IP Library › Granted Patent US 10,547,636
Granted Patent B2
US 10,547,636 · App. 15/392,700 · Granted Jan 28, 2020

Method and system for detecting and mitigating denial-of-service attacks

Inventors: Duane Wessels (Moscow, ID); Matt Weinberg (Vienna, VA)
Assignee: VERISIGN, INC.
H04L63/1458H04L61/1511H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,547,636
App. No.
15/392,700
Granted
Jan 28, 2020
Kind
B2
Abstract

A method of detecting a DDOS attack is disclosed. The method includes obtaining, at an authoritative DNS server, a plurality of DNS query packets from a plurality of DNS requestors over a communications network; analyzing, by an electronic processor, a set of the plurality of DNS query packets; determining, by an electronic processor, that a subset of the plurality of DNS query packets of the set meets a predetermined threshold for a rate of DNS queries; filtering the plurality of DNS query packets based on the determining to produce a filtered number of DNS query packets; and providing, by the authoritative DNS server, a DNS response for the plurality of DNS query packets that were filtered.

Claims (28)

1. A method of detecting a distributed denial of service (DDOS) attack, the method comprising:

obtaining, at an authoritative domain name system (DNS) server, a plurality of DNS query packets from a plurality of DNS requestors over a communications network;

analyzing, by an electronic processor, a set of the plurality of DNS query packets to determine a count of unique source IP addresses in the plurality of DNS query packets over a predetermined period of time;

in response to the count reaching a predetermined threshold, determining that one or more fields in the set of the plurality of DNS query packets share a common feature, wherein the one or more fields comprise at least one or more of: a DNS data field, a recursion desired field, or a time-to-live field;

maintaining a count of the plurality of DNS query packets;

time sampling the set of the plurality of DNS query packets to generate a subset of the plurality of DNS query packets;

determining, by an electronic processor, that the subset of the plurality of DNS query packets of the set that share the common feature meets a predetermined threshold for a rate of DNS queries;

filtering the plurality of DNS query packets based on the determining to produce a filtered number of DNS query packets; and

providing, by the authoritative DNS server, a DNS response for the plurality of DNS query packets that were filtered.

2. A method of detecting a distributed denial of service (DDOS) attack, the method comprising:

obtaining a plurality of domain name system (DNS) query packets from a plurality of DNS requestors from one or more authoritative DNS servers;

analyzing, by an electronic processor, a set of the plurality of DNS query packets to determine a count of unique source IP addresses in the plurality of DNS query packets over a predetermined period of time;

in response to the count reaching a predetermined threshold, determining that one or more fields in the set of the plurality of DNS query packets share a common feature, wherein the one or more fields comprise at least one or more of: a DNS data field, a recursion desired field, or a time-to-live field;

maintaining a count of the plurality of DNS query packets;

time sampling the set of the plurality of DNS query packets to generate a subset of the plurality of DNS query packets;

determining, by an electronic processor, that the subset of the plurality of DNS query packets of the set that share the common feature meets a predetermined threshold; and

providing a result of the determining to a filtering mechanism of each of the one or more authoritative DNS servers.

3. A system comprising:

one or more processors; and

a memory system comprising one or more non-transitory computer-readable media storing instructions that are executed by at least one of the one or more processors, to cause the one or more processors to perform a method of detecting a distributed denial of service (DDOS) attack, the method comprising:

obtaining a plurality of domain name system (DNS) query packets from a plurality of DNS requestors over a communications network;

analyzing, by the one or more processors, a set of the plurality of DNS query packets to determine a count of unique source IP addresses in the plurality of DNS query packets over a predetermined period of time;

in response to the count reaching a predetermined threshold, determining that one or more fields in the set of the plurality of DNS query packets share a common feature, wherein the one or more fields comprise at least one or more of: a DNS data field, a recursion desired field, or a time-to-live field;

maintaining a count of the plurality of DNS query packets;

time sampling the set of the plurality of DNS query packets to generate a subset of the plurality of DNS query packets;

determining, by the one or more processors, that the subset of the plurality of DNS query packets of the set that share the common feature meets a predetermined threshold for a rate of DNS queries;

filtering the plurality of DNS query packets based on the determining to produce a filtered number of DNS query packets; and

providing a DNS response for the plurality of DNS query packets that were filtered.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2017
From: WESSELS, DUANE; WEINBERG, MATT
To: VERISIGN, INC.
Reel/Frame 043359/0742 →
Continuity (1)
Related Publication 20180183830A1 · Jun 28, 2018