 30, 2025

Identification and inspection of outlier domain name system requests

Inventors: David J. Mitchell (Danville, CA); Paul C. van Gool (Santa Barbara, CA)
Assignee: HYAS Infosec Inc.
H04L63/1425H04L61/4511H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,237
App. No.
18/173,024
Granted
Sep 30, 2025
Kind
B2
Abstract

The technology disclosed herein enables identification of outlier DNS requests so the identified requests can be inspected to determine whether the identified requests may be associated with suspicious activity. In a particular example, a method provides determining characteristics of a Domain Name System (DNS) request and generating a score for the DNS request from the characteristics. The method further provides grouping a plurality of DNS requests into one or more groups based on a plurality of DNS request scores for the plurality of DNS requests. The plurality of DNS requests occurred in a specified timeframe and include the DNS request. The plurality of DNS request scores includes the score. In response to determining the DNS request is an outlier relative to the one or more groups, the method provides inspecting the DNS request for anomalies.

Claims (59)

1. A method comprising:

determining characteristics of a Domain Name System (DNS) request;

generating a score for the DNS request from the characteristics;

grouping a plurality of DNS requests into one or more groups based on a plurality of DNS request scores for the plurality of DNS requests, wherein the plurality of DNS requests occurred in a specified timeframe and include the DNS request, wherein the plurality of DNS request scores includes the score; and

in response to determining the DNS request is an outlier relative to the one or more groups, inspecting the DNS request for anomalies.

2. The method of claim 1 , comprising:

determining a plurality of characteristics of the plurality of DNS requests; and

generating the plurality of DNS request scores from the plurality of characteristics.

3. The method of claim 1 , wherein inspecting the DNS request comprises:

determining a host posture for a system that generated the DNS request.

4. The method of claim 1 , comprising:

receiving the specified timeframe from a user.

5. The method of claim 4 , wherein the specified timeframe corresponds to a time when malicious activity is thought to have originated.

6. The method of claim 1 , wherein the characteristics include one or more from a set comprising:

a nameserver network address to which the DNS request is directed;

a first geographic location of a nameserver having the nameserver network address;

a network address of a system that generated the DNS request;

a domain name indicated by the DNS request;

a destination network address resolved in response to the DNS request; and

a second geographic location of a system having the destination network address.

7. The method of claim 1 , comprising:

receiving the DNS request; and

transmitting the DNS request to a nameserver for resolution.

8. The method of claim 1 , wherein generating the score comprises:

adjusting a value for the score based on values assigned to each of the characteristics.

9. The method of claim 8 , wherein the values correspond to levels of importance of the characteristics relative to each other.

10. An apparatus comprising:

one or more computer readable storage media;

a processing system operatively coupled with the one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media that, when read and executed by the processing system, direct the apparatus to:

determine characteristics of a Domain Name System (DNS) request;

generate a score for the DNS request from the characteristics;

group a plurality of DNS requests into one or more groups based on a plurality of DNS request scores for the plurality of DNS requests, wherein the plurality of DNS requests occurred in a specified timeframe and include the DNS request, wherein the plurality of DNS request scores includes the score; and

in response to determining the DNS request is an outlier relative to the one or more groups, inspect the DNS request for anomalies.

11. The apparatus of claim 10 , wherein the program instructions direct the apparatus to:

determine a plurality of characteristics of the plurality of DNS requests; and

generate the plurality of DNS request scores from the plurality of characteristics.

12. The apparatus of claim 10 , wherein to inspect the DNS request, the program instructions direct the apparatus to:

determine a host posture for a system that generated the DNS request.

13. The apparatus of claim 10 , wherein the program instructions direct the apparatus to:

receive the specified timeframe from a user.

14. The apparatus of claim 13 , wherein the specified timeframe corresponds to a time when malicious activity is thought to have originated.

15. The apparatus of claim 10 , wherein the characteristics include one or more from a set comprising:

a nameserver network address to which the DNS request is directed;

a first geographic location of a nameserver having the nameserver network address;

a network address of a system that generated the DNS request;

a domain name indicated by the DNS request;

a destination network address resolved in response to the DNS request; and

a second geographic location of a system having the destination network address.

16. The apparatus of claim 10 , wherein the program instructions direct the apparatus to:

receive the DNS request; and

transmit the DNS request to a nameserver for resolution.

17. The apparatus of claim 10 , wherein to generate the score, the program instructions direct the apparatus to:

adjust a value for the score based on values assigned to each of the characteristics.

18. One or more non-transitory computer readable storage media having program instructions stored thereon, the program instructions, when read and executed by a processing system, direct the processing system to:

determine characteristics of a Domain Name System (DNS) request;

generate a score for the DNS request from the characteristics;

group a plurality of DNS requests into one or more groups based on a plurality of DNS request scores for the plurality of DNS requests, wherein the plurality of DNS requests occurred in a specified timeframe and include the DNS request, wherein the plurality of DNS request scores includes the score; and

in response to determining the DNS request is an outlier relative to the one or more groups, inspect the DNS request for anomalies.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2026
From: HYAS INFOSEC INC.
To: THREATER, INC.
Reel/Frame 074518/0777 →
SECURITY INTEREST Recorded Jul 28, 2023
From: HYAS INFOSEC INC.
To: COMMERCE, CANADIAN IMPERIAL BANK OF
Reel/Frame 064425/0663 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2023
From: MITCHELL, DAVID J.; VAN GOOL, PAUL C.
To: HYAS INFOSEC INC.
Reel/Frame 063621/0610 →
Continuity (1)
Related Publication 20240283804A1 · Aug 22, 2024
References Cited (8)
US 8997227B1 · Mhatre · 2015 [cited by examiner]
US 10362057B1 · Wu · 2019 [cited by examiner]
US 20130117282A1 · Mugali, Jr. · 2013 [cited by examiner]
US 20150180892A1 · Balderas · 2015 [cited by examiner]
US 20160308739A1 · Benjamin · 2016 [cited by examiner]
US 20180027013A1 · Wright · 2018 [cited by examiner]
US 20240223583A1 · Pasini · 2024 [cited by examiner]
US 20240333755A1 · Rodriguez · 2024 [cited by examiner]