IP Library Granted Patent US 12,621,316
Granted Patent B2
US 12,621,316 · App. 18/679,186 · Granted May 5, 2026

DNS automated intelligence

Inventors: Renée Carol Burton (Seattle, WA); Christopher June Kim (Puyallup, WA); Laura Teixeira da Rocha (Seattle, WA); Chance Mitchell Tudor (Athens, GA)
Assignee: Infoblox Inc.
H04L63/1416H04L61/4511H04L63/0236H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,316
App. No.
18/679,186
Granted
May 5, 2026
Kind
B2
Abstract

Various techniques for providing a DNS automated intelligence solution are disclosed. In some embodiments, a DNS Automated Intelligence System (DAISy) is disclosed that includes a system designed to create threat intelligence for use in protective DNS, or DNS Detection and Response systems which control access to internet resources at a DNS resolver. The disclosed DAISy solution includes the ingestion of raw source data, the curation and refinement of this source data into specialized data sets used for identifying threats, active processes to increase visibility into internet domain names, and can also include human-in-the-loop acceleration that allows for rapid automation, and a modular incorporation of DNS-specific signatures for identification of suspicious domain names. The disclosed DAISy solution is self-sustaining, automated, and incorporates human guidance. Moreover, it is effective for scaling the detection of malicious and suspicious domains, which is not possible with existing traditional approaches to DNS security.

Claims (49)

1 . A system, comprising:

a processor configured to:

selectively aggregate DNS data from a plurality of networks;

automatically classify DNS resources from the aggregated DNS data, comprising to:

identify a new domain from the aggregated DNS data;

determine at least one name server associated with the new domain;

classify the at least one name server based on a set of existing DNS signatures, wherein one DNS signature of the set of existing DNS signatures includes a set of characteristics, wherein the set of characteristics includes one or more of the following: a top level domain (TLD), a name server, autonomous system number (ASN), and/or a mail server;

determine that the at least one name server is malicious; and

in response to a determination that the at least one name server is malicious, determine that the at least one name server is a new threat domain;

send new threat domains to a DNS threat feed; and

perform the following action in response to identification of the new threat domain, comprising to:

block the new threat domain at a DNS security platform; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system recited in claim 1 , wherein a new domain server is identified as a compromised or an inherently malicious or suspicious name server.

3 . The system recited in claim 1 , wherein a new domain server is identified as a compromised or an inherently malicious or suspicious name server, and wherein new domains associated with the new domain server are monitored to identify new malicious domains.

4 . The system recited in claim 1 , wherein the aggregated DNS data is collected from a plurality of monitored enterprise, university, and/or government networks.

5 . The system recited in claim 1 , wherein the processor is further configured to:

report a new threat domain for a first network based on a DNS security policy associated with the first network.

6 . The system recited in claim 1 , wherein the processor is further configured to:

quarantine an unclassified domain for further security professional review to update configuration for a classifier.

7 . The system recited in claim 1 , wherein the processor is further configured to:

automatically generate a new DNS signature for a new DNS threat using a statistical classifier.

8 . The system recited in claim 1 , wherein the processor is further configured to:

periodically revisit the new threat domains during a predetermined time window to update threat intelligence information associated with the new threat domains.

9 . A method, comprising:

selectively aggregating DNS data from a plurality of networks;

automatically classifying DNS resources from the aggregated DNS data, comprising:

identifying a new domain from the aggregated DNS data;

determining at least one name server associated with the new domain;

classifying the at least one name server based on a set of existing DNS signatures, wherein one DNS signature of the set of existing DNS signatures includes a set of characteristics, wherein the set of characteristics includes one or more of the following: a top level domain (TLD), a name server, autonomous system number (ASN), and/or a mail server;

determining that the at least one name server is malicious; and

in response to a determination that the at least one name server is malicious, determining that the at least one name server is a new threat domain;

sending new threat domains to a DNS threat feed; and

performing the following action in response to identification of the new threat domain, comprising:

blocking the new threat domain at a DNS security platform.

10 . The method of claim 9 , wherein a new domain server is identified as a compromised or an inherently malicious or suspicious name server.

11 . The method of claim 9 , wherein a new domain server is identified as a compromised or an inherently malicious or suspicious name server, and wherein new domains associated with the new domain server are monitored to identify new malicious domains.

12 . The method of claim 9 , wherein the aggregated DNS data is collected from a plurality of monitored enterprise, university, and/or government networks.

13 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

selectively aggregating DNS data from a plurality of networks;

automatically classifying DNS resources from the aggregated DNS data, comprising:

identifying a new domain from the aggregated DNS data;

determining at least one name server associated with the new domain;

classifying the at least one name server based on a set of existing DNS signatures, wherein one DNS signature of the set of existing DNS signatures includes a set of characteristics, wherein the set of characteristics includes one or more of the following: a top level domain (TLD), a name server, autonomous system number (ASN), and/or a mail server;

determining that the at least one name server is malicious; and

in response to a determination that the at least one name server is malicious, determining that the at least one name server is a new threat domain;

sending new threat domains to a DNS threat feed; and

performing the following action in response to identification of the new threat domain, comprising:

blocking the new threat domain at a DNS security platform.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: BURTON, RENÉE CAROL; KIM, CHRISTOPHER JUNE; DA ROCHA, LAURA TEIXEIRA; TUDOR, CHANCE MITCHELL
To: INFOBLOX INC.
Reel/Frame 068297/0565 →
Continuity (2)
Provisional Application 63538587 · Sep 15, 2023
Related Publication 20250097238A1 · Mar 20, 2025
References Cited (32)
US 12500914B2 · Boord · 2025 [cited by examiner]
US 20020010798A1 · Ben-Shaul · 2002 [cited by examiner]
US 20120054106A1 · Stephenson · 2012 [cited by examiner]
US 20120198549A1 · Antonakakis · 2012 [cited by examiner]
US 20130061321A1 · Gardner · 2013 [cited by applicant]
US 20140007238A1 · Magee · 2014 [cited by applicant]
US 20140282887A1 · Kaminsky · 2014 [cited by examiner]
US 20150350240A1 · Mitchell · 2015 [cited by examiner]
US 20150373043A1 · Wang · 2015 [cited by examiner]
US 20160127402A1 · Veeramachaneni · 2016 [cited by examiner]
US 20160380773A1 · Woodworth · 2016 [cited by examiner]
US 20160381049A1 · Lakhani · 2016 [cited by examiner]
US 20160381077A1 · Bassias · 2016 [cited by examiner]
US 20170026391A1 · Abu-Nimeh · 2017 [cited by examiner]
US 20170163425A1 · Kaliski, Jr. · 2017 [cited by examiner]
US 20180167405A1 · Comay · 2018 [cited by examiner]
US 20200351270A1 · Burton · 2020 [cited by examiner]
US 20210168160A1 · Wang · 2021 [cited by examiner]
US 20210266293A1 · Liu · 2021 [cited by applicant]
US 20220060477A1 · Burton · 2022 [cited by applicant]
US 20220103597A1 · Gobena · 2022 [cited by examiner]
US 20220182401A1 · Boord · 2022 [cited by examiner]
US 20220353276A1 · Hegrat · 2022 [cited by examiner]
US 20230069845A1 · Woodworth · 2023 [cited by examiner]
US 20240422185A1 · Burton · 2024 [cited by examiner]
US 20250097238A1 · Burton · 2025 [cited by examiner]
US 20250097245A1 · Johnson · 2025 [cited by examiner]
CN 112425139A · 2021 [cited by examiner]
Marques et al., DNS Firewall Based on Machine Learning, Future Internet, MDPI, 2021, 13, 309, pp. 1-18. [cited by applicant]
Mitsuhashi et al., Identifying Malicious DNS Tunnel Tools from DoH Traffic Using Hierarchical Machine Learning Classification, Hokkaido University Collection of Scholarly and Academic Papers : HUSCAP, Information Securi… [cited by applicant]
Saeli et al., DNS Covert Channel Detection via Behavioral Analysis: a Machine Learning Approach, Oct. 4, 2020, pp. 1-10. [cited by applicant]
Tang et al., A Practical Machine Learning-Based Framework to Detect DNS Covert Communication in Enterprises, 2020. [cited by applicant]