IP Library Granted Patent US 12,517,966
Granted Patent B2
US 12,517,966 · App. 18/778,607 · Granted Jan 6, 2026

Ranking services and top N rank lists

Inventors: Laura Teixeira da Rocha (Seattle, WA); Renée Carol Burton (Seattle, WA)
Assignee: Infoblox Inc.
G06F16/9536G06F16/24578H04L61/4511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,517,966
App. No.
18/778,607
Granted
Jan 6, 2026
Kind
B2
Abstract

Techniques for ranking services and top N rank lists are disclosed. In some embodiments, a system, process, and/or computer program product for ranking services and top N rank lists includes receiving a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related event data; aggregating the DNS related event data over a period of time and rank order by popularity; and generating a top N rank list for ranking popularity over the period of time for a set of domains using the aggregated DNS related event data and rank order by popularity.

Claims (47)

1 . A system, comprising:

a processor configured to:

receive a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related event data;

aggregate the DNS related event data over a period of time and rank order by popularity;

generate a top N rank list for ranking popularity over the period of time for a set of domains using the aggregated DNS related event data and rank order by popularity; and

determine rank intervals using the top N rank list by aggregating the data over a set of consecutive periods of days to obtain ranks over the period of time for the set of domains, comprising to:

determine, over the period of time, a confidence interval for a rank of one domain of a plurality of domains of the set of network related event data, wherein the period of time includes a number of T days, wherein the determining of the confidence interval comprises to:

approximate daily T ranks associated with the one domain to a normal distribution, wherein the daily T ranks are determined based on ordered observation counts of the one domain; and

determine the confidence interval based on the normal distribution; and

order, based on popularity, the confidence interval of the one domain and confidence interval of another domain of the plurality of domains to obtain the rank intervals; and

output, based on the rank intervals, a rank interval list for the set of domains that is used by a network device to enforce a network security policy using the rank interval list; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system recited in claim 1 , wherein the processor is further configured to:

normalize the ranks; and

generate confidence intervals based on the normalized ranks.

3 . The system recited in claim 1 , wherein the processor is further configured to:

generate, based on the rank intervals, a most likely rank and an interval range for the set of domains.

4 . A method, comprising:

receiving a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related event data;

aggregating the DNS related event data over a period of time and rank order by popularity; and

generating a top N rank list for ranking popularity over the period of time for a set of domains using the aggregated DNS related event data and rank order by popularity; and

determining rank intervals using the top N rank list by aggregating the data over a set of consecutive period of days to obtain ranks over the period of time for the set of domains, comprising:

determining, over the period of time, a confidence interval for a rank of one domain of a plurality of domains of the set of network related event data, wherein the period of time includes a number of T days, wherein the determining of the confidence interval comprises:

approximating daily T ranks associated with the one domain to a normal distribution, wherein the daily T ranks are determined based on ordered observation counts of the one domain; and

determining the confidence interval based on the normal distribution; and

ordering, based on popularity, the confidence interval of the one domain and confidence interval of another domain of the plurality of domains to obtain the rank intervals; and

outputting, based on the rank intervals, a rank interval list for the set of domains that is used by a network device to enforce a network security policy using the rank interval list.

5 . The method of claim 4 , further comprising:

normalizing the ranks; and

generating confidence intervals based on the normalized ranks.

6 . The method of claim 4 , further comprising:

generating, based on the rank intervals, a most likely rank and an interval range for the set of domains.

7 . A non-transitory computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related event data;

aggregating the DNS related event data over a period of time and rank order by popularity;

generating a top N rank list for ranking popularity over the period of time for a set of domains using the aggregated DNS related event data and rank order by popularity; and

determining rank intervals using the top N rank list by aggregating the data over a set of consecutive periods of days to obtain ranks over the period of time for the set of domains, comprising:

determining, over the period of time, a confidence interval for a rank of one domain of a plurality of domains of the set of network related event data, wherein the period of time includes a number of T days, wherein the determining of the confidence interval comprises:

approximating daily T ranks associated with the one domain to a normal distribution, wherein the daily T ranks are determined based on ordered observation counts of the one domain; and

determining the confidence interval based on the normal distribution; and

ordering, based on popularity, the confidence interval of the one domain and confidence interval of another domain of the plurality of domains to obtain the rank intervals; and

outputting, based on the rank intervals, a rank interval list for the set of domains that is used by a network device to enforce a network security policy using the rank interval list.

8 . The non-transitory computer program product recited in claim 7 , further comprising computer instructions for:

normalizing the ranks; and

generating the confidence intervals based on the normalized ranks.

9 . The non-transitory computer program product recited in claim 7 , further comprising computer instructions for:

generating, based on the rank intervals, a most likely rank and an interval range for the set of domains.

Continuity (4)
Continuation 18140501 · Apr 27, 2023
Division 17161436 · Jan 28, 2021
Provisional Application 62968825 · Jan 31, 2020
Related Publication 20240370511A1 · Nov 7, 2024
References Cited (22)
US 20160065535A1 · O'Leary · 2016 [cited by examiner]
US 20170155562A1 · Vasant · 2017 [cited by examiner]
US 20200351270A1 · Burton · 2020 [cited by applicant]
Author Unknown, “A Science of Cities: Rank Clocks”, captured Jan. 24, 2020. [cited by applicant]
Author Unknown, “CI*Rank: Ranked Incidence and Mortality Rates by State, County, and Special Region”, National Cancer Institute, Division of Cancer Control and Population Sciences, captured Nov. 6, 2020. Retrieved from … [cited by applicant]
Diaa Al Mohamad et al., “An improvement of Tukey's HSD with application to ranking institutions”; Leiden University Medical Center, The Netherlands; Aug. 9, 2017. [cited by applicant]
Diaa Al Mohamad, “Simultaneous Confidence Intervals for Ranks With Application to Ranking Institutions”, Nov. 26, 2018. [cited by applicant]
E Clare Marshall et al., “Reliability of league tables of in vitro fertilisation clinics: retrospective analysis of live birth rates”, BMJ vol. 316, Jun. 6, 1998. [cited by applicant]
Hamish Oglivy, “Reinforcement learning assisted search ranking”, Medium, Jan. 10, 2018. [cited by applicant]
Jean Morrison et al., “Rank conditional coverage and confidence intervals in high dimensional problems”, Department of Biostatistics, University of Washington, Seattle, WA, Feb. 24, 2017. [cited by applicant]
Jean Morrison et al., “Rank Conditional Coverage and Confidence Intervals in High-Dimensional Problems”, from https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6364309/, Jun. 14, 2018. [cited by applicant]
Luca Becchetti et al., “The Distribution of PageRank Follows a Power-Law only for Particular Values of the Damping Factor”, WWW2006, May 22-26, 2006, Edinburgh, UK. [cited by applicant]
M. E. J. Newman, “Power laws, Pareto distributions and Zipf's law”, Department of Physics and Center for the Study of Complex Systems, University of Michigan, Ann Arbor, MI 48109, U.S.A. May 29, 2006. [cited by applicant]
O'Madadhain et al., “Prediction and Ranking Algorithms for Event-Based Network Data”, SIGKDD Explorations, vol. 7, Issue 2., Dec. 2005. [cited by applicant]
Pochat et al., “Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation”, Dec. 17, 2018. [cited by applicant]
Quirin Scheitle et al., “A Long Way to the Top: Significance, Structure and Stability of Internet Top Lists”, Sep. 23, 2018. [cited by applicant]
Rick Wicklin, “Ranking with confidence: Part 1”, from https://blogs.sas.com/content/iml/2011/03/25/ranking-with-confidence-part-1.html, Mar. 25, 2011. [cited by applicant]
Roger Newson, “Confidence intervals for rank statistics: percentile slopes, differences and ratios”, Stata Journal, vol. 6, pp. 497-520, ISSN: 1536-867X, 2006. [cited by applicant]
Ting Bie, “Confidence Intervals for Ranks: Theory and Applications in Binomial Data”, Department of Statistics, Uppsala University, 2013. [cited by applicant]
Tom Callahan et al., “On Modern DNS Behavior and Properties”, Case Western Reserve University, International Computer Science Institute, 2013. [cited by applicant]
Walter Rweyemamu et al., “Clustering and the Weekend Effect: Recommendations for the Use of Top Domain Lists in Security Research”, 2019. [cited by applicant]
Zheng Wang, “Analysis of DNS Cache Effects on Query Distribution”, The Scientific World Journal, Jul. 31, 2013. [cited by applicant]