IP Library Granted Patent US 12,683,984
Granted Patent B2
US 12,683,984 · App. 18/217,253 · Granted Jul 14, 2026

Real-time detection of DNS infiltration traffic

Inventors: Ruian Duan (Santa Clara, CA); Daiping Liu (Sunnyvale, CA); Tingxiang Zhu (Santa Clara, CA); Xing Wang (Santa Clara, CA); Jun Wang (Fremont, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1416H04L63/1425H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,683,984
App. No.
18/217,253
Filed
Jun 30, 2023
Granted
Jul 14, 2026
Kind
B2
Examiner
CHACKO, JOE
Art Unit
2457
USPC
726/22
Abstract

Real-time detection of DNS infiltration traffic is disclosed. A DNS response associated with a DNS query sent by a client device is received. An attempted DNS infiltration is detected based at least in part on an automated analysis of the DNS response. In response to the detection, a remedial action is performed.

Claims (31)

1 . A system, comprising:

a processor configured to:

receive a DNS response associated with a DNS query sent by a client device;

detect an attempted DNS infiltration of information from a remote server to the client device based at least in part on an automated analysis of the DNS response, including by using a set of infiltration-specific detectors which use infiltration-specific features, including one or more response-specific entropy features, to determine whether the DNS response is likely to encode the information; and

in response to the detection, perform a remedial action; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein the DNS response is received, at a server on an external network, from a security appliance collocated with the client device.

3 . The system of claim 1 , wherein the processor is configured to perform the detection using at least one model trained on DNS response feature information.

4 . The system of claim 1 , wherein the processor is configured to perform the detection using a set of heuristics.

5 . The system of claim 1 , wherein performing the remedial action includes including a domain associated with the DNS response in a blocklist.

6 . The system of claim 1 , wherein performing the remedial action includes providing a result of the analysis to a security appliance during a session of the client device.

7 . The system of claim 1 , wherein the remote server is a malicious DNS server and wherein performing the remedial action includes preventing the client device from communicating with the malicious DNS server.

8 . The system of claim 1 , wherein the processor is configured to perform the analysis based at least in part on a feature vector that maintains information for a sliding time window of DNS information.

9 . The system of claim 8 , wherein a feature included in the feature vector represents a number of distinct fully qualified domain names associated with a root domain portion.

10 . The system of claim 1 , wherein the analysis includes determining a correlation between a plurality of IP addresses associated with a domain.

11 . The system of claim 1 , wherein the analysis includes determining a location of a domain.

12 . The system of claim 1 , wherein the analysis includes determining entropy of a set of unique IP addresses.

13 . The system of claim 1 , wherein the analysis includes determining whether the DNS response includes a non-public IPv6 address.

14 . The system of claim 1 , wherein the analysis includes determining whether data in a TXT response matches a pattern.

15 . The system of claim 1 , wherein the analysis includes determining a count of unknown TXT responses.

16 . The system of claim 1 , wherein the analysis includes determining an entropy of a set of unique TXT responses.

17 . The system of claim 1 , wherein the analysis includes determining a meaningful word ratio.

18 . The system of claim 1 , wherein the analysis includes determining a subdomain Jeffrey distribution.

19 . A method, comprising:

receiving a DNS response associated with a DNS query sent by a client device;

detecting an attempted DNS infiltration of information from a remote server to the client device based at least in part on an automated analysis of the DNS response, including by using a set of infiltration-specific detectors which use infiltration-specific features, including one or more response-specific entropy features, to determine whether the DNS response is likely to encode the information; and

in response to the detection, performing a remedial action.

20 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving a DNS response associated with a DNS query sent by a client device;

detecting an attempted DNS infiltration of information from a remote server to the client device based at least in part on an automated analysis of the DNS response, including by using a set of infiltration-specific detectors which use infiltration-specific features, including one or more response-specific entropy features, to determine whether the DNS response is likely to encode the information; and

in response to the detection, performing a remedial action.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2023
From: DUAN, RUIAN; LIU, DAIPING; ZHU, TINGXIANG; WANG, XING; WANG, JUN
To: PALO ALTO NETWORKS, INC.
Reel/Frame 065921/0407 →
Continuity (2)
Provisional Application 63432963 · Dec 15, 2022
Related Publication 20240205240A1 · Jun 20, 2024
References Cited (122)
US 7467410B2 · Graham · 2008 [cited by applicant]
US 7934254B2 · Graham · 2011 [cited by applicant]
US 7958555B1 · Chen · 2011 [cited by applicant]
US 8141157B2 · Farley · 2012 [cited by applicant]
US 8260914B1 · Ranjan · 2012 [cited by applicant]
US 8269914B2 · Huo · 2012 [cited by applicant]
US 8494985B1 · Keralapura · 2013 [cited by applicant]
US 8561177B1 · Aziz · 2013 [cited by applicant]
US 8566928B2 · Dagon · 2013 [cited by applicant]
US 8631489B2 · Antonakakis · 2014 [cited by applicant]
US 8826444B1 · Kalle · 2014 [cited by applicant]
US 9043894B1 · Dennison · 2015 [cited by applicant]
US 9178901B2 · Xue · 2015 [cited by applicant]
US 9330258B1 · Satish · 2016 [cited by applicant]
US 9356942B1 · Joffe · 2016 [cited by applicant]
US 9363282B1 · Yu · 2016 [cited by applicant]
US 9497213B2 · Thompson · 2016 [cited by applicant]
US 9516039B1 · Yen · 2016 [cited by applicant]
US 9621576B1 · Oprea · 2017 [cited by applicant]
US 9922190B2 · Antonakakis · 2018 [cited by applicant]
US 10089411B2 · Kassa · 2018 [cited by applicant]
US 10097568B2 · Baughman · 2018 [cited by applicant]
US 10270744B2 · Yu · 2019 [cited by applicant]
US 10362057B1 · Wu · 2019 [cited by examiner]
US 10673880B1 · Pratt · 2020 [cited by applicant]
US 10679088B1 · Dalal · 2020 [cited by applicant]
US 10848509B1 · Mcnab · 2020 [cited by applicant]
US 10958668B1 · Wang · 2021 [cited by applicant]
US 11153330B1 · Antoniewicz · 2021 [cited by applicant]
US 11159486B2 · Pangeni · 2021 [cited by applicant]
US 20020111769A1 · Takeuchi · 2002 [cited by applicant]
US 20040073640A1 · Martin · 2004 [cited by applicant]
US 20060212925A1 · Shull · 2006 [cited by applicant]
US 20080028463A1 · Dagon · 2008 [cited by applicant]
US 20080155694A1 · Kwon · 2008 [cited by applicant]
US 20090089426A1 · Yamasaki · 2009 [cited by applicant]
US 20100192225A1 · Ma · 2010 [cited by applicant]
US 20110078794A1 · Manni · 2011 [cited by applicant]
US 20110191423A1 · Krasser · 2011 [cited by applicant]
US 20110231935A1 · Gula · 2011 [cited by applicant]
US 20110283359A1 · Prince · 2011 [cited by applicant]
US 20110283361A1 · Perdisci · 2011 [cited by applicant]
US 20110302656A1 · El-Moussa · 2011 [cited by applicant]
US 20120054860A1 · Wyschogrod · 2012 [cited by applicant]
US 20120303808A1 · Xie · 2012 [cited by applicant]
US 20120304287A1 · Yu · 2012 [cited by applicant]
US 20130080574A1 · Prince · 2013 [cited by applicant]
US 20130174253A1 · Thomas · 2013 [cited by applicant]
US 20130191915A1 · Antonakakis · 2013 [cited by applicant]
US 20130232574A1 · Carothers · 2013 [cited by applicant]
US 20140013434A1 · Ranum · 2014 [cited by applicant]
US 20140068763A1 · Ward · 2014 [cited by applicant]
US 20140068775A1 · Ward · 2014 [cited by applicant]
US 20140075558A1 · Ward · 2014 [cited by applicant]
US 20140090058A1 · Ward · 2014 [cited by applicant]
US 20140143825A1 · Behrendt · 2014 [cited by applicant]
US 20140230062A1 · Kumaran · 2014 [cited by applicant]
US 20140245436A1 · Dagon · 2014 [cited by applicant]
US 20140283063A1 · Thompson · 2014 [cited by applicant]
US 20140298460A1 · Xue · 2014 [cited by applicant]
US 20150007250A1 · Dicato, Jr. · 2015 [cited by applicant]
US 20150007312A1 · Pidathala · 2015 [cited by applicant]
US 20150143504A1 · Desai · 2015 [cited by applicant]
US 20150188879A1 · Cha · 2015 [cited by applicant]
US 20150264070A1 · Harlacher · 2015 [cited by applicant]
US 20150281257A1 · Hart · 2015 [cited by applicant]
US 20160036848A1 · Reddy · 2016 [cited by applicant]
US 20160065611A1 · Fakeri-Tabrizi · 2016 [cited by applicant]
US 20160294773A1 · Yu · 2016 [cited by applicant]
US 20160352679A1 · Hagen · 2016 [cited by applicant]
US 20160352772A1 · O'Connor · 2016 [cited by applicant]
US 20160359887A1 · Yadav · 2016 [cited by applicant]
US 20170126706A1 · Minea · 2017 [cited by applicant]
US 20170195285A1 · Kakhki · 2017 [cited by applicant]
US 20170295187A1 · Havelka · 2017 [cited by applicant]
US 20170331789A1 · Kumar · 2017 [cited by applicant]
US 20180063162A1 · Baughman · 2018 [cited by applicant]
US 20180081991A1 · Barber · 2018 [cited by applicant]
US 20180115582A1 · Thakar · 2018 [cited by applicant]
US 20180124020A1 · Rodriguez · 2018 [cited by applicant]
US 20180198821A1 · Gopalakrishna · 2018 [cited by applicant]
US 20180278633A1 · Brutzkus · 2018 [cited by applicant]
US 20180309795A1 · Ithal · 2018 [cited by applicant]
US 20180351972A1 · Yu · 2018 [cited by applicant]
US 20190268379A1 · Narayanaswamy · 2019 [cited by applicant]
US 20200059451A1 · Huang · 2020 [cited by applicant]
US 20200169570A1 · Kleymenov · 2020 [cited by applicant]
US 20200228500A1 · Olumofin · 2020 [cited by applicant]
US 20210097168A1 · Patel · 2021 [cited by applicant]
US 20210126901A1 · Rodriguez · 2021 [cited by applicant]
US 20210203693A1 · Clausen · 2021 [cited by applicant]
US 20210266293A1 · Liu · 2021 [cited by examiner]
US 20210400061A1 · Antoniewicz · 2021 [cited by examiner]
US 20220070194A1 · Pon · 2022 [cited by applicant]
CN 105577660 · 2019 [cited by applicant]
WO 2007050244 · 2007 [cited by applicant]
Qi et al., BotCensor: Detecting DGA-Based Botnet Using Two-Stage Anomaly Detection, 2018 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications/12th IEEE International Conferen… [cited by applicant]
Alan Shaikh, Botnet Analysis and Detection System, Nov. 2010. [cited by applicant]
Antonakakis et al., DGAs and Cyber-Criminals: A Case Study, 2012. [cited by applicant]
Antonakakis et al., From Throw-Away Traffic to Bots: Detecting the Rise of DGA-Based Malware, 21st {USENIX} Security Symposium ({USENIX} Security 12), 2012, pp. 491-506. [cited by applicant]
Christian Rossow, Thesis, Using Malware Analysis to Evaluate Botnet Resilience, Apr. 23, 2013. [cited by applicant]
Dietrich et al., On Botnets That Use DNS for Command and Control, 2011 Seventh European Conference on Computer Network Defense, 2011, pp. 9-16. [cited by applicant]
Gavin E. Crooks, Inequalities Between the Jenson-Shannon and Jeffreys Divergences, 2008. [cited by applicant]
Greg Farnham et al., Detecting DNS Tunneling, SANS Institute InfoSec Reading Room, accepted on Feb. 25, 2013. [cited by applicant]
Guy Bruneau, DNS Sinkhole, Aug. 7, 2010, Sans Institute InfoSec Reading Room, pp. 1-41. [cited by applicant]
Ivan Nikolaev, Network Service Anomaly Detection, Jun. 2014. [cited by applicant]
Liu et al., CCGA: Clustering and Capturing Group Activities for DGA-Based Botnets Detection, 2019 18th IEEE International Conference on Trust, Security and Privacy in Computing and Communications/ 13th IEEE Internationa… [cited by applicant]
Martin Rataj, Simulation of Botnet C&C Channels, 2014. [cited by applicant]
Mustafa Toprak, Intrusion Detection System Alert Correlation with Operating System Level Logs, Dec. 11, 2009. [cited by applicant]
Nadler et al., Detection of Malicious and Low Throughput Data Exfiltration Over the DNS Protocol, Jun. 18, 2018. [cited by applicant]
Palo Alto Networks, We Know it Before You Do: Predicting Malicious Domains, retrieved on Jun. 22, 2015. [cited by applicant]
Pedro Marques da LUZ, Thesis, Botnet Detection Using Passive DNS, 2013/2014. [cited by applicant]
Qi et al., A Bigram Based Real Time DNS Tunnel Detection Approach, Procedia Computer Science 17, 2013, pp. 852-860. [cited by applicant]
Qi et al., BotCensor: Detecting DGA-Based Botnet Using Two-Stage Anomaly Detection, 2018 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications/ 12th IEEE International Confere… [cited by applicant]
Schuppen et al., FANCI: Feature-based Automated NXDomain Classification and Intelligence, Proceedings of the 27th USENIX Security Symposium, Aug. 2018, pp. 1165-1181. [cited by applicant]
Sebastian Garcia, Identifying, Modeling and Detecting Botnet Behaviors in the Network, Nov. 2014. [cited by applicant]
Seung Won Shin, Protecting Networked Systems from Malware Threats, Aug. 2013. [cited by applicant]
Shehar Bano, A Study of Botnets: Systemization of Knowledge and Correlation-based Detection, Oct. 2012. [cited by applicant]
Van Der Toorn et al., TXTing 101: Finding Security Issues in the Long Tail of DNS TXT Records, 2020 IEEE European Symposium on Security and Privacy Workshops, 2020, pp. 544-549. [cited by applicant]
Mshnu Teja Kilari, Thesis, Detection of Advanced Bots in Smartphones Through User Profiling, Dec. 2013. [cited by applicant]
Xu et al., We Know it Before You Do: Predicting Malicious Domains, Virus Bulletin Conference Sep. 2014. [cited by applicant]
Xu et al., We Know it Before You Do: Predicting Malicious Domains, Sep. 2014. [cited by applicant]