IP Library › Granted Patent US 11,153,330
Granted Patent B1
US 11,153,330 · App. 15/897,141 · Granted Oct 19, 2021

Detection of DNS (domain name system) tunneling and exfiltration through DNS query analysis

Inventor: Brad J. Antoniewicz (New Milford, NJ)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/1416H04L61/1511H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,330
App. No.
15/897,141
Granted
Oct 19, 2021
Kind
B1
Abstract

In one embodiment, a method includes collecting DNS (Domain Name System) communications, analyzing the DNS communications, and identifying DNS tunneling or exfiltration based analysis of the DNS communications. Analyzing the DNS communications includes identifying a distinct query count for each of a plurality of clients over a specified time period and a data transfer direction between the clients and one or more servers, and categorizing the DNS communications based on session features associated with at least one of query type, transfer capability, and server response. An apparatus and logic are also disclosed herein.

Claims (26)

1. A method comprising:

collecting and storing DNS (Domain Name System) communications comprising query and response information;

analyzing said stored DNS communications; and

identifying DNS tunneling or exfiltration based on analysis of said DNS communications;

wherein analyzing said DNS communications comprises:

identifying a distinct query count associated with a registered level-domain for each of a plurality of clients over a specified time period and a data transfer direction between said plurality of clients and one or more servers; and

categorizing said DNS communications based on session features associated with query type, wherein said categorization is based on transfer capability, server response, and query type diversity.

2. The method of claim 1 wherein said DNS communications comprise queries and analyzing said DNS communications further comprises analyzing lexical features of said queries.

3. The method of claim 1 wherein categorizing said DNS communications comprises categorizing usage based on client count.

4. The method of claim 1 further comprising prefiltering said DNS communications before analyzing said DNS communications.

5. The method of claim 1 further comprising actively probing a suspected authoritative name server.

6. The method of claim 1 wherein analyzing said DNS communications comprises analyzing a payload of a response.

7. The method of claim 1 wherein dynamic DNS domains are identified as public suffixes.

8. An apparatus comprising:

a DNS (Domain Name System) communications collector for collecting query and response information;

memory for storing said DNS communications; and

a DNS communications analyzer for identifying DNS tunneling or exfiltration based on analysis of said stored DNS communications;

wherein the DNS communications analyzer is configured for identifying a distinct query count associated with a registered level-domain for each of a plurality of clients over a specified time period and a data transfer direction between said plurality of clients and one or more servers, and categorizing said DNS communications based on session features associated with query type, wherein said categorization is based on transfer capability, server response, and query type diversity.

9. The apparatus of claim 8 wherein said DNS communications comprise queries and analyzing said DNS communications further comprises analyzing lexical features of said queries.

10. The apparatus of claim 8 wherein categorizing said DNS communications comprises categorizing usage based on client count.

11. The apparatus of claim 8 wherein dynamic DNS domains are identified as public suffixes.

12. The method of claim 1 further comprising categorizing the transfer capability by the server response.

13. The method of claim 1 further comprising breaking down features into said session features, lexical features, and active profiling.

14. The method of claim 2 wherein said lexical features describe characters within the query and are used to identify client-to-attacker traffic and attacker-to-client traffic.

15. The method of claim 2 wherein signature-based encoding detection is used to identify said lexical features.

16. The method of claim 1 further comprising using said query type and said server response to categorize bidirectional and attacker-to-client unidirectional transfers, using lexical analysis to detect data fields, and using active probing to identify client-to-attacker unidirectional transfers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2018
From: ANTONIEWICZ, BRAD J.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 044933/0578 →
Continuity (1)
Provisional Application 62589995 · Nov 22, 2017
Cited By (6)
US 12,301,595 US 12,445,410 US 12,531,829 US 12,568,094 US 12,598,198 US 12,683,984