IP Library › Granted Patent US 12,355,792
Granted Patent B2
US 12,355,792 · App. 18/072,485 · Granted Jul 8, 2025

Strategically aged domain detection

Inventors: Zhanhao Chen (Sunnyvale, CA); Daiping Liu (Sunnyvale, CA); Wanjin Li (Santa Clara, CA); Fan Fei (San Jose, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1425H04L63/1416H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,792
App. No.
18/072,485
Granted
Jul 8, 2025
Kind
B2
Abstract

Detection of strategically aged domains is detected. A list of aged dormant domains is determined, including by evaluating passive Domain Name System (DNS) information. The list of aged dormant domains is monitored for a change by an aged dormant domain from a dormant domain status to an active status. In response to determining the change to active status of the aged dormant domain, an action is taken with respect to the aged dormant domain.

Claims (34)

1. A system, comprising:

a processor configured to:

determine, as a list of candidate strategically aged domains, a set of initially benign aged dormant domains, including by evaluating passive Domain Name System (DNS) information;

monitor the list of candidate strategically aged domains for a change by a particular domain from a dormant status to an active status, at least in part by determining that a threshold volume of DNS traffic for the particular domain has been exceeded; and

in response to determining the change to active status of the particular domain, take a remedial action with respect to the particular domain; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein taking the remedial action includes determining whether the particular domain is associated with an algorithmically generated domain.

3. The system of claim 2 , wherein determining whether the particular domain is associated with the algorithmically generated domain includes performing Markov chain analysis.

4. The system of claim 2 , wherein determining whether the particular domain is associated with the algorithmically generated domain includes evaluating a DNS traffic pattern for an abnormality.

5. The system of claim 1 , wherein taking the remedial action includes determining whether the particular domain is associated with a phishing attack.

6. The system of claim 1 , wherein taking the remedial action includes determining whether the particular domain is associated with wildcard DNS abuse.

7. The system of claim 1 , wherein taking the remedial action includes adding the particular domain to a block list.

8. The system of claim 1 , wherein taking the remedial action includes responding to a DNS query with an indication that a DNS request indicates that a client has been compromised.

9. The system of claim 1 , wherein determining the list includes determining whether an average DNS request for a given domain is below a threshold for a given time window.

10. The system of claim 1 , wherein monitoring the list of candidate strategically aged domains includes determining whether an average DNS request for a given domain is above a threshold within a time window.

11. The system of claim 1 , wherein the processor is further configured to collect a first set of metrics quantifying activities associated with the particular domain prior to changing status and collect a second set of metrics quantifying activities associated with the particular domain after changing the status.

12. A method, comprising:

determining, as a list of candidate strategically aged domains, a set of initially benign aged dormant domains, including by evaluating passive Domain Name System (DNS) information;

monitoring the list of candidate strategically aged domains for a change by a particular domain from a dormant status to an active status, at least in part by determining that a threshold volume of DNS traffic for the particular domain has been exceeded; and

in response to determining the change to active status of the particular domain, taking a remedial action with respect to the particular domain.

13. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

determining, as a list of candidate strategically aged domains, a set of initially benign aged dormant domains, including by evaluating passive Domain Name System (DNS) information;

monitoring the list of candidate strategically aged domains for a change by a particular domain from a dormant status to an active status, at least in part by determining that a threshold volume of DNS traffic for the particular domain has been exceeded; and

in response to determining the change to active status of the particular domain, taking a remedial action with respect to the particular domain.

14. The method of claim 12 , wherein taking the remedial action includes determining whether the particular domain is associated with an algorithmically generated domain.

15. The method of claim 14 , wherein determining whether the particular domain is associated with the algorithmically generated domain includes performing Markov chain analysis.

16. The method of claim 14 , wherein determining whether the particular domain is associated with the algorithmically generated domain includes evaluating a DNS traffic pattern for an abnormality.

17. The method of claim 12 , wherein taking the remedial action includes determining whether the particular domain is associated with a phishing attack.

18. The method of claim 12 , wherein taking the remedial action includes determining whether the particular domain is associated with wildcard DNS abuse.

19. The method of claim 12 , wherein taking the remedial action includes adding the particular domain to a block list.

20. The method of claim 12 , wherein taking the remedial action includes responding to a DNS query with an indication that a DNS request indicates that a client has been compromised.

21. The method of claim 12 , wherein determining the list includes determining whether an average DNS request for a given domain is below a threshold for a given time window.

22. The method of claim 12 , wherein monitoring the list of candidate strategically aged domains includes determining whether an average DNS request for a given domain is above a threshold within a time window.

23. The method of claim 12 , further comprising collecting a first set of metrics quantifying activities associated with the particular domain prior to changing status and collecting a second set of metrics quantifying activities associated with the particular domain after changing the status.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2023
From: CHEN, ZHANHAO; LIU, DAIPING; LI, WANJIN; FEI, FAN
To: PALO ALTO NETWORKS, INC.
Reel/Frame 062966/0135 →
Continuity (1)
Related Publication 20240179164A1 · May 30, 2024
References Cited (12)
US 10178121B2 · Klatt · 2019 [cited by examiner]
US 10686814B2 · Arnell · 2020 [cited by examiner]
US 10944781B1 · Bilge · 2021 [cited by examiner]
US 20140250524A1 · Meyers · 2014 [cited by examiner]
US 20190012456A1 · Moore · 2019 [cited by examiner]
US 20190068624A1 · Compton · 2019 [cited by examiner]
US 20210099414A1 · Liu · 2021 [cited by examiner]
Gao et al., “Reexamining DNS From a Global Recursive Resolver Perspective”, IEEE/ACM Transactions on Networking, vol. 24, Issue: 1, (Year: Feb. 2016). [cited by examiner]
He et al., Mining DNS for Malicious Domain Registrations, 6th International Conference on Collaborative Computing: Networking, Applications and Worksharing, 2010. [cited by applicant]
Spooren et al., PREMADOMA: An Operational Solution for DNS Registries to Prevent Malicious Domain Registrations, 2019 Annual Computer Security Applications Conference, Dec. 2019. [cited by applicant]
Huang, Caiyun et al. SFDS: A Self-Feedback Detection System for DNS Hijacking Based on Multi-Protocol Cross Validation 26th International Conference on Telecommunications (ICT), IEEE, XP033596542, DOI: 10.1109/ICT.2019.… [cited by applicant]
Suwa et al., DNS Resource Record Analysis of URLs in E-Mail Messages for Improving Spam Filtering, 2011 IEEE/IPSJ International Symposium on Applications and the Internet, Aug. 30, 2011. [cited by applicant]