IP Library › Granted Patent US 12,568,138
Granted Patent B2
US 12,568,138 · App. 18/631,652 · Granted Mar 3, 2026

DNS load balancing via request routing

Inventors: Seven Starosta (Brooklyn, NY); Jeffrey M. Tejnecky (Chesterfield, VA); Brandon Krouse (Frisco, TX)
Assignee: Capital One Services, LLC
H04L67/1038H04L61/4511H04L63/10H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,138
App. No.
18/631,652
Filed
Apr 10, 2024
Granted
Mar 3, 2026
Kind
B2
Examiner
JOO, JOSHUA
Art Unit
2445
USPC
726/21
Abstract

Methods, systems, and apparatuses are described herein for management of a Domain Name System (DNS) system. The system comprises numerous improvements, many related to CNAME records of the DNS. A computing device may manage authentication for a DNS using shared authentication credentials of a first authentication framework. In this manner, a wide variety of users might authenticate themselves using a first framework and use authentication credentials for a second framework to access a DNS. The computing device may further protect DNS servers from Denial of Service (DOS) attacks by bifurcating read and write requests to a DNS to different servers, such that attacks on read requests do not affect all of the DNS. The computing device may further validate DNS requests using, for example, natural language processing to avoid typographical errors inadvertently creating DNS zones.

Claims (85)

1 . A system configured to protect Domain Name System (DNS) servers from Denial of Service (DOS) attacks, the system comprising:

a computing device;

a first DNS server; and

a second DNS server;

wherein the computing device is configured to:

receive, via an Application Programming Interface (API) and during a first time period, a first DNS request;

based on determining that the first DNS request comprises a requested change to a first DNS record, based on authenticating one or more first authentication credentials in the first DNS request, and based on comparing a first quantity of DNS requests received during the first time period to a threshold associated with DNS attacks;

modify the first DNS request to replace the one or more first authentication credentials in the first DNS request with shared authentication credentials; and

route the modified first DNS request to the first DNS server;

receive, via the API and during a second time period different from the first time period, a second DNS request; and

based on determining that the second DNS request comprises a read request associated with the first DNS record, based on authenticating one or more second authentication credentials in the second DNS request, and based on comparing a second quantity of DNS requests received during the second time period to the threshold associated with DNS attacks;

modify the second DNS request to replace the one or more second authentication credentials in the second DNS request with the shared authentication credentials; and

route the modified second DNS request to the second DNS server;

receive, via the API and during a third time period different from the first time period and the second time period, a third DNS request comprising either or both the one or more first authentication credentials or the one or more second authentication credentials; and

based on comparing a third quantity of DNS requests received during the third time period to the threshold associated with DNS attacks, prevent transmission of the third DNS request to the first DNS server or the second DNS server;

wherein the first DNS server is configured to:

receive the modified first DNS request;

modify, based on authenticating the shared authentication credentials and based on the modified first DNS request, a DNS record; and

transmit the modified DNS record to the second DNS server; and

wherein the second DNS server is configured to:

store the modified DNS record;

receive the modified second DNS request; and

provide, in response to the modified second DNS request and based on authenticating the shared authentication credentials, the modified DNS record.

2 . The system of claim 1 , wherein the shared credentials comprise a token indicating successful authentication of one or more third authentication credentials.

3 . The system of claim 1 , wherein the first DNS server maintains a first copy of DNS records, wherein the second DNS server maintains a second copy of the DNS records, and wherein the first DNS server is configured to transmit the modified DNS record to the second DNS server as part of an update to the second copy of the DNS records.

4 . The system of claim 1 , wherein the computing device is configured to:

receive, via the API, a fourth DNS request; and

based on determining that the fourth DNS request is associated with a user on a blocklist, cause display, on a user device, of a notification indicating that the fourth DNS request is denied.

5 . The system of claim 1 , wherein the computing device is configured to prevent transmission of the third DNS request to the first DNS server or the second DNS server by:

causing display, on a user device, of a notification indicating that the third DNS request is denied.

6 . The system of claim 1 , wherein the second DNS request comprises authentication credentials, and wherein the computing device is configured to route the second DNS request to the second DNS server further based on validating the authentication credentials.

7 . The system of claim 1 , wherein the first DNS request comprises a request to create a Canonical Name (CNAME) record.

8 . A method configured to protect Domain Name System (DNS) servers from Denial of Service (DoS) attacks, the method comprising:

receiving, by a computing device, via an Application Programming Interface (API), and during a first time period a first DNS request;

based on determining that the first DNS request comprises a requested change to a first DNS record, based on authenticating one or more first authentication credentials in the first DNS request, and based on comparing a first quantity of DNS requests received during the first time period to a threshold associated with DNS attacks;

modifying the first DNS request to replace the one or more first authentication credentials in the first DNS request with shared authentication credentials; and

routing, by the computing device, the modified first DNS request to a first DNS server;

receiving, by the computing device, via the API, and during a second time period different from the first time period, a second DNS request;

based on determining that the second DNS request comprises a read request associated with the first DNS record, based on authenticating one or more second authentication credentials in the second DNS request, and based on comparing a second quantity of DNS requests received during the second time period to the threshold associated with DNS attacks;

modifying the second DNS request to replace the one or more second authentication credentials in the second DNS request with the shared authentication credentials; and

routing, by the computing device, the modified second DNS request to a second DNS server;

receiving, via the API and during a third time period different from the first time period and the second time period, a third DNS request comprising either or both the one or more first authentication credentials or the one or more second authentication credentials; and

based on comparing a third quantity of DNS requests received during the third time period to the threshold associated with DNS attacks, preventing transmission of the third DNS request to the first DNS server or the second DNS server;

receiving, by the first DNS server, the modified first DNS request;

modifying, by the first DNS server and based on authenticating the shared authentication credentials, a DNS record based on the first DNS request;

transmitting, by the first DNS server, the modified DNS record to the second DNS server;

storing, by the second DNS server, the modified DNS record;

receiving, by the second DNS server, the modified second DNS request; and

providing, by the second DNS server, in response to the modified second DNS request, and, based on authenticating the shared authentication credentials, the modified DNS record.

9 . The method of claim 8 , wherein the shared credentials comprise a token indicating successful authentication of one or more third authentication credentials.

10 . The method of claim 8 , wherein the first DNS server maintains a first copy of DNS records, wherein the second DNS server maintains a second copy of the DNS records, and wherein the first DNS server is configured to transmit the modified DNS record to the second DNS server as part of an update to the second copy of the DNS records.

11 . The method of claim 8 , further comprising:

receiving, by the computing device and via the API, a fourth DNS request; and

based on determining that the fourth DNS request is associated with a user on a blocklist, causing display, on a user device, of a notification indicating that the fourth DNS request is denied.

12 . The method of claim 8 , wherein the preventing transmission of the third DNS request to the first DNS server or the second DNS server comprises:

causing display, on a user device, of a notification indicating that the third DNS request is denied.

13 . The method of claim 8 , wherein the second DNS request comprises authentication credentials, and wherein the computing device is configured to route the second DNS request to the second DNS server further based on validating the authentication credentials.

14 . The method of claim 8 , wherein the first DNS request comprises a request to create a Canonical Name (CNAME) record.

15 . One or more non-transitory computer-readable media storing instructions that, when executed by one or more processors, cause a computing device to:

receive, via an Application Programming Interface (API) and during a first time period, a first DNS request;

based on determining that the first DNS request comprises a requested change to a first DNS record, based on authenticating one or more first authentication credentials in the first DNS request, and based on comparing a first quantity of DNS requests received during the first time period to a threshold associated with DNS attacks;

modify the first DNS request to replace the one or more first authentication credentials in the first DNS request with shared authentication credentials; and

route the modified first DNS request to a first DNS server;

receive, via the API and during a second time period different from the first time period, a second DNS request; and

based on determining that the second DNS request comprises a read request associated with the first DNS record, based on authenticating one or more second authentication credentials in the second DNS request, and based on comparing a second quantity of DNS requests received during the second time period to the threshold associated with DNS attacks;

modify the second DNS request to replace the one or more second authentication credentials in the second DNS request with the shared authentication credentials; and

route the modified second DNS request to a second DNS server;

receive, via the API and during a third time period different from the first time period and the second time period, a third DNS request comprising either or both the one or more first authentication credentials or the one or more second authentication credentials; and

based on comparing a third quantity of DNS requests received during the third time period to the threshold associated with DNS attacks, prevent transmission of the third DNS request to the first DNS server or the second DNS server;

wherein the instructions, when executed by the one or more processors, further cause the first DNS server to:

receive the modified first DNS request;

modify, based on authenticating the shared authentication credentials, a DNS record based on the first DNS request; and

transmit the modified DNS record to the second DNS server; and

wherein the instructions, when executed by the one or more processors, further cause the second DNS server to:

store the modified DNS record;

receive the modified second DNS request; and

provide, in response to the modified second DNS request and based on authenticating the shared authentication credentials, the modified DNS record.

16 . The non-transitory computer-readable media of claim 15 , wherein the shared credentials comprise a token indicating successful authentication of one or more third authentication credentials.

17 . The non-transitory computer-readable media of claim 15 , wherein the first DNS server maintains a first copy of DNS records, wherein the second DNS server maintains a second copy of the DNS records, and wherein the instructions, when executed by the one or more processors, further cause the first DNS server to transmit the modified DNS record to the second DNS server as part of an update to the second copy of the DNS records.

18 . The non-transitory computer-readable media of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the computing device to:

receive, via the API, a fourth DNS request; and

based on determining that the fourth DNS request is associated with a user on a blocklist, cause display, on a user device, of a notification indicating that the fourth DNS request is denied.

19 . The non-transitory computer-readable media of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the computing device to prevent transmission of the third DNS request to the first DNS server or the second DNS server by causing the computing device to:

cause display, on a user device, of a notification indicating that the third DNS request is denied.

20 . The non-transitory computer-readable media of claim 15 , wherein the second DNS request comprises authentication credentials, and wherein the instructions, when executed by the one or more processors, further cause the computing device to route the second DNS request to the second DNS server further based on validating the authentication credentials.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2024
From: STAROSTA, SEVEN; TEJNECKY, JEFFREY M.; KROUSE, BRANDON
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 067148/0608 →
Continuity (1)
Related Publication 20250323973A1 · Oct 16, 2025
References Cited (140)
US 6701329B1 · Esibov et al. · 2004 [cited by applicant]
US 7296155B1 · Trostle et al. · 2007 [cited by applicant]
US 7620733B1 · Tzakikario et al. · 2009 [cited by applicant]
US 7680876B1 · Cioli et al. · 2010 [cited by applicant]
US 7748047B2 · O'Neill · 2010 [cited by applicant]
US 8261351B1 · Thornewell et al. · 2012 [cited by applicant]
US 8285830B1 · Stout et al. · 2012 [cited by applicant]
US 8473635B1 · Lohner · 2013 [cited by examiner]
US 8799639B2 · Balazs · 2014 [cited by examiner]
US 8886747B1 · Chen et al. · 2014 [cited by applicant]
US 8935748B2 · Statia et al. · 2015 [cited by applicant]
US 9143494B2 · Giles et al. · 2015 [cited by applicant]
US 9239911B2 · Duryee · 2016 [cited by examiner]
US 9372688B1 · Ben-Yair et al. · 2016 [cited by applicant]
US 9491135B1 · Earl et al. · 2016 [cited by applicant]
US 9516130B1 · Graham-Cumming · 2016 [cited by applicant]
US 9705959B1 · Strand · 2017 [cited by examiner]
US 9736185B1 · Belamaric et al. · 2017 [cited by applicant]
US 9813303B1 · Guigli · 2017 [cited by applicant]
US 9948527B1 · Bryan et al. · 2018 [cited by applicant]
US 10009443B1 · Guigli · 2018 [cited by applicant]
US 10104039B1 · Knecht et al. · 2018 [cited by applicant]
US 10148493B1 · Ennis, Jr. et al. · 2018 [cited by applicant]
US 10193852B2 · Kommula · 2019 [cited by applicant]
US 10205701B1 · Voss et al. · 2019 [cited by applicant]
US 10462180B1 · Ben David et al. · 2019 [cited by applicant]
US 10649744B1 · Black et al. · 2020 [cited by applicant]
US 10904273B1 · Mccarty et al. · 2021 [cited by applicant]
US 10931786B1 · Vasquez et al. · 2021 [cited by applicant]
US 11153265B1 · Fayed et al. · 2021 [cited by applicant]
US 11218326B1 · Eland · 2022 [cited by applicant]
US 11394540B1 · Larrew · 2022 [cited by applicant]
US 11516253B1 · Van Deman, V et al. · 2022 [cited by applicant]
US 11777992B1 · Cross et al. · 2023 [cited by applicant]
US 11818055B1 · Lanoy et al. · 2023 [cited by applicant]
US 11882117B1 · Kumar · 2024 [cited by applicant]
US 11902242B1 · Larrew · 2024 [cited by applicant]
US 11997065B1 · Monti et al. · 2024 [cited by applicant]
US 12095734B1 · Engskow et al. · 2024 [cited by applicant]
US 12289289B1 · Deknecht et al. · 2025 [cited by applicant]
US 12445433B1 · Starosta et al. · 2025 [cited by applicant]
US 12476793B2 · Kumar · 2025 [cited by applicant]
US 20030079125A1 · Hope et al. · 2003 [cited by applicant]
US 20040083306A1 · Gloe · 2004 [cited by examiner]
US 20050203875A1 · Mohammed · 2005 [cited by examiner]
US 20060165060A1 · Dua · 2006 [cited by applicant]
US 20060248190A1 · Gardos et al. · 2006 [cited by applicant]
US 20070073660A1 · Quinlan · 2007 [cited by examiner]
US 20070253377A1 · Janneteau et al. · 2007 [cited by applicant]
US 20080104182A1 · Jimmei · 2008 [cited by applicant]
US 20080114879A1 · Roussel et al. · 2008 [cited by applicant]
US 20080189437A1 · Halley · 2008 [cited by applicant]
US 20100031078A1 · Foote et al. · 2010 [cited by applicant]
US 20100107215A1 · Bechtel et al. · 2010 [cited by applicant]
US 20100174785A1 · Cai · 2010 [cited by examiner]
US 20110078327A1 · Li et al. · 2011 [cited by applicant]
US 20110225206A1 · Sureshchandra et al. · 2011 [cited by applicant]
US 20110225263A1 · Sureshchandra et al. · 2011 [cited by applicant]
US 20110283174A1 · M'Raihi et al. · 2011 [cited by applicant]
US 20110283359A1 · Prince et al. · 2011 [cited by applicant]
US 20120066360A1 · Ghosh · 2012 [cited by applicant]
US 20120079115A1 · Richardson et al. · 2012 [cited by applicant]
US 20120239731A1 · Shyamsunder et al. · 2012 [cited by applicant]
US 20130018944A1 · Shyamsunder et al. · 2013 [cited by applicant]
US 20130085914A1 · McPherson et al. · 2013 [cited by applicant]
US 20140258346A1 · Meltzer et al. · 2014 [cited by applicant]
US 20140344663A1 · Joel et al. · 2014 [cited by applicant]
US 20150215276A1 · Bhagwat et al. · 2015 [cited by applicant]
US 20150281168A1 · Holloway et al. · 2015 [cited by applicant]
US 20150319097A1 · Hyatt et al. · 2015 [cited by applicant]
US 20160021055A1 · Krzywonos et al. · 2016 [cited by applicant]
US 20160026796A1 · Monrose et al. · 2016 [cited by applicant]
US 20160028847A1 · Bradshaw et al. · 2016 [cited by applicant]
US 20160197898A1 · Hozza et al. · 2016 [cited by applicant]
US 20160262021A1 · Lee et al. · 2016 [cited by applicant]
US 20160352840A1 · Negron et al. · 2016 [cited by applicant]
US 20160381048A1 · Zhao · 2016 [cited by examiner]
US 20170041321A1 · Tan · 2017 [cited by examiner]
US 20170048186A1 · Blinn · 2017 [cited by applicant]
US 20170099341A1 · Joe et al. · 2017 [cited by applicant]
US 20170279617A1 · Blinn et al. · 2017 [cited by applicant]
US 20170279792A1 · Tse et al. · 2017 [cited by applicant]
US 20170302699A1 · Adams · 2017 [cited by examiner]
US 20170310636A1 · Jheeta et al. · 2017 [cited by applicant]
US 20170339222A1 · Newton · 2017 [cited by applicant]
US 20170359447A1 · Chan et al. · 2017 [cited by applicant]
US 20180048673A1 · Hunt et al. · 2018 [cited by applicant]
US 20180213052A1 · MacCarthaigh · 2018 [cited by examiner]
US 20180219912A1 · Maslak et al. · 2018 [cited by applicant]
US 20180278471A1 · Burli et al. · 2018 [cited by applicant]
US 20180285170A1 · Gamon et al. · 2018 [cited by applicant]
US 20180324137A1 · Tuliani · 2018 [cited by applicant]
US 20180343122A1 · Spacek et al. · 2018 [cited by applicant]
US 20180375716A1 · Huque et al. · 2018 [cited by applicant]
US 20190044940A1 · Khalil et al. · 2019 [cited by applicant]
US 20190104103A1 · Newton · 2019 [cited by applicant]
US 20190116153A1 · Deverakonda Venkata et al. · 2019 [cited by applicant]
US 20190130100A1 · Dymshits · 2019 [cited by examiner]
US 20190132280A1 · Meuninck et al. · 2019 [cited by applicant]
US 20190207927A1 · Lakhani et al. · 2019 [cited by applicant]
US 20190238498A1 · Cleary et al. · 2019 [cited by applicant]
US 20190245875A1 · Chen · 2019 [cited by examiner]
US 20190306110A1 · Davis · 2019 [cited by applicant]
US 20200007548A1 · Sanghavi · 2020 [cited by examiner]
US 20200073944A1 · Mishra et al. · 2020 [cited by applicant]
US 20200134102A1 · Yoneuchi et al. · 2020 [cited by applicant]
US 20200137138A1 · Rice et al. · 2020 [cited by applicant]
US 20200220946A1 · Chan · 2020 [cited by examiner]
US 20210203671A1 · Baldwin · 2021 [cited by examiner]
US 20210289001A1 · Wilson et al. · 2021 [cited by applicant]
US 20220006772A1 · Eland · 2022 [cited by applicant]
US 20220021639A1 · Eland · 2022 [cited by applicant]
US 20220038544A1 · Grinstein et al. · 2022 [cited by applicant]
US 20220094661A1 · Woodworth et al. · 2022 [cited by applicant]
US 20220200976A1 · Lam et al. · 2022 [cited by applicant]
US 20220210147A1 · Galvin et al. · 2022 [cited by applicant]
US 20220286431A1 · Winn et al. · 2022 [cited by applicant]
US 20220321596A1 · Weizman et al. · 2022 [cited by applicant]
US 20220337654A1 · Koenig et al. · 2022 [cited by applicant]
US 20230156044A1 · St. Pierre et al. · 2023 [cited by applicant]
US 20230231870A1 · St. Pierre · 2023 [cited by applicant]
US 20230269269A1 · Bjarnason · 2023 [cited by applicant]
US 20230362207A1 · St. Pierre · 2023 [cited by examiner]
US 20240095733A1 · Gauvreau, Jr. · 2024 [cited by applicant]
US 20240119133A1 · Mohan et al. · 2024 [cited by applicant]
US 20240176829A1 · Vilcinskas · 2024 [cited by examiner]
US 20240195781A1 · Wertkin et al. · 2024 [cited by applicant]
US 20250047687A1 · Duan et al. · 2025 [cited by applicant]
US 20250071111A1 · Parla · 2025 [cited by applicant]
US 20250088531A1 · St. Pierre · 2025 [cited by examiner]
US 20250110816A1 · Kfir et al. · 2025 [cited by applicant]
US 20250211563A1 · Raghunath · 2025 [cited by applicant]
US 20250322045A1 · Starosta et al. · 2025 [cited by applicant]
US 20250323973A1 · Starosta et al. · 2025 [cited by applicant]
What is Airflow™?, «https://airflow.apache.org/docs/apache-airflow/stable/», captured on Apr. 9, 2024, 5 pages. [cited by applicant]
DAGs, Apache Airflow, date of publication unknown but, «https://airflow.apache.org/docs/apache-airflow/stable/concepts/dags.html», captured on Apr. 9, 2024, 27 pages. [cited by applicant]
Xu, Tony, “Step by Step: build a data pipeline with Airflow,” Towards Data Science, Aug. 15, 2020, «https://towardsdatascience.com/step-by-step-build-a-data-pipeline-with-airflow-4f96854f7466», captured on Apr. 9, 2024,… [cited by applicant]
Apache Airflow, “How to Work with Databases—ETL Pipeline,” better data science, captured on Apr. 9, 2024, «https://betterdatascience.com/apache-airflow-postgres-database/», 31 pages. [cited by applicant]
Access the Airflow database, «https://docs.astronomer.io/software/access-airflow-database», captured on Apr. 9, 2024, 10 pages. [cited by applicant]
Understanding the Airflow metadata database, «https://www.astronomer.io/guides/airflow-database», captured on Apr. 9, 2024, 8 pages. [cited by applicant]