DNS automated intelligence
Various techniques for providing a DNS automated intelligence solution are disclosed. In some embodiments, a DNS Automated Intelligence System (DAISy) is disclosed that includes a system designed to create threat intelligence for use in protective DNS, or DNS Detection and Response systems which control access to internet resources at a DNS resolver. The disclosed DAISy solution includes the ingestion of raw source data, the curation and refinement of this source data into specialized data sets used for identifying threats, active processes to increase visibility into internet domain names, and can also include human-in-the-loop acceleration that allows for rapid automation, and a modular incorporation of DNS-specific signatures for identification of suspicious domain names. The disclosed DAISy solution is self-sustaining, automated, and incorporates human guidance. Moreover, it is effective for scaling the detection of malicious and suspicious domains, which is not possible with existing traditional approaches to DNS security.
1 . A system, comprising:
a processor configured to:
selectively aggregate DNS data from a plurality of networks;
automatically classify DNS resources from the aggregated DNS data, comprising to:
identify a new domain from the aggregated DNS data;
determine at least one name server associated with the new domain;
classify the at least one name server based on a set of existing DNS signatures, wherein one DNS signature of the set of existing DNS signatures includes a set of characteristics, wherein the set of characteristics includes one or more of the following: a top level domain (TLD), a name server, autonomous system number (ASN), and/or a mail server;
determine that the at least one name server is malicious; and
in response to a determination that the at least one name server is malicious, determine that the at least one name server is a new threat domain;
send new threat domains to a DNS threat feed; and
perform the following action in response to identification of the new threat domain, comprising to:
block the new threat domain at a DNS security platform; and
a memory coupled to the processor and configured to provide the processor with instructions.
2 . The system recited in claim 1 , wherein a new domain server is identified as a compromised or an inherently malicious or suspicious name server.
3 . The system recited in claim 1 , wherein a new domain server is identified as a compromised or an inherently malicious or suspicious name server, and wherein new domains associated with the new domain server are monitored to identify new malicious domains.
4 . The system recited in claim 1 , wherein the aggregated DNS data is collected from a plurality of monitored enterprise, university, and/or government networks.
5 . The system recited in claim 1 , wherein the processor is further configured to:
report a new threat domain for a first network based on a DNS security policy associated with the first network.
6 . The system recited in claim 1 , wherein the processor is further configured to:
quarantine an unclassified domain for further security professional review to update configuration for a classifier.
7 . The system recited in claim 1 , wherein the processor is further configured to:
automatically generate a new DNS signature for a new DNS threat using a statistical classifier.
8 . The system recited in claim 1 , wherein the processor is further configured to:
periodically revisit the new threat domains during a predetermined time window to update threat intelligence information associated with the new threat domains.
9 . A method, comprising:
selectively aggregating DNS data from a plurality of networks;
automatically classifying DNS resources from the aggregated DNS data, comprising:
identifying a new domain from the aggregated DNS data;
determining at least one name server associated with the new domain;
classifying the at least one name server based on a set of existing DNS signatures, wherein one DNS signature of the set of existing DNS signatures includes a set of characteristics, wherein the set of characteristics includes one or more of the following: a top level domain (TLD), a name server, autonomous system number (ASN), and/or a mail server;
determining that the at least one name server is malicious; and
in response to a determination that the at least one name server is malicious, determining that the at least one name server is a new threat domain;
sending new threat domains to a DNS threat feed; and
performing the following action in response to identification of the new threat domain, comprising:
blocking the new threat domain at a DNS security platform.
10 . The method of claim 9 , wherein a new domain server is identified as a compromised or an inherently malicious or suspicious name server.
11 . The method of claim 9 , wherein a new domain server is identified as a compromised or an inherently malicious or suspicious name server, and wherein new domains associated with the new domain server are monitored to identify new malicious domains.
12 . The method of claim 9 , wherein the aggregated DNS data is collected from a plurality of monitored enterprise, university, and/or government networks.
13 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:
selectively aggregating DNS data from a plurality of networks;
automatically classifying DNS resources from the aggregated DNS data, comprising:
identifying a new domain from the aggregated DNS data;
determining at least one name server associated with the new domain;
classifying the at least one name server based on a set of existing DNS signatures, wherein one DNS signature of the set of existing DNS signatures includes a set of characteristics, wherein the set of characteristics includes one or more of the following: a top level domain (TLD), a name server, autonomous system number (ASN), and/or a mail server;
determining that the at least one name server is malicious; and
in response to a determination that the at least one name server is malicious, determining that the at least one name server is a new threat domain;
sending new threat domains to a DNS threat feed; and
performing the following action in response to identification of the new threat domain, comprising:
blocking the new threat domain at a DNS security platform.