IP Library Granted Patent US 12,641,055
Granted Patent B2
US 12,641,055 · App. 18/819,496 · Granted May 26, 2026

Collecting passive DNS traffic to generate a virtual authoritative DNS server

Inventors: John R. Woodworth (Amissville, VA); Dean Ballew (Sterling, VA); Mark Dehus (Thornton, CO)
Assignee: Level 3 Communications, LLC
H04L61/4511H04L61/301H04L61/58
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,641,055
App. No.
18/819,496
Granted
May 26, 2026
Kind
B2
Abstract

The present application describes a system and method for passively collecting DNS traffic data as that data is passed between a recursive DNS resolver and an authoritative DNS server. The information contained in the collected DNS traffic data is used to generate a virtual authoritative DNS server, or a zone associated with the authoritative DNS server, when it is determined that the authoritative DNS server has been compromised.

Claims (13)

1 . A method, comprising:

passively capturing domain name system (DNS) data;

detecting a trigger event associated with an authoritative DNS server;

in response to detecting the trigger event:

causing a recursive DNS resolver to retrieve last known valid information associated with a zone from an observer system, the last known valid information being associated with the passively captured DNS data; and

causing the recursive DNS resolver to use the passively captured DNS data to provide an answer to a query received from a remote computing device;

generating a virtual authoritative DNS server using the passively captured DNS data; and

causing the recursive DNS resolver to host the virtual authoritative DNS server.

2 . The method of claim 1 , further comprising storing the passively captured DNS data at the observer system.

3 . The method of claim 1 , wherein detecting the trigger event comprises detecting a change in an address record associated with the authoritative DNS server.

4 . The method of claim 1 , wherein detecting the trigger event comprises receiving a notification from an entity associated with the authoritative DNS server.

5 . The method of claim 1 , wherein detecting the trigger event comprises determining that an internet protocol (IP) address associated with an answer to a received query is identified in a database of known IP address threats.

6 . The method of claim 1 , wherein the passively captured DNS data is associated with a geographic area.

Assignments (3)
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (SECOND LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0749 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (FIRST LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: BALLEW, DEAN; WOODWORTH, JOHN R.; DEHUS, MARK
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 068470/0116 →
Continuity (4)
Continuation 18204711 · Jun 1, 2023
Continuation 17479685 · Sep 20, 2021
Provisional Application 63101241 · Sep 21, 2020
Related Publication 20240422122A1 · Dec 19, 2024
References Cited (8)
US 9736185B1 · Belamaric · 2017 [cited by applicant]
US 11444931B1 · Quevedo · 2022 [cited by applicant]
US 20140006577A1 · Joe · 2014 [cited by examiner]
US 20170019371A1 · Osterweil · 2017 [cited by applicant]
US 20180343122A1 · Spacek · 2018 [cited by applicant]
US 20190342260A1 · Treuhaft · 2019 [cited by examiner]
US 20220094661A1 · Woodworth · 2022 [cited by applicant]
US 20230308414A1 · Woodworth · 2023 [cited by applicant]