IP Library › Granted Patent US 12,659,331
Granted Patent B2
US 12,659,331 · App. 18/538,945 · Granted Jun 16, 2026

Real-time attribution of tools and campaigns for DNS tunneling traffic

Inventors: Ruian Duan (Santa Clara, CA); Daiping Liu (Sunnyvale, CA); Zihang Xiao (Los Gatos, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1425H04L63/1416H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,331
App. No.
18/538,945
Granted
Jun 16, 2026
Kind
B2
Abstract

Various embodiments provide a system, method, and device for applying a DNS activity classification framework. The method incudes (i) collecting DNS-related activity, (ii) determining whether the DNS-related activity is associated with a DNS tunneling campaign or tool, and (iii) performing an active measure in response to detecting DNS traffic associated with a tunneling domain.

Claims (45)

1 . A system for classifying DNS tunneling traffic, comprising:

one or more processors configured to:

collect DNS-related activity;

determine whether the DNS-related activity is associated with a DNS tunneling campaign or tool, wherein determining whether the DNS-related activity is associated with a DNS tunneling campaign or tool comprises:

aggregating domain-level data from a plurality of heterogeneous data sources to generate multi-source features for the DNS-related activity, wherein the plurality of heterogeneous data sources include two or more of passive DNS repositories, certificate transparency logs, and third-party threat intelligence feeds; and

handle network traffic based at least in part on (i) detecting DNS traffic associated with a tunneling domain, and (ii) a predefined security policy; and

a memory coupled to the one or more processors and configured to provide the one or more processors with instructions.

2 . The system of claim 1 , wherein the DNS-related activity collected comprises one or more of query and response information, passive DNS information, DNS structural information, and auxiliary information.

3 . The system of claim 2 , wherein the DNS structural information comprises one or more of whois data, certificates, active DNS data, and web sites.

4 . The system of claim 2 , wherein the auxiliary information comprises one or more of customer information, third-party threat assessment information, information obtained from security entities that monitor network traffic for one or more organizations, and incident of compromise (IoC) feeds.

5 . The system of claim 1 , wherein the DNS-related activity is determined in real-time with receiving network traffic associated with the collected DNS-related activity.

6 . The system of claim 1 , wherein determining whether the DNS-related activity is associated with the DNS tunneling campaign or tool includes attributing the DNS-related to a particular campaign or tool.

7 . The system of claim 1 , wherein an incident response is deployed based on a determination of an attribution of a campaign or tool associated with the DNS-related activity.

8 . The system of claim 1 , wherein determining whether the DNS-related activity is associated with a DNS tunneling campaign or tool comprises determining one or more features, and attributing the DNS-related activity to a particular campaign or tool based at least in part on the one or more features.

9 . The system of claim 8 , wherein the one or more features includes one or more of a lexical feature, a statistical feature, an infrastructural features, and an auxiliary feature.

10 . The system of claim 1 , wherein determining whether the DNS-related activity is associated with a DNS tunneling campaign or tool comprises:

performing a lookup process to match unknown tunneling domains against known domains.

11 . The system of claim 10 , wherein the lookup process includes performing a Term Frequency-Inverse Document Frequency (TF-IDF) scoring.

12 . The system of claim 10 , wherein a particular campaign or tool to which the DNS-related activity corresponds is determined based at least in part on results from the lookup process.

13 . The system of claim 1 , wherein determining whether the DNS-related activity is associated with a DNS tunneling campaign or tool comprises:

in response to determining the campaign or tool attribution for the DNS-related activity, storing information pertaining to the DNS-related activity to an index for subsequent DNS tunneling detections.

14 . The system of claim 13 , wherein the information pertaining to the DNS-related activity stored in the index includes one or more features that are determined based at least in part on domain information associated with the DNS-related activity.

15 . The system of claim 1 , wherein determining whether the DNS-related activity is associated with a DNS tunneling campaign or tool comprises:

determining whether the DNS-related activity is a Cobalt strike campaign or generated using a Pupy tool.

16 . The system of claim 1 , wherein the one or more processors are further configured to:

determine one or more features associated with network traffic;

perform a clustering on the one or more features; and

detect new DNS-tunneling campaigns or tools based at least in part on results of the clustering of the one or more features.

17 . The system of claim 16 , wherein performing a cluster on the one or more features comprises implementing a machine learning process to detect new clusters corresponding to previously unknown DNS-tunneling campaigns or tools.

18 . The system of claim 1 , wherein the network traffic is handled according to a security policy.

19 . The system of claim 1 , wherein handling the network traffic according to the security policy comprises performing an active measure in response to detecting DNS traffic associated with a tunneling domain.

20 . The system of claim 19 , wherein the active measure includes one or more of: blocking, providing an alert to a user or other system, logging a determination of whether the DNS-related activity is associated with the DNS tunneling campaign or tool, quarantine network traffic corresponding to the DNS-related activity, and adding the network traffic corresponding to the DNS-related activity to a block list.

21 . A method for classifying DNS tunneling traffic, comprising:

collecting DNS-related activity; and

determining whether the DNS-related activity is associated with a DNS tunneling campaign or tool, wherein determining whether the DNS-related activity is associated with a DNS tunneling campaign or tool comprises:

aggregating domain-level data from a plurality of heterogeneous data sources to generate multi-source features for the DNS-related activity, wherein the plurality of heterogeneous data sources include two or more of passive DNS repositories, certificate transparency logs, and third-party threat intelligence feeds; and

performing an active measure in response to detecting DNS traffic associated with a tunneling domain, wherein the active measure is determined based at least in part on a predefined security policy.

22 . A computer program product embodied in a non-transitory computer readable medium for classifying DNS tunneling traffic, and the computer program product comprising computer instructions for:

collecting DNS-related activity; and

determining whether the DNS-related activity is associated with a DNS tunneling campaign or tool, wherein determining whether the DNS-related activity is associated with a DNS tunneling campaign or tool comprises:

aggregating domain-level data from a plurality of heterogeneous data sources to generate multi-source features for the DNS-related activity, wherein the plurality of heterogeneous data sources include two or more of passive DNS repositories, certificate transparency logs, and third-party threat intelligence feeds; and

performing an active measure in response to detecting DNS traffic associated with a tunneling domain, wherein the active measure is determined based at least in part on a predefined security policy.

23 . The system of claim 1 , wherein the one or more processors are configured to cluster unlabeled DNS-related activity using unsupervised learning to identify new potential tunneling campaigns or tools based on deviations from previously indexed feature distributions.

24 . The system of claim 1 , wherein determine whether the DNS-related activity is associated with a DNS tunneling campaign or tool comprises:

attributing the DNS-related activity to a particular campaign.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2024
From: DUAN, RUIAN; LIU, DAIPING; XIAO, ZIHANG
To: PALO ALTO NETWORKS, INC.
Reel/Frame 066421/0967 →
Continuity (1)
Related Publication 20250202916A1 · Jun 19, 2025
References Cited (14)
US 7188191B1 · Hovell · 2007 [cited by examiner]
US 20160127395A1 · Underwood · 2016 [cited by examiner]
US 20180063162A1 · Baughman · 2018 [cited by examiner]
US 20210126901A1 · Rodriguez · 2021 [cited by examiner]
US 20210266293A1 · Liu · 2021 [cited by examiner]
US 20220210170A1 · Di Pinto · 2022 [cited by examiner]
US 20220407870A1 · Vega · 2022 [cited by examiner]
US 20230056625A1 · Afonin · 2023 [cited by examiner]
US 20240220613A1 · Israel · 2024 [cited by examiner]
US 20240311479A1 · Yan · 2024 [cited by examiner]
Mishuhashi et al., Malicious DNS Tunnel Tool Recognition Using Persistent DoH Traffic Analysis, Jun. 2023 (Year: 2023). [cited by examiner]
Wu et al., FTPB: A Three-stage DNS Tunnel Detection Method Based on Character Feature Extraction, 2020 (Year: 2020). [cited by examiner]
Luo et al., Towards Comprehensive Detection of DNS Tunnels, 2020 (Year: 2020). [cited by examiner]
Liang et al., FECC: DNS tunnel detection model based on CNN and clustering, Feb. 2023 (Year: 2023). [cited by examiner]