IP Library Granted Patent US 12,500,914
Granted Patent B2
US 12,500,914 · App. 18/410,746 · Granted Dec 16, 2025

Automated identification of false positives in DNS tunneling detectors

Inventor: Peter Boord (Puyallup, WA)
Assignee: Infoblox Inc.
H04L63/1425H04L63/1441H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,914
App. No.
18/410,746
Granted
Dec 16, 2025
Kind
B2
Abstract

Techniques for automated identification of false positives in DNS tunneling detectors are disclosed. In some embodiments, a system, process, and/or computer program product for automated identification of false positives in DNS tunneling detectors includes receiving a set of passive DNS data, wherein the set of passive DNS data includes a DNS query and a DNS response for resolution of the DNS query for each of a plurality of DNS queries; extracting a plurality of features associated with each domain in the set of passive DNS data; and classifying DNS tunneling activities and performing false positive reduction using the plurality of features associated with each domain in the set of passive DNS data to reduce false positive detections.

Claims (41)

1 . A system, comprising:

a processor configured to:

receive a set of passive DNS data, wherein the set of passive DNS data includes a DNS query and a DNS response for resolution of the DNS query for each of a plurality of DNS queries, and wherein the set of passive DNS data is preprocessed to automatically filter a set of domains included in the set of passive DNS data;

extract a plurality of features associated with each domain in the set of passive DNS data, wherein the plurality of features includes a first feature and a second feature, wherein the first feature includes a ratio of a number of unique sub-prefixes for a domain to a total number of queries for the domain, and wherein the second feature includes a time span between an earliest observation and a latest observation of a sub-prefix in the domain; and

classify DNS tunneling activities and perform false positive reduction using the plurality of features associated with each domain in the set of passive DNS data to reduce false positive detections, comprising to:

classify, using a model, the DNS tunneling activities into a DNS tunnel or a non-tunnel, wherein the model implements a machine learning technique; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system recited in claim 1 , wherein one or more of the plurality of features are based on name server information.

3 . The system recited in claim 1 , wherein one or more of the plurality of features are based on a retransmission rate of queries and/or responses associated with a domain.

4 . The system recited in claim 1 , wherein the processor is further configured to:

determine a ratio of a unique number of sub-prefixes to a total number of queries for each domain in a filtered set of passive DNS data.

5 . The system recited in claim 1 , wherein the processor is further configured to:

calculate a time span between a latest and an earliest observation of each sub-prefix in each domain in a filtered set of passive DNS data.

6 . The system recited in claim 1 , wherein the processor is further configured to:

perform a mitigation action in response to detecting a malicious DNS tunneling activity.

7 . The system recited in claim 1 , wherein the processor is further configured to:

detect a malicious DNS tunneling activity; and

perform a mitigation action in response to detecting the malicious DNS tunneling activity.

8 . A method, comprising:

receiving a set of passive DNS data, wherein the set of passive DNS data includes a DNS query and a DNS response for resolution of the DNS query for each of a plurality of DNS queries, and wherein the set of passive DNS data is preprocessed to automatically filter a set of domains included in the set of passive DNS data;

extracting a plurality of features associated with each domain in the set of passive DNS data, wherein the plurality of features includes a first feature and a second feature, wherein the first feature includes a ratio of a number of unique sub-prefixes for a domain to a total number of queries for the domain, and wherein the second feature includes a time span between an earliest observation and a latest observation of a sub-prefix in the domain; and

classifying DNS tunneling activities and performing false positive reduction using the plurality of features associated with each domain in the set of passive DNS data to reduce false positive detections, comprising:

classifying, using a model, the DNS tunneling activities into a DNS tunnel or a non-tunnel, wherein the model implements a machine learning technique.

9 . The method of claim 8 , wherein one or more of the plurality of features are based on name server information.

10 . The method of claim 8 , wherein one or more of the plurality of features are based on a retransmission rate of queries and/or responses associated with a domain.

11 . The method of claim 8 , further comprising:

determining a ratio of a unique number of sub-prefixes to a total number of queries for each domain in a filtered set of passive DNS data.

12 . The method of claim 8 , further comprising:

calculating a time span between a latest and an earliest observation of each sub-prefix in each domain in a filtered set of passive DNS data.

13 . The method of claim 8 , further comprising:

performing a mitigation action in response to detecting a malicious DNS tunneling activity.

14 . The method of claim 8 , further comprising:

detecting a malicious DNS tunneling activity; and

performing a mitigation action in response to detecting the malicious DNS tunneling activity.

15 . A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

receiving a set of passive DNS data, wherein the set of passive DNS data includes a DNS query and a DNS response for resolution of the DNS query for each of a plurality of DNS queries, and wherein the set of passive DNS data is preprocessed to automatically filter a set of domains included in the set of passive DNS data;

extracting a plurality of features associated with each domain in the set of passive DNS data, wherein the plurality of features includes a first feature and a second feature, wherein the first feature includes a ratio of a number of unique sub-prefixes for a domain to a total number of queries for the domain, and wherein the second feature includes a time span between an earliest observation and a latest observation of a sub-prefix in the domain; and

classifying DNS tunneling activities and performing false positive reduction using the plurality of features associated with each domain in the set of passive DNS data to reduce false positive detections, comprising:

classifying, using a model, the DNS tunneling activities into a DNS tunnel or a non-tunnel, wherein the model implements a machine learning technique.

16 . The computer program product recited in claim 15 , wherein one or more of the plurality of features are based on name server information.

17 . The computer program product recited in claim 15 , wherein one or more of the plurality of features are based on a retransmission rate of queries and/or responses associated with a domain.

Continuity (3)
Continuation 17366813 · Jul 2, 2021
Provisional Application 63121756 · Dec 4, 2020
Related Publication 20240146753A1 · May 2, 2024
References Cited (83)
US 7426576B1 · Banga · 2008 [cited by applicant]
US 7970878B1 · Burshan · 2011 [cited by applicant]
US 8260914B1 · Ranjan · 2012 [cited by applicant]
US 8539577B1 · Stewart · 2013 [cited by applicant]
US 8904524B1 · Hodgman · 2014 [cited by applicant]
US 9178876B1 · Johansson · 2015 [cited by applicant]
US 9560072B1 · Xu · 2017 [cited by examiner]
US 9749336B1 · Zhang · 2017 [cited by examiner]
US 9917852B1 · Xu · 2018 [cited by examiner]
US 20060031928A1 · Conley · 2006 [cited by applicant]
US 20070261112A1 · Todd · 2007 [cited by applicant]
US 20090158430A1 · Borders · 2009 [cited by applicant]
US 20110191455A1 · Gardner · 2011 [cited by applicant]
US 20110311140A1 · Urbach · 2011 [cited by applicant]
US 20120042381A1 · Antonakakis · 2012 [cited by applicant]
US 20120054860A1 · Wyschogrod · 2012 [cited by applicant]
US 20120054869A1 · Yen · 2012 [cited by applicant]
US 20120254333A1 · Chandramouli · 2012 [cited by applicant]
US 20130283337A1 · Schechter · 2013 [cited by applicant]
US 20140307551A1 · Forssell · 2014 [cited by applicant]
US 20140310808A1 · Yao · 2014 [cited by applicant]
US 20140344345A1 · Venkatraman · 2014 [cited by applicant]
US 20150082431A1 · Davis · 2015 [cited by applicant]
US 20150195299A1 · Zoldi · 2015 [cited by applicant]
US 20160026796A1 · Monrose · 2016 [cited by applicant]
US 20160036844A1 · Kopp · 2016 [cited by examiner]
US 20160065611A1 · Fakeri-Tabrizi · 2016 [cited by applicant]
US 20160099852A1 · Cook · 2016 [cited by applicant]
US 20160127395A1 · Underwood · 2016 [cited by applicant]
US 20160294773A1 · Yu · 2016 [cited by examiner]
US 20190058718A1 · Pangeni · 2019 [cited by examiner]
US 20200351244A1 · Moore · 2020 [cited by examiner]
US 20210126901A1 · Rodriguez · 2021 [cited by examiner]
US 20210258325A1 · Meyer · 2021 [cited by examiner]
US 20210266293A1 · Liu · 2021 [cited by examiner]
JP 2011193343 · 2011 [cited by applicant]
JP 2013519257 · 2013 [cited by applicant]
Lambion et al., “Malicious DNS Tunneling Detection in Real-Traffic DNS Data,” 2020 IEEE International Conference on Big Data (Big Data) Year: 2020 | Conference Paper | Publisher: IEEE. [cited by examiner]
Singh et al., “Detecting Malicious DNS over HTTPS Traffic Using Machine Learning,” 2020 International Conference on Innovation and Intelligence for Informatics, Computing and Technologies (3ICT) Year: 2020 | Conference … [cited by examiner]
Antonakakis et al., Building a Dynamic Reputation System for DNS, downloaded on Jan. 27, 2014. [cited by applicant]
Antonakakis et al., Detecting Malware Domains at the Upper DNS Hierarchy, downloaded on Jan. 27, 2014. [cited by applicant]
Author Unknown, Alexa—The Web Information Company, Analytics for any Website, downloaded from http://www.alexa.com/ on Jan. 28, 2014. [cited by applicant]
Author Unknown, Apache Kafka, A High-Throughput Distributed Messaging System, downloaded from https://kafka.apache.org/ on Jan. 28, 2014. [cited by applicant]
Author Unknown, Catching DNS Tunnels with IDS that doesn't suck A.I, downloaded on Sep. 28, 2015. [cited by applicant]
Author Unknown, FSI, downloaded from https://www.farsightsecurity.com/ on Jan. 28, 2014. [cited by applicant]
Author Unknown, Google Books, Ngram Viewer, downloaded from http://storage.googleapis.com/books/ngrams/books/datasetsv2.html on Sep. 22, 2015. [cited by applicant]
Author Unknown, HBase—Apache HBase Home, downloaded from http://hbase.apache.org/ on Jan. 28, 2014. [cited by applicant]
Author Unknown, Internet Systems Consortium, Maintainers of BIND and ISC DHCP, downloaded from http://www.isc.org/ on Jan. 28, 2014. [cited by applicant]
Author Unknown, Internet Systems Consortium, Maintainers of BIND and ISC DHCP, downloaded from http://www.isc.org/ on Sep. 22, 2015. [cited by applicant]
Author Unknown, Kyro.se: Iodine, Jun. 16, 2014. [cited by applicant]
Author Unknown, Storm, downloaded from http://storm-project.net/ on Jan. 28, 2014. [cited by applicant]
Author Unknown, Welcome to Apache Hadoop, What is Apache Hadoop?, downloaded from http://hadoop.apache.org/ on Jan. 28, 2014. [cited by applicant]
Bilge et al., “Exposure: Finding Malicious Domains Using Passive DNS Analysis”, NDSS 2011, 18th Annual Network and Distributed System Security Symposium, Feb. 2011, San Diego, CA. [cited by applicant]
Bilge et al., Exposure: Finding Malicious Domains Using Passive DNS Analysis, Conference: Proceedings of the Network and Distributed System Security Symposium, NDSS, Jan. 2011, pp. 1-17. [cited by applicant]
Borders et al., Web Tap: Detecting Covert Web Traffic, CCS'04, Washington, DC, USA, ACM, Oct. 25-29, 2004. [cited by applicant]
Born et al., Detecting DNS Tunnels Using Character Frequency Analysis, 2010. [cited by applicant]
Burton et al., Whitelists that Work: Creating Defensible Dynamic Whitelists with Statistical Learning, Nov. 2019. [cited by applicant]
C.E. Shannon, A Mathematical Theory of Communication, Reprinted with Correction from The Bell System Technical Journal, vol. 27, Jul. and Oct. 1948. [cited by applicant]
Cejka et al., Stream-Wise Detection of Surreptitious Traffic over DNS, Proceeding of 2014 IEEE 19th International Workshop on Computer Aided Modeling and Design of Communication Links and Networks (CAMAD), IEEE, Dec. 1,… [cited by applicant]
Chang et al., Bigtable: A Distributed Storage System for Structured Data, OSDI, 2006. [cited by applicant]
Crotti et al., Detecting HTTP Tunnels with Statistical Mechanisms, 2007. [cited by applicant]
Dr. Jim Metzler, The 2012 Cloud Networking Report, Dec. 2012. [cited by applicant]
Dusi et al., A Preliminary Look at the Privacy of SSH Tunnels, 17th IEEE International Conference on Computer Communication and Networks (ICCCN'08), U.S. Virgin Islands, Aug. 3-7, 2008. [cited by applicant]
Dusi et al., Detection of Encrypted Tunnels Across Network Boundaries, IEEE, 2008. [cited by applicant]
Ellens et al., Flow-Based Detection of DNS Tunnels, IFIP International Federation for Information Processing, AIMS 2013, LNCS 7943, pp. 124-135, 2013. [cited by applicant]
Greg Farnham et al., Detecting DNS Tunneling, SANS Institute InfoSec Reading Room, accepted on Feb. 25, 2013. [cited by applicant]
Hoffman et al., A Covert Channel in TTL Field of DNS Packets, Rochester Institute of Technology, RIT Scholar Works, Jul. 2012, pp. 1-5. [cited by applicant]
Hu et al., RB-Seeker: Auto-detection of Redirection Botnets, downloaded on Jan. 27, 2014. [cited by applicant]
Ishibashi et al., [Invited Talk] Anomalous Traffic Observed in DNS, The Institute of Electronics Information and Communication Engineers, IEICE Technical Report, published Jul. 2, 2009. [cited by applicant]
Joe St. Sauver, Record Type=Null, Records in DNSDB Mtbl Files, Mar. 8, 2017. [cited by applicant]
Kara et al., Detection of Malicious Payload Distribution Channels in DNS, Proceeding of 2014 IEEE International Conference on Communications (ICC), IEEE, Jun. 10, 2014, pp. 853-858. [cited by applicant]
Konte et al., Dynamics of Online Scam Hosting Infrastructure, downloaded on Jan. 27, 2014. [cited by applicant]
Lambion et al., “Malicious DNS Tunneling Detection in Real-Traffic DNS Data,” 2020 IEEE International Conference on Big Data (U Big Data) Year: 2020 | Conference Paper| Publisher: IEEE. [cited by applicant]
Nadler et al., Detection of Malicious and Low Throughput Data Exfiltration Over the DNS Protocol, Jun. 18, 2018. [cited by applicant]
P.Vixie, Network Working Group, ISC, Extension Mechanisms for DNS (EDNS0), Aug. 1999. [cited by applicant]
Paxson et al., Practical Comprehensive Bounds on Surreptitious Communication Over DNS, Proceedings of the 22nd USENIX Security Symposium, Aug. 14-16, 2013, Washington, D.C., USA. [cited by applicant]
Qi et al., A Bigram Based Real Time DNS Tunnel Detection Approach, Information Technology and Quantitative Management (ITQM2013), Procedia Computer Science 17 (2013) pp. 852-860. [cited by applicant]
Romana et al., Entropy Based Analysis of DNS Query Traffic in the Campus Network, Systemics, Cybernetic and Informatics, vol. 6, No. 5, pp. 42-44, 2007. [cited by applicant]
Tanaka et al., Extracting Malicious Website from DNS Log-Analysis Method and Anonymity, Computer Security Symposium 2013 Papers, Information Processing Society, Oct. 14, 2013, vol. 2013, No. 4. [cited by applicant]
Tsuda et al., A Detection System which uses DNS Traffic Features to Detect Domains which are Related to Botnets, Technical Study Report by the Institute of Electronics, Information and Communication Engineers, Feb. 24, … [cited by applicant]
Yamada et al., Anomaly Client Detection by Monitoring DNS Server Traffic, Technical Study Report by the Institute of Electronics, Information and Communication Engineers, Sep. 4, 2008, vol. 108, No. 2013. [cited by applicant]
Yu et al., Behavior Analysis Based DNS Tunneling Detection and Classification with Big Data Technologies, Proceedings of the International Conference on Internet of Things and Big Data, 2016, pp. 284-290. [cited by applicant]
Yu et al., Semi-Supervised Time Series Modeling for Real-Time Flux Domain Detection on Passive DNS Traffic, MLDM 2014, LNAI 8556, pp. 258-271, 2014. [cited by applicant]
Cited By (1)
US 12,621,316