IP Library › Granted Patent US 12,513,115
Granted Patent B2
US 12,513,115 · App. 18/378,809 · Granted Dec 30, 2025

Methods and systems for prevention of attacks associated with the domain name system

Inventors: Sean Moore (Hollis, NH); Jonathan R. Rogers (Hampton Falls, NH); Steven Rogers (Leesburg, VA)
Assignee: Centripetal Networks, LLC
H04L63/0245H04L61/4511H04L63/1458H04L63/20H04L2463/142
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,115
App. No.
18/378,809
Granted
Dec 30, 2025
Kind
B2
Abstract

The attack vectors for some denial-of-service cyber attacks on the Internet's Domain Name System (DNS) are bad, bogus, or unregistered domain name DNS requests to resolve domain names that are not registered in the DNS. Some other cyber attacks steal sensitive data by encoding the data in bogus domain names, or domain names otherwise not registered in the DNS, that are transferred across networks in bogus DNS requests. A DNS gatekeeper may filter in-transit packets containing DNS requests and may efficiently determine if a request's domain name is registered in the DNS. When the domain name is not registered in the DNS, the DNS gatekeeper may take one of a plurality of protective actions. The DNS gatekeeper drops requests determined not to be legitimate, which may prevent an attack.

Claims (104)

1 . A method comprising:

storing, by a gatekeeper device that controls query access to a Domain Name System (DNS), a probabilistic data structure representing a plurality of domain names, wherein the plurality of domain names comprises a subset of domain names resolvable by the DNS, wherein at least two of the plurality of domain names originated from different domain name servers, of a plurality of domain name servers, managed by different organizations;

receiving, by the gatekeeper device, one or more packets comprising a DNS query;

determining, based on packet information, whether the one or more packets comprise a first domain name;

based on determining that the one or more packets comprise the first domain name, testing, without querying the DNS, the probabilistic data structure to determine if the first domain name is represented in the probabilistic data structure; and

based on a determination that the first domain name is not represented in the probabilistic data structure:

determining whether at least a portion of the first domain name is being used to exfiltrate data based on detecting at least a portion of the data in the first domain name;

based on a determination that the at least the portion of the first domain name is being used to exfiltrate the data, dropping the one or more packets; and

transmitting a DNS response to a sender of the one or more packets.

2 . The method of claim 1 , wherein the DNS response comprises an NXDOMAIN response code.

3 . The method of claim 1 , wherein the determining that the at least the portion of the first domain name is being used to exfiltrate the data is further based on one or more of:

a frequency of DNS queries received from the sender,

one or more lengths of labels associated with the one or more packets, or

syntactical characteristics of the first domain name.

4 . The method of claim 1 , wherein the determining that the at least the portion of the first domain name is being used to exfiltrate the data is further based on a determination that a destination of the one or more packets does not send a DNS response to the DNS query.

5 . The method of claim 1 , further comprising:

receiving, by the gatekeeper device and from a second sender, one or more second packets comprising a second DNS query;

testing, without querying the DNS, the probabilistic data structure to determine if a second domain name indicated by the one or more second packets is represented in the probabilistic data structure; and

based on a determination that a second domain name indicated by the one or more second packets is not represented in the probabilistic data structure and a determination, based on a frequency of packets received from the second sender, that the one or more second packets are associated with a denial of service attack:

dropping the one or more second packets.

6 . The method of claim 1 , further comprising:

based on the determination that the first domain name is not represented in the probabilistic data structure, transmitting data regarding the one or more packets to a management server.

7 . The method of claim 1 , further comprising:

based on a determination that one or more second packets do not comprise a domain name, transmitting, without testing the probabilistic data structure, the one or more second packets toward their intended destination.

8 . The method of claim 1 , further comprising:

based on a determination that one or more second packets comprise a second domain name, testing, without querying the DNS, the probabilistic data structure to determine if the second domain name is represented in the probabilistic data structure; and

based on a determination that the second domain name is represented in the probabilistic data structure, transmitting the one or more second packets toward their intended destination.

9 . The method of claim 1 , further comprising:

testing, without querying the DNS, the probabilistic data structure to determine if a second domain name of one or more second packets is represented in the probabilistic data structure;

based on a determination that the second domain name is not represented in the probabilistic data structure, determining whether a second DNS request contained in the one or more second packets is legitimate; and

based on a determination that the second DNS request contained in the one or more second packets is legitimate, transmitting the one or more second packets towards their intended destination.

10 . The method of claim 1 , wherein the probabilistic data structure is one of:

a Bloom filter; or

a Cuckoo filter.

11 . A gatekeeper device that controls query access to a Domain Name System (DNS), the gatekeeper device comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the gatekeeper device to:

store a probabilistic data structure representing a plurality of domain names, wherein the plurality of domain names comprises a subset of domain names resolvable by the DNS, wherein at least two of the plurality of domain names originated from different domain name servers, of a plurality of domain name servers, managed by different organizations;

receive one or more packets comprising a DNS query;

determine, based on packet information, whether the one or more packets comprise a first domain name;

based on determining that the one or more packets comprise the first domain name, test, without querying the DNS, the probabilistic data structure to determine if the first domain name is represented in the probabilistic data structure; and

based on a determination that the first domain name is not represented in the probabilistic data structure:

determine whether at least a portion of the first domain name is being used to exfiltrate data based on detecting at least a portion of the data in the first domain name;

based on a determination that the at least the portion of the first domain name is being used to exfiltrate the data, drop the one or more packets; and

transmit a DNS response to a sender of the one or more packets.

12 . The gatekeeper device of claim 11 , wherein the DNS response comprises an NXDOMAIN response code.

13 . The gatekeeper device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the gatekeeper device to determine that the at least the portion of the first domain name is being used to exfiltrate the data further based on one or more of:

a frequency of DNS queries received from the sender,

one or more lengths of labels associated with the one or more packets, or

syntactical characteristics of the first domain name.

14 . The gatekeeper device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the gatekeeper device to determine that the at least the portion of the first domain name is being used to exfiltrate the data further based on a determination that a destination of the one or more packets does not send a DNS response to the DNS query.

15 . The gatekeeper device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the gatekeeper device to:

receive, from a second sender, one or more second packets comprising a second DNS query;

test, without querying the DNS, the probabilistic data structure to determine if a second domain name indicated by the one or more second packets is represented in the probabilistic data structure; and

based on a determination that a second domain name indicated by the one or more second packets is not represented in the probabilistic data structure and a determination, based on a frequency of packets received from the second sender, that the one or more second packets are associated with a denial of service attack:

drop the one or more second packets.

16 . The gatekeeper device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the gatekeeper device to:

based on the determination that the first domain name is not represented in the probabilistic data structure, transmit data regarding the one or more packets to a management server.

17 . The gatekeeper device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the gatekeeper device to:

based on a determination that one or more second packets do not comprise a domain name, transmit, without testing the probabilistic data structure, the one or more second packets toward their intended destination.

18 . The gatekeeper device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the gatekeeper device to:

based on a determination that one or more second packets comprise a second domain name, test, without querying the DNS, the probabilistic data structure to determine if the second domain name is represented in the probabilistic data structure; and

based on a determination that the second domain name is represented in the probabilistic data structure, transmit the one or more second packets toward their intended destination.

19 . The gatekeeper device of claim 11 , wherein the instructions, when executed by the one or more processors, cause the gatekeeper device to:

test, without querying the DNS, the probabilistic data structure to determine if a second domain name of one or more second packets is represented in the probabilistic data structure;

based on a determination that the second domain name is not represented in the probabilistic data structure, determine whether a second DNS request contained in the one or more second packets is legitimate; and

based on a determination that the second DNS request contained in the one or more second packets is legitimate, transmit the one or more second packets towards their intended destination.

20 . The gatekeeper device of claim 11 , wherein the probabilistic data structure is one of:

a Bloom filter; or

a Cuckoo filter.

21 . One or more non-transitory computer-readable media storing instructions that, when executed by a gatekeeper device that controls query access to a Domain Name System (DNS), cause the gatekeeper device to:

store a probabilistic data structure representing a plurality of domain names, wherein the plurality of domain names comprises a subset of domain names resolvable by the DNS, wherein at least two of the plurality of domain names originated from different domain name servers, of a plurality of domain name servers, managed by different organizations;

receive one or more packets comprising a DNS query;

determine, based on packet information, whether the one or more packets comprise a first domain name;

based on determining that the one or more packets comprise the first domain name, test, without querying the DNS, the probabilistic data structure to determine if the first domain name is represented in the probabilistic data structure; and

based on a determination that the first domain name is not represented in the probabilistic data structure:

determine whether at least a portion of the first domain name is being used to exfiltrate data based on detecting at least a portion of the data in the first domain name;

based on a determination that the at least the portion of the first domain name is being used to exfiltrate the data, drop the one or more packets; and

transmit a DNS response to a sender of the one or more packets.

22 . The one or more non-transitory computer-readable media of claim 21 , wherein the DNS response comprises an NXDOMAIN response code.

23 . The one or more non-transitory computer-readable media of claim 21 , wherein the instructions, when executed, cause the gatekeeper device to determine that the at least the portion of the first domain name is being used to exfiltrate the data further based on one or more of:

a frequency of DNS queries received from the sender,

one or more lengths of labels associated with the one or more packets, or

syntactical characteristics of the first domain name.

24 . The one or more non-transitory computer-readable media of claim 21 , wherein the instructions, when executed, cause the gatekeeper device to determine that the at least the portion of the first domain name is being used to exfiltrate the data further based on a determination that a destination of the one or more packets does not send a DNS response to the DNS query.

25 . The one or more non-transitory computer-readable media of claim 21 , wherein the instructions, when executed, cause the gatekeeper device to:

receive, from a second sender, one or more second packets comprising a second DNS query;

test, without querying the DNS, the probabilistic data structure to determine if a second domain name indicated by the one or more second packets is represented in the probabilistic data structure; and

based on a determination that a second domain name indicated by the one or more second packets is not represented in the probabilistic data structure and a determination, based on a frequency of packets received from the second sender, that the one or more second packets are associated with a denial of service attack:

drop the one or more second packets.

26 . The one or more non-transitory computer-readable media of claim 21 , wherein the instructions, when executed, cause the gatekeeper device to:

based on the determination that the first domain name is not represented in the probabilistic data structure, transmit data regarding the one or more packets to a management server.

27 . The one or more non-transitory computer-readable media of claim 21 , wherein the instructions, when executed, cause the gatekeeper device to:

based on a determination that one or more second packets do not comprise a domain name, transmit, without testing the probabilistic data structure, the one or more second packets toward their intended destination.

28 . The one or more non-transitory computer-readable media of claim 21 , wherein the instructions, when executed, cause the gatekeeper device to:

based on a determination that one or more second packets comprise a second domain name, test, without querying the DNS, the probabilistic data structure to determine if the second domain name is represented in the probabilistic data structure; and

based on a determination that the second domain name is represented in the probabilistic data structure, transmit the one or more second packets toward their intended destination.

29 . The one or more non-transitory computer-readable media of claim 21 , wherein the instructions, when executed, cause the gatekeeper device to:

test, without querying the DNS, the probabilistic data structure to determine if a second domain name of one or more second packets is represented in the probabilistic data structure;

based on a determination that the second domain name is not represented in the probabilistic data structure, determine whether a second DNS request contained in the one or more second packets is legitimate; and

based on a determination that the second DNS request contained in the one or more second packets is legitimate, transmit the one or more second packets towards their intended destination.

30 . The one or more non-transitory computer-readable media of claim 21 , wherein the probabilistic data structure is one of:

a Bloom filter; or

a Cuckoo filter.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2023
From: MOORE, SEAN; ROGERS, JONATHAN R.; ROGERS, STEVEN
To: CENTRIPETAL NETWORKS, INC.
Reel/Frame 065184/0580 →
CHANGE OF NAME Recorded Oct 11, 2023
From: CENTRIPETAL NETWORKS, INC.
To: CENTRIPETAL NETWORKS, LLC
Reel/Frame 065218/0498 →
Continuity (4)
Continuation 17220407 · Apr 1, 2021
Continuation 16692365 · Nov 22, 2019
Continuation In Part 16399700 · Apr 30, 2019
Related Publication 20240259345A1 · Aug 1, 2024
References Cited (52)
US 7444515B2 · Dharmapurikar et al. · 2008 [cited by applicant]
US 8510821B1 · Brandwine et al. · 2013 [cited by applicant]
US 8578497B2 · Antonakakis et al. · 2013 [cited by applicant]
US 9171153B2 · Jorgensen · 2015 [cited by applicant]
US 10051001B1 · Ashley et al. · 2018 [cited by applicant]
US 11271963B2 · Manadhata · 2022 [cited by examiner]
US 11582263B2 · Goldstein · 2023 [cited by applicant]
US 20080163333A1 · Kasralikar · 2008 [cited by applicant]
US 20080201772A1 · Mondaeev et al. · 2008 [cited by applicant]
US 20090172138A1 · Wang et al. · 2009 [cited by applicant]
US 20120054860A1 · Wyschogrod et al. · 2012 [cited by applicant]
US 20140157405A1 · Joll et al. · 2014 [cited by applicant]
US 20150052606A1 · Romero Bueno et al. · 2015 [cited by applicant]
US 20150358234A1 · Krieger · 2015 [cited by applicant]
US 20160134639A1 · Kaminsky · 2016 [cited by applicant]
US 20180004942A1 · Martin et al. · 2018 [cited by applicant]
US 20180063084A1 · Wakumoto et al. · 2018 [cited by applicant]
US 20190052658A1 · Clarke et al. · 2019 [cited by applicant]
US 20200204581A1 · Manadhata et al. · 2020 [cited by applicant]
CN 102438025A · 2012 [cited by applicant]
CN 102523311A · 2012 [cited by applicant]
CN 102857493A · 2013 [cited by applicant]
CN 103152357A · 2013 [cited by applicant]
CN 103294822A · 2013 [cited by applicant]
CN 104601557A · 2015 [cited by applicant]
CN 106105278A · 2016 [cited by applicant]
CN 107360198A · 2017 [cited by applicant]
CN 108370352A · 2018 [cited by applicant]
CN 108683686A · 2018 [cited by applicant]
EP 3010208A1 · 2016 [cited by applicant]
JP 2012501127A · 2012 [cited by applicant]
JP 2017534110A · 2017 [cited by applicant]
WO 2010022799A1 · 2010 [cited by applicant]
WO 2016057342A1 · 2016 [cited by applicant]
Qaosar et al., 2019 IEEE, “A Framework for Privacy-Preserving Multi-Party Skyline Query Based on Homomorphic Encryption”, pp. 167481-167496 (Year: 2019). [cited by examiner]
Mishra, Preeti, et al., “A Detailed Investigation and Analsyis of Using Machine Learning Techniques for Intrusion Detection,” IEEE Communications Surveys & Tutorials, vol. 21, No. 1, First Quarter 2019, pp. 686-728. [cited by applicant]
Jul. 12, 2019 U.S. Non-Final Office Action—U.S. Appl. No. 16/399,700. [cited by applicant]
Jun. 23, 2020—International Search Report—PCT/US2020/030044. [cited by applicant]
Geravand, et al., “Bloom Filter Applications in Network Security: A State-of-the-Art Survey,” Computer Networks, vol. 57, No. 18, Sep. 14, 2013, pp. 4047-4064. [cited by applicant]
Van Rijswijk-Deij, et al., “Privacy-Conscious Threat Intelligence Using DNSBloom,” 2019 IFIP/IEEE Symposium on Integrated Network and Service Management (IM), IFIP, Apr. 8, 2019, pp. 98-106. [cited by applicant]
Jan. 28, 2020—U.S. Non-Final Office Action—U.S. Appl. No. 16/692,365. [cited by applicant]
Jun. 29, 2020—U.S. Final Office Action—U.S. Appl. No. 16/692,365. [cited by applicant]
Hamed, et al., “On Dynamic Optimization of Packet Matching in High-Speed Firewalls,” 2006 IEEE, Apr. 1, 206. [cited by applicant]
Wu, et al., “DNS Usage Mining and Its Two Applications,” 978-1-4577-1539-6/11, 2011 IEEE, pp. 54-60. [cited by applicant]
Xu, et al., “DNS for Massive-Scale Command and Control,” IEEE Transactions on Dependable and Secure Computing, vol. 10, No. 3, May/Jun. 2013, pp. 143-153. [cited by applicant]
Schales, et al., “Scalable analytics to detect DNS misuse for establishing stealthy communication channels,” IBM J. Res. & Dev., vol. 60, No. 4, Paper 3, Jul./Aug. 2016, 0018-8646/16 B 2016 IEEE, pp. 3:1-3:14. [cited by applicant]
Feb. 19, 2021—(WO) International Search Report and Written Opinion—App PCT/US2020/061805. [cited by applicant]
Fu, et al., “A covert data transport protocol”, IEEE 2016 11th International Conference on Malicious and Unwanted Software: “Know Your Enemy” (MALWARE), pp. 93-100 (Year: 2016). [cited by applicant]
Mar. 24, 2021—U.S. Notice of Allowance—U.S. Appl. No. 16/692,365. [cited by applicant]
Apr. 2, 2021 U.S.—Notice of Allowance—U.S. Appl. No. 16/399,700. [cited by applicant]
Pecori, et al., “A Statistical Blind Technique for Recognition of Internet Traffic with Dependence Enforcement”, 2014 IEEE, pp. 328-333 (Year: 2014). [cited by applicant]
Das, et al., “Detection of Exfiltration and Tunneling over DNS,” 2017 16th IEEE International Conference on Machine Learning and Applications, pp. 737-742 (Year: 2017), 6 pages. [cited by applicant]
Cited By (1)
US 12,621,342