IP Library Granted Patent US 12,081,512
Granted Patent B2
US 12,081,512 · App. 18/204,711 · Granted Sep 3, 2024

Collecting passive DNS traffic to generate a virtual authoritative DNS server

Inventors: John R. Woodworth (Amissville, VA); Dean Ballew (Sterling, VA); Mark Dehus (Thornton, CO)
Assignee: Level 3 Communications, LLC
H04L61/4511H04L61/301H04L61/58
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,081,512
App. No.
18/204,711
Granted
Sep 3, 2024
Kind
B2
Abstract

The present application describes a system and method for passively collecting DNS traffic data as that data is passed between a recursive DNS resolver and an authoritative DNS server. The information contained in the collected DNS traffic data is used to generate a virtual authoritative DNS server, or a zone associated with the authoritative DNS server, when it is determined that the authoritative DNS server has been compromised.

Claims (13)

1. A method, comprising:

capturing domain name system (DNS) data;

receiving a trigger notification, the trigger notification indicating a zone associated with an authoritative DNS server is compromised;

causing a recursive DNS resolver to retrieve last known valid information associated with the zone from an observer system, the last known valid information being captured from the DNS data;

generating a virtual zone using the last known valid information; and

causing the recursive DNS resolver to host the virtual zone.

2. The method of claim 1 , wherein the authoritative DNS server is associated with a first entity and the recursive DNS resolver is associated with a second entity.

3. The method of claim 1 , wherein the domain name system data is passively captured by the observer system.

4. The method of claim 1 , further comprising deconstructing the virtual zone when the trigger notification is resolved.

5. The method of claim 1 , wherein cached information is an internet protocol (IP) address associated with the authoritative DNS server.

6. The method of claim 1 , further comprising causing the virtual zone to provide a last known valid internet protocol (IP) address associated with the authoritative DNS server.

7. The method of claim 1 , further comprising causing the virtual zone to provide public key data information to a requesting device.

8. The method of claim 1 , further comprising enabling the recursive DNS resolver to provide private key data information to a requesting device.

Assignments (3)
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (SECOND LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0749 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (FIRST LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2023
From: BALLEW, DEAN; WOODWORTH, JOHN R.; DEHUS, MARK
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 063848/0065 →
Continuity (3)
Continuation 17479685 · Sep 20, 2021
Provisional Application 63101241 · Sep 21, 2020
Related Publication 20230308414A1 · Sep 28, 2023