IP Library › Granted Patent US 12,641,054
Granted Patent B2
US 12,641,054 · App. 18/615,401 · Granted May 26, 2026

Detection of domain hijacking during DNS lookup

Inventors: Christopher Michael Davis (Nanaimo, CA); Steven Mark Heyns (Nanaimo, CA); Paul Cornelius van Gool (Santa Barbara, CA)
Assignee: HYAS Infosec Inc.
H04L61/4511H04L63/101H04L63/126H04L63/1483H04L2101/69
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,641,054
App. No.
18/615,401
Granted
May 26, 2026
Kind
B2
Abstract

The technology disclosed herein enables detection of domain hijacking when a DNS resolver is performing a DNS lookup. In a particular embodiment, a method provides receiving a DNS request from a requesting computing system. The DNS request includes a domain name for which the requesting computing system is requesting resolution of a network address associated with the domain name in the DNS. The method further provides, in response to receiving the DNS request, identifying a nameserver, via a root nameserver of the DNS, to handle the DNS request and determining the nameserver is not a proper nameserver for the domain name specifically. The proper nameserver is defined by nameserver criteria generated specifically for the domain name. The method also provides preventing the nameserver from being used to resolve the DNS request in response to determining that the nameserver is not a proper nameserver for the domain name.

Claims (66)

1 . A method for operating a Domain Name System (DNS) resolver, comprising:

in the DNS resolver:

receiving a DNS request from a requesting computing system, wherein the DNS request includes a domain name for which the requesting computing system is requesting resolution of a network address associated with the domain name in the DNS;

in response to receiving the DNS request:

identifying a nameserver, via a root nameserver of the DNS, the DNS resolver should contact to handle the DNS request;

before contacting the nameserver, determining the nameserver is not a proper nameserver for the domain name specifically, wherein the proper nameserver is defined by nameserver criteria generated specifically for the domain name; and

preventing the nameserver from being used to resolve the DNS request in response to determining that the nameserver is not a proper nameserver for the domain name.

2 . The method of claim 1 , further comprising:

before the DNS request, determining characteristics of nameservers properly associated with the domain name; and

generating the nameserver criteria based on the characteristics.

3 . The method of claim 2 , wherein the characteristics include geographic locations of the nameservers.

4 . The method of claim 2 , wherein the characteristics include a host associated with the nameservers.

5 . The method of claim 2 , wherein determining the characteristics comprises:

performing a WHOIS lookup for the nameservers.

6 . The method of claim 2 , further comprising:

after determining that the nameservers are properly associated with the domain name, generating a hash of the nameservers;

after generating the hash, identifying current nameservers for the domain name and generating a second hash of the current nameservers; and

upon determining that the hash does not match the second hash, determining whether one or more of the current nameservers are suspect based on satisfaction of the nameserver criteria.

7 . The method of claim 1 , comprising:

receiving a second DNS request, wherein the second DNS request includes a different domain name from the domain name, wherein the second DNS request requests resolution of a second network address associated with a different domain name in the DNS;

in response to receiving the second DNS request:

identifying the nameserver, via the root nameserver of the DNS, to handle the second DNS request;

determining the nameserver is a proper nameserver for the different domain name specifically, wherein the different proper nameserver is defined by different nameserver criteria generated specifically for the different domain name; and

allowing the nameserver to resolve the second DNS request in response to determining that the nameserver is a proper nameserver for the domain name while preventing the nameserver from resolving the DNS request.

8 . The method of claim 1 , further comprising:

before the DNS request, determining other characteristics of other nameservers properly associated with other domain names; and

generating the nameserver criteria based on the other characteristics.

9 . The method of claim 1 , wherein a whitelist of domain names includes the domain name and wherein each domain name in the whitelist has corresponding nameserver criteria.

10 . The method of claim 9 , further comprising:

setting a lookup cache time-to-live for the whitelist of domain names to a predetermined value that is lower than a time-to-live value for other domain names.

11 . An apparatus for a Domain Name System (DNS) resolver, the apparatus comprising:

one or more computer readable storage media;

a processing system operatively coupled with the one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media that, when read and executed by the processing system, direct the processing system to:

receive a DNS request from a requesting computing system, wherein the DNS request includes a domain name for which the requesting computing system is requesting resolution of a network address associated with the domain name in the DNS;

in response to receiving the DNS request:

identify a nameserver, via a root nameserver of the DNS, the DNS resolver should contact to handle the DNS request;

before contacting the nameserver, determine the nameserver is not a proper nameserver for the domain name specifically, wherein the proper nameserver is defined by nameserver criteria generated specifically for the domain name; and

prevent the nameserver from being used to resolve the DNS request in response to determining that the nameserver is not a proper nameserver for the domain name.

12 . The apparatus of claim 11 , wherein the program instructions further direct the processing system to:

before the DNS request, determine characteristics of nameservers properly associated with the domain name; and

generate the nameserver criteria based on the characteristics.

13 . The apparatus of claim 12 , wherein the characteristics include geographic locations of the nameservers.

14 . The apparatus of claim 12 , wherein the characteristics include a host associated with the nameservers.

15 . The apparatus of claim 12 , wherein to determine the characteristics, the program instructions direct the processing system to:

perform a WHOIS lookup for the nameservers.

16 . The apparatus of claim 12 , wherein the program instructions further direct the processing system to:

after the nameservers are determined to be properly associated with the domain name, generate a hash of the nameservers;

after the hash is generated, identify current nameservers for the domain name and generate a second hash of the current nameservers; and

upon a determination that the hash does not match the second hash, determine whether one or more of the current nameservers are suspect based on satisfaction of the nameserver criteria.

17 . The apparatus of claim 16 , wherein the program instructions further direct the processing system to:

receive a second DNS request, wherein the second DNS request includes a different domain name from the domain name, wherein the second DNS request requests resolution of a second network address associated with a different domain name in the DNS;

in response to receiving the second DNS request:

identify the nameserver, via the root nameserver of the DNS, to handle the second DNS request;

determine the nameserver is a proper nameserver for the different domain name specifically, wherein the different proper nameserver is defined by different nameserver criteria generated specifically for the different domain name; and

allow the nameserver to resolve the second DNS request in response to determining that the nameserver is a proper nameserver for the domain name while preventing the nameserver from resolving the DNS request.

18 . The apparatus of claim 11 , wherein the program instructions further direct the processing system to:

before the DNS request, determine other characteristics of other nameservers properly associated with other domain names; and

generate the nameserver criteria based on the other characteristics.

19 . The apparatus of claim 11 , wherein a whitelist of domain names includes the domain name and wherein each domain name in the whitelist has corresponding nameserver criteria.

20 . One or more non-transitory computer readable storage media having program instructions stored thereon for a Domain Name System (DNS) resolver, the program instructions, when read and executed by a processing system, direct the processing system to:

receive a DNS request from a requesting computing system, wherein the DNS request includes a domain name for which the requesting computing system is requesting resolution of a network address associated with the domain name in the DNS;

in response to receiving the DNS request:

identify a nameserver, via a root nameserver of the DNS, the DNS resolver should contact to handle the DNS request;

before contacting the nameserver, determine the nameserver is not a proper nameserver for the domain name specifically, wherein the proper nameserver is defined by nameserver criteria generated specifically for the domain name; and

prevent the nameserver from being used to resolve the DNS request in response to determining that the nameserver is not a proper nameserver for the domain name.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2026
From: HYAS INFOSEC INC.
To: THREATER, INC.
Reel/Frame 074518/0777 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2024
From: DAVIS, CHRISTOPHER MICHAEL; HEYNS, STEVEN MARK; VAN GOOL, PAUL CORNELIUS
To: HYAS INFOSEC INC.
Reel/Frame 066888/0752 →
Continuity (2)
Continuation 17108585 · Dec 1, 2020
Related Publication 20240236035A1 · Jul 11, 2024
References Cited (6)
US 10110614B2 · Kaliski, Jr. · 2018 [cited by examiner]
US 20060112176A1 · Liu · 2006 [cited by examiner]
US 20090157889A1 · Treuhaft · 2009 [cited by examiner]
US 20100175137A1 · Parsons · 2010 [cited by examiner]
US 20160150004A1 · Hentunen · 2016 [cited by examiner]
US 20180234439A1 · Heuser · 2018 [cited by examiner]