IP Library Granted Patent US 12,445,410
Granted Patent B2
US 12,445,410 · App. 18/212,311 · Granted Oct 14, 2025

In-line detection of algorithmically generated domains

Inventors: Daiping Liu (Sunnyvale, CA); Martin Walter (Livermore, CA); Ben Hua (San Jose, CA); Suquan Li (Saratoga, CA); Fan Fei (San Jose, CA); Seokkyung Chung (Sunnyvale, CA); Jun Wang (Fremont, CA); Wei Xu (Cupertino, CA)
Assignee: Palo Alto Networks, Inc.
H04L61/4511G06F16/9566G06F21/552G06F21/554G06F21/56G06N20/00H04L61/10H04L61/3025H04L63/0236H04L63/029H04L63/1416H04L63/1425H04L63/20H04L63/0209H04L63/145H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,410
App. No.
18/212,311
Granted
Oct 14, 2025
Kind
B2
Abstract

Detection of algorithmically generated domains is disclosed. A DNS query is received. Markov Chain analysis is performed on a domain included in the received query. A determination of whether the received query implicates an algorithmically generated domain is made based at least in part on a result of the Markov Chain analysis.

Claims (44)

1. A system, comprising:

a processor configured to:

receive, at a first node, a DNS query in response to a client device making a DNS resolution request;

determine whether the received DNS query implicates an algorithmically generated domain (AGD) based at least in part by performing Markov Chain analysis on a domain included in the received DNS query; and

include, by the first node, in a response to the received DNS query, an indication that the DNS resolution request made by the client device is indicative of the client device engaging in AGD activity;

wherein the indication included in the response to the received DNS query is usable by a security appliance to at least partially remediate the client device; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein determining whether the received DNS query implicates the algorithmically generated domain includes evaluating historical resolution information.

3. The system of claim 2 , wherein the historical resolution information comprises a count of resolutions.

4. The system of claim 2 , wherein the historical resolution information comprises an interval between a first resolution and a last resolution.

5. The system of claim 1 , wherein performing the Markov Chain analysis includes using a model trained at least in part using a set of known algorithmically generated domains.

6. The system of claim 1 , wherein performing the Markov Chain analysis includes using a model trained at least in part using a set of known benign domains.

7. The system of claim 1 , wherein determining whether the received DNS query implicates the AGD includes using a random forest trained using features extracted from a plurality of other AGDs.

8. The system of claim 7 , wherein at least one feature comprises a domain suffix.

9. The system of claim 7 , wherein at least one feature comprises a count of hyphens.

10. The system of claim 7 , wherein at least one feature comprises a domain length.

11. The system of claim 7 , wherein at least one feature comprises a distinct number of characters.

12. The system of claim 7 , wherein at least one feature comprises a ratio of digits to other characters.

13. The system of claim 7 , wherein at least one feature comprises whether a first character of a root domain is a digit.

14. A method, comprising:

receiving, at a first node, a DNS query in response to a client device making a DNS resolution request;

determining whether the received DNS query implicates an algorithmically generated domain (AGD) based at least in part by performing Markov Chain analysis on a domain included in the received DNS query; and

including, by the first node, in a response to the received DNS query, an indication that the DNS resolution request made by the client device is indicative of the client device engaging in AGD activity;

wherein the indication included in the response to the received DNS query is usable by a security appliance to at least partially remediate the client device.

15. A computer program product embodied in a tangible computer readable storage medium and comprising computer instructions for:

receiving, at a first node, a DNS query in response to a client device making a DNS resolution request;

determining whether the received DNS query implicates an algorithmically generated domain (AGD) based at least in part by performing Markov Chain analysis on a domain included in the received DNS query; and

including, by the first node, in a response to the received DNS query, an indication that the DNS resolution request made by the client device is indicative of the client device engaging in AGD activity;

wherein the indication included in the response to the received DNS query is usable by a security appliance to at least partially remediate the client device.

16. The system of claim 1 , wherein the security appliance is configured to alert an administrator that the client device is engaging in AGD activity.

17. The system of claim 1 , wherein the security appliance is configured to quarantine the client device.

18. The system of claim 1 , wherein the security appliance is configured to prevent communications between the client device and the AGD.

19. The method of claim 14 , wherein determining whether the received DNS query implicates the algorithmically generated domain includes evaluating historical resolution information.

20. The method of claim 19 , wherein the historical resolution information comprises a count of resolutions.

21. The method of claim 19 , wherein the historical resolution information comprises an interval between a first resolution and a last resolution.

22. The method of claim 14 , wherein performing the Markov Chain analysis includes using a model trained at least in part using a set of known algorithmically generated domains.

23. The method of claim 14 , wherein performing the Markov Chain analysis includes using a model trained at least in part using a set of known benign domains.

24. The method of claim 14 , wherein determining whether the received DNS query implicates the AGD includes using a random forest trained using features extracted from a plurality of other AGDs.

25. The method of claim 24 , wherein at least one feature comprises a domain suffix.

26. The method of claim 24 , wherein at least one feature comprises a count of hyphens.

27. The method of claim 24 , wherein at least one feature comprises a domain length.

28. The method of claim 24 , wherein at least one feature comprises a distinct number of characters.

29. The method of claim 24 , wherein at least one feature comprises a ratio of digits to other characters.

30. The method of claim 24 , wherein at least one feature comprises whether a first character of a root domain is a digit.

Continuity (2)
Continuation 16588169 · Sep 30, 2019
Related Publication 20230336524A1 · Oct 19, 2023
References Cited (112)
US 7467410B2 · Graham · 2008 [cited by applicant]
US 7934254B2 · Graham · 2011 [cited by applicant]
US 7958555B1 · Chen · 2011 [cited by applicant]
US 8141157B2 · Farley · 2012 [cited by applicant]
US 8260914B1 · Ranjan · 2012 [cited by applicant]
US 8269914B2 · Huo · 2012 [cited by applicant]
US 8494985B1 · Keralapura · 2013 [cited by applicant]
US 8561177B1 · Aziz · 2013 [cited by applicant]
US 8566928B2 · Dagon · 2013 [cited by applicant]
US 8631489B2 · Antonakakis · 2014 [cited by applicant]
US 8826444B1 · Kalle · 2014 [cited by applicant]
US 9043894B1 · Dennison · 2015 [cited by applicant]
US 9178901B2 · Xue · 2015 [cited by applicant]
US 9330258B1 · Satish · 2016 [cited by applicant]
US 9356942B1 · Joffe · 2016 [cited by applicant]
US 9363282B1 · Yu · 2016 [cited by applicant]
US 9497213B2 · Thompson · 2016 [cited by applicant]
US 9516039B1 · Yen · 2016 [cited by applicant]
US 9621576B1 · Oprea · 2017 [cited by applicant]
US 9922190B2 · Antonakakis · 2018 [cited by applicant]
US 10089411B2 · Kassa · 2018 [cited by applicant]
US 10097568B2 · Baughman · 2018 [cited by applicant]
US 10270744B2 · Yu · 2019 [cited by applicant]
US 10679088B1 · Dalal · 2020 [cited by applicant]
US 10848509B1 · McNab · 2020 [cited by applicant]
US 11153330B1 · Antoniewicz · 2021 [cited by applicant]
US 11159486B2 · Pangeni · 2021 [cited by applicant]
US 20020111769A1 · Takeuchi · 2002 [cited by applicant]
US 20040073640A1 · Martin · 2004 [cited by applicant]
US 20060212925A1 · Shull · 2006 [cited by applicant]
US 20080028463A1 · Dagon · 2008 [cited by applicant]
US 20080155694A1 · Kwon · 2008 [cited by applicant]
US 20090089426A1 · Yamasaki · 2009 [cited by applicant]
US 20100192225A1 · Ma · 2010 [cited by applicant]
US 20110078794A1 · Manni · 2011 [cited by applicant]
US 20110191423A1 · Krasser · 2011 [cited by applicant]
US 20110231935A1 · Gula · 2011 [cited by applicant]
US 20110283359A1 · Prince · 2011 [cited by applicant]
US 20110283361A1 · Perdisci · 2011 [cited by applicant]
US 20120054860A1 · Wyschogrod · 2012 [cited by applicant]
US 20120303808A1 · Xie · 2012 [cited by applicant]
US 20120304287A1 · Yu · 2012 [cited by applicant]
US 20130080574A1 · Prince · 2013 [cited by applicant]
US 20130174253A1 · Thomas · 2013 [cited by applicant]
US 20130191915A1 · Antonakakis · 2013 [cited by applicant]
US 20130232574A1 · Carothers · 2013 [cited by applicant]
US 20140013434A1 · Ranum · 2014 [cited by applicant]
US 20140068763A1 · Ward · 2014 [cited by applicant]
US 20140068775A1 · Ward · 2014 [cited by applicant]
US 20140075558A1 · Ward · 2014 [cited by applicant]
US 20140090058A1 · Ward · 2014 [cited by applicant]
US 20140143825A1 · Behrendt · 2014 [cited by applicant]
US 20140230062A1 · Kumaran · 2014 [cited by applicant]
US 20140245436A1 · Dagon · 2014 [cited by applicant]
US 20140283063A1 · Thompson · 2014 [cited by applicant]
US 20140298460A1 · Xue · 2014 [cited by applicant]
US 20150007250A1 · Dicato, Jr. · 2015 [cited by applicant]
US 20150007312A1 · Pidathala · 2015 [cited by applicant]
US 20150143504A1 · Desai · 2015 [cited by applicant]
US 20150264070A1 · Harlacher · 2015 [cited by applicant]
US 20150281257A1 · Hart · 2015 [cited by applicant]
US 20160036848A1 · Reddy · 2016 [cited by examiner]
US 20160065611A1 · Fakeri-Tabrizi · 2016 [cited by applicant]
US 20160294773A1 · Yu · 2016 [cited by applicant]
US 20160352679A1 · Hagen · 2016 [cited by applicant]
US 20160352772A1 · O'Connor · 2016 [cited by applicant]
US 20160359887A1 · Yadav · 2016 [cited by applicant]
US 20170126706A1 · Minea · 2017 [cited by applicant]
US 20170295187A1 · Havelka · 2017 [cited by applicant]
US 20170331789A1 · Kumar · 2017 [cited by applicant]
US 20180063162A1 · Baughman · 2018 [cited by applicant]
US 20180115582A1 · Thakar · 2018 [cited by applicant]
US 20180124020A1 · Rodriguez · 2018 [cited by applicant]
US 20180198821A1 · Gopalakrishna · 2018 [cited by applicant]
US 20180278633A1 · Brutzkus · 2018 [cited by applicant]
US 20180351972A1 · Yu · 2018 [cited by applicant]
US 20200059451A1 · Huang · 2020 [cited by applicant]
US 20200169570A1 · Kleymenov · 2020 [cited by applicant]
US 20200228500A1 · Olumofin · 2020 [cited by applicant]
US 20210097168A1 · Patel · 2021 [cited by applicant]
US 20210126901A1 · Rodriguez · 2021 [cited by applicant]
US 20210203693A1 · Clausen · 2021 [cited by applicant]
US 20210400061A1 · Antoniewicz · 2021 [cited by applicant]
US 20220070194A1 · Pon · 2022 [cited by applicant]
CN 105577660 · 2019 [cited by applicant]
WO 2007050244 · 2007 [cited by applicant]
Van Der Toorn et al., TXTing 101: Finding Security Issues in the Long Tail of DNS TXT Records, 2020 IEEE European Symposium on Security and Privacy Workshops, 2020, pp. 544-549. [cited by applicant]
Alan Shaikh, Botnet Analysis and Detection System, Nov. 2010. [cited by applicant]
Antonakakis et al., DGAs and Cyber-Criminals: A Case Study, 2012. [cited by applicant]
Antonakakis et al., From Throw-Away Traffic to Bots: Detecting the Rise of DGA-Based Malware, 21st {USENIX} Security Symposium ({USENIX} Security 12), 2012, pp. 491-506. [cited by applicant]
Christian Rossow, Thesis, Using Malware Analysis to Evaluate Botnet Resilience, Apr. 23, 2013. [cited by applicant]
Dietrich et al., On Botnets That Use DNS for Command and Control, 2011 Seventh European Conference on Computer Network Defense, 2011, pp. 9-16. [cited by applicant]
Gavin E. Crooks, Inequalities Between the Jenson-Shannon and Jeffreys Divergences, 2008. [cited by applicant]
Greg Farnham et al., Detecting DNS Tunneling, SANS Institute InfoSec Reading Room, accepted on Feb. 25, 2013. [cited by applicant]
Guy Bruneau, DNS Sinkhole, Aug. 7, 2010, Sans Institute InfoSec Reading Room, pp. 1-41. [cited by applicant]
Ivan Nikolaev, Network Service Anomaly Detection, Jun. 2014. [cited by applicant]
Liu et al., CCGA: Clustering and Capturing Group Activities for DGA-Based Botnets Detection, 2019 18th IEEE International Conference on Trust, Security and Privacy in Computing and Communications/ 13th IEEE Internationa… [cited by applicant]
Martin Rataj, Simulation of Botnet C&C Channels, 2014. [cited by applicant]
Mustafa Toprak, Intrusion Detection System Alert Correlation with Operating System Level Logs, Dec. 11, 2009. [cited by applicant]
Nadler et al., Detection of Malicious and Low Throughput Data Exfiltration Over the DNS Protocol, Jun. 18, 2018. [cited by applicant]
Palo Alto Networks, We Know it Before You Do: Predicting Malicious Domains, retrieved on Jun. 22, 2015. [cited by applicant]
Pedro Marques da LUZ, Thesis, Botnet Detection Using Passive DNS, 2013/2014. [cited by applicant]
Qi et al., A Bigram Based Real Time DNS Tunnel Detection Approach, Procedia Computer Science 17, 2013, pp. 852-860. [cited by applicant]
Ql et al., BotCensor: Detecting DGA-Based Botnet Using Two-Stage Anomaly Detection, 2018 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications/ 12th IEEE International Confere… [cited by applicant]
Schüppen et al., FANCI: Feature-based Automated NXDomain Classification and Intelligence, Proceedings of the 27th USENIX Security Symposium, Aug. 2018, pp. 1165-1181. [cited by applicant]
Sebastian Garcia, Identifying, Modeling and Detecting Botnet Behaviors in the Network, Nov. 2014. [cited by applicant]
Seung Won Shin, Protecting Networked Systems from Malware Threats, Aug. 2013. [cited by applicant]
Shehar Bano, A Study of Botnets: Systemization of Knowledge and Correlation-based Detection, Oct. 2012. [cited by applicant]
Vishnu Teja Kilari, Thesis, Detection of Advanced Bots in Smartphones Through User Profiling, Dec. 2013. [cited by applicant]
Xu et al., We Know it Before You Do: Predicting Malicious Domains, Virus Bulletin Conference Sep. 2014. [cited by applicant]
Xu et al., We Know it Before You Do: Predicting Malicious Domains, Sep. 2014. [cited by applicant]
Qi et al., BotCensor: Detecting DGA-Based Botnet Using Two-Stage Anomaly Detection, 2018 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications/12th IEEE International Conferen… [cited by applicant]