IP Library › Granted Patent US 12,149,422
Granted Patent B2
US 12,149,422 · App. 18/321,218 · Granted Nov 19, 2024

Query prints (Qprints): telemetry-based similarity for DNS

Inventor: Renée Carol Burton (Seattle, WA)
Assignee: Infoblox Inc.
H04L43/067H04L43/04H04L43/0817H04L61/4511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,149,422
App. No.
18/321,218
Granted
Nov 19, 2024
Kind
B2
Abstract

Techniques for Qprints using telemetry-based similarity for DNS are provided. In some embodiments, a system/process/computer program product for Qprints using telemetry-based similarity for DNS in accordance with some embodiments includes aggregating a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related query data; clustering the DNS related query data; and generating similarity clusters for domains based on their DNS related query data. For example, the set of network related event data can include passive DNS (pDNS) data aggregated over a period of time to express pDNS data at-scale, and similarity of the pDNS data aggregated over the period of time is quantified, within and across networks based on telemetry-based similarity for DNS using a statistical model.

Claims (61)

1. A system, comprising:

a processor configured to:

aggregate a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related query data, comprising to:

create a vocabulary including a plurality of words, wherein a word of the plurality of words corresponds to a combination of a response code and a query type; and

generate a model for a given domain based on the vocabulary;

generate similarity clusters for domains based on the DNS related query data, comprising to:

group, based on the model, domains having a similar behavior to obtain a similarity cluster; and

perform an application using the similarity clusters for domains; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system recited in claim 1 , wherein the set of network related event data includes passive DNS (pDNS) data.

3. The system recited in claim 1 , wherein the set of network related event data includes passive DNS (pDNS) data aggregated over a period of time.

4. The system recited in claim 1 , wherein the set of network related event data includes passive DNS (pDNS) data aggregated over a period of time to express passive DNS (pDNS) data at-scale, and similarity of the pDNS data aggregated over the period of time is quantified, within and across networks based on telemetry-based similarity for DNS using a statistical model.

5. The system recited in claim 1 , wherein the set of network related event data includes DNS related query data associated with a first enterprise network and DNS related query data associated with a second enterprise network.

6. The system recited in claim 1 , wherein the processor is further configured to:

compare DNS activities within a first enterprise network based on a baseline of DNS activity associated with the first enterprise network.

7. The system recited in claim 1 , wherein the processor is further configured to:

detect anomalous network activity within a first enterprise network based on a baseline of DNS activity associated with the first enterprise network.

8. The system recited in claim 1 , wherein the processor is further configured to:

compare DNS activities between a first enterprise network and other enterprise networks.

9. The system recited in claim 1 , wherein:

the set of network related event data includes passive DNS (pDNS) data aggregated over a period of time to express pDNS data at-scale, and quantify similarity of the pDNS data aggregated over the period of time, within and across networks based on telemetry-based similarity for DNS; and

the performing of the application comprises to:

perform a similar domain search using the pDNS data aggregated over the period of time.

10. The system recited in claim 1 , wherein:

the set of network related event data includes passive DNS (pDNS) data aggregated over a period of time to express pDNS data at-scale, and quantify similarity of the pDNS data aggregated over the period of time, within and across networks based on telemetry-based similarity for DNS; and

the performing of the application comprises to:

perform a network summarization using the pDNS data aggregated over the period of time.

11. The system recited in claim 1 , wherein:

the set of network related event data includes passive DNS (pDNS) data aggregated over a period of time to express pDNS data at-scale, and quantify similarity of the pDNS data aggregated over the period of time, within and across networks based on telemetry-based similarity for DNS; and

the performing of the application comprises to:

perform a domain characterization using the pDNS data aggregated over the period of time.

12. The system recited in claim 1 , wherein:

the set of network related event data includes passive DNS (pDNS) data aggregated over a period of time to express pDNS data at-scale, and quantify similarity of the pDNS data aggregated over the period of time, within and across networks based on telemetry-based similarity for DNS; and

the performing of the application comprises to:

detect a domain change and/or anomaly using the pDNS data aggregated over the period of time.

13. The system recited in claim 1 , wherein:

the set of network related event data includes passive DNS (pDNS) data aggregated over a period of time to express pDNS data at-scale, and quantify similarity of the pDNS data aggregated over the period of time, within and across networks based on telemetry-based similarity for DNS; and

the performing of the application comprises to:

identify a network misconfiguration using the pDNS data aggregated over the period of time.

14. The system recited in claim 1 , wherein:

the set of network related event data includes passive DNS (pDNS) data aggregated over a period of time to express pDNS data at-scale, and quantify similarity of the pDNS data aggregated over the period of time, within and across networks based on telemetry-based similarity for DNS; and

the performing of the application comprises to:

perform service discovery using the pDNS data aggregated over the period of time.

15. A method, comprising:

aggregating a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related query data, comprising:

creating a vocabulary including a plurality of words, wherein a word of the plurality of words corresponds to a combination of a response code and a query type; and

generating a model for a given domain based on the vocabulary;

generating similarity clusters for domains based on the DNS related query data, comprising:

grouping, based on the model, domains having a similar behavior to obtain a similarity cluster; and

performing an application using the similarity clusters for domains.

16. The method of claim 15 , wherein the set of network related event data includes passive DNS (pDNS) data.

17. The method of claim 15 , wherein the set of network related event data includes passive DNS (pDNS) data aggregated over a period of time.

18. The method of claim 15 , wherein the set of network related event data includes passive DNS (pDNS) data aggregated over a period of time to express passive DNS (pDNS) data at-scale, and similarity of the pDNS data aggregated over the period of time is quantified, within and across networks based on telemetry-based similarity for DNS using a statistical model.

19. A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for:

aggregating a set of network related event data, wherein the set of network related event data includes Domain Name System (DNS) related query data, comprising:

creating a vocabulary including a plurality of words, wherein a word of the plurality of words corresponds to a combination of a response code and a query type; and

generating a model for a given domain based on the vocabulary;

generating similarity clusters for domains based on the DNS related query data, comprising:

grouping, based on the model, domains having a similar behavior to obtain a similarity cluster; and

performing an application using the similarity clusters for domains.

20. The computer program product recited in claim 19 , wherein the set of network related event data includes passive DNS (pDNS) data aggregated over a period of time to express pDNS data at-scale, and similarity of the pDNS data aggregated over the period of time is quantified, within and across networks based on telemetry-based similarity for DNS using a statistical model.

Assignments (2)
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Dec 15, 2023
From: INFOBLOX, INC.
To: MORGAN STANLEY SENIOR FUNDING INC., AS SECOND LIEN COLLATERAL AGENT
Reel/Frame 066043/0866 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Dec 15, 2023
From: INFOBLOX, INC.
To: MORGAN STANLEY SENIOR FUNDING INC., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 066043/0850 →
Continuity (3)
Continuation 17535226 · Nov 24, 2021
Provisional Application 63118259 · Nov 25, 2020
Related Publication 20230403216A1 · Dec 14, 2023