IP Library › Granted Patent US 12,580,927
Granted Patent B2
US 12,580,927 · App. 18/228,357 · Granted Mar 17, 2026

Detecting and protecting claimable non-existent domains

Inventors: Ruian Duan (Santa Clara, CA); Zhanhao Chen (Sunnyvale, CA); Janos Szurdi (Santa Clara, CA); Daiping Liu (Sunnyvale, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1416H04L63/0263H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,927
App. No.
18/228,357
Granted
Mar 17, 2026
Kind
B2
Abstract

Techniques for detecting and protecting claimable non-existent domains are disclosed. A system, process, and/or computer program product for detecting and protecting claimable non-existent domains includes monitoring network activity using a network security device, detecting that a session is querying a claimable non-existent domain using a domain name system (DNS) security service, and performing an action in response to the session querying the claimable non-existent domain.

Claims (42)

1 . A system, comprising:

a processor; and

a memory coupled to the processor and configured to provide the processor with instructions, when executed by the processor, to:

monitor network activity using a network security device;

detect that a session is querying a claimable non-existent domain (NXDOMAIN) using a domain name system (DNS) security service, wherein the detecting that the session is querying the claimable NXDOMAIN comprises to:

perform a high impact check, comprising to:

check a server-side source to identify a high impact NXDOMAIN; and

check a client-side source to identify a high impact NXDOMAIN, wherein the client-side source includes a telemetry log for determining domains having more than N customers or M visits, and/or a passive DNS log for determining domains having more than N customers or M visits, wherein N corresponds to a first positive integer, wherein M corresponds to a second positive integer; and

perform an action in response to the session querying the claimable NXDOMAIN.

2 . The system of claim 1 , wherein the server-side source includes a telemetry log, a passive DNS log, a DNS zone file, or any combination thereof.

3 . The system of claim 1 , wherein the client-side source includes an email domain list and/or a Whois database for determining recently expired domains.

4 . The system of claim 1 , wherein the detecting that the session is querying the claimable NXDOMAIN comprises to:

perform a claimability check for a candidate claimable NXDOMAIN.

5 . The system of claim 1 , wherein the detecting that the session is querying the claimable NXDOMAIN comprises to:

perform an internal resolvability check for a candidate claimable NXDOMAIN.

6 . The system of claim 1 , wherein the detecting that the session is querying the claimable NXDOMAIN comprises to:

perform a registration check for a candidate claimable NXDOMAIN.

7 . The system of claim 1 , wherein the claimable NXDOMAIN includes a root domain that is not registered or claimed and/or a rentable subdomain that is not registered or claimed.

8 . The system of claim 1 , wherein the action includes one or more of the following: block query, block a response to the claimable NXDOMAIN, alert an administrator, quarantine a source device querying the claimable NXDOMAIN, log a source device que rying the claimable NXDOMAIN, and/or register the claimable NXDOMAIN.

9 . A method, comprising:

monitoring network activity using a network security device;

detecting that a session is querying a claimable non-existent domain (NXDOMAIN) using a domain name system (DNS) security service, wherein the detecting that the session is querying the claimable NXDOMAIN comprises:

performing a high impact check, comprising:

checking a server-side source to identify a high impact NXDOMAIN; and

checking a client-side source to identify a high impact NXDOMAIN, wherein the client-side source includes a telemetry log for determining domains having more than N customers or M visits, and/or a passive DNS log for determining domains having more than N customers or M visits, wherein N corresponds to a first positive integer, wherein M corresponds to a second positive integer; and

performing an action in response to the session querying the claimable NXDOMAIN.

10 . The method of claim 9 , wherein the server-side source includes a telemetry log, a passive DNS log, a DNS zone file, or any combination thereof.

11 . The method of claim 9 , wherein the client-side source includes an email domain list and/or a Whois database for determining recently expired domains.

12 . The method of claim 9 , wherein the detecting that the session is querying the claimable NXDOMAIN comprises:

performing a claimability check for a candidate claimable NXDOMAIN.

13 . The method of claim 9 , wherein the detecting that the session is querying the claimable NXDOMAIN comprises:

performing an internal resolvability check for a candidate claimable NXDOMAIN.

14 . The method of claim 9 , wherein the detecting that the session is querying the claimable NXDOMAIN comprises:

performing a registration check for a candidate claimable NXDOMAIN.

15 . The method of claim 9 , wherein the action includes one or more of the following: block query, block a response to the claimable NXDOMAIN, alert an administrator, quarantine a source device querying the claimable NXDOMAIN, log a source device querying the claimable NXDOMAIN, and/or register the claimable NXDOMAIN.

16 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

monitoring network activity using a network security device;

detecting that a session is querying a claimable non-existent domain (NXDOMAIN) using a domain name system (DNS) security service, wherein the detecting that the session is querying the claimable NXDOMAIN comprises:

performing a high impact check, comprising:

checking a server-side source to identify a high impact NXDOMAIN; and

checking a client-side source to identify a high impact NXDOMAIN, wherein the client-side source includes a telemetry log for determining domains having more than N customers or M visits, and/or a passive DNS log for determining domains having more than N customers or M visits, wherein N corresponds to a first positive integer, wherein M corresponds to a second positive integer; and

performing an action in response to the session querying the claimable NXDOMAIN.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2023
From: DUAN, RUIAN; CHEN, ZHANHAO; SZURDI, JANOS; LIU, DAIPING
To: PALO ALTO NETWORKS, INC.
Reel/Frame 065147/0708 →
Continuity (1)
Related Publication 20250047687A1 · Feb 6, 2025
References Cited (13)
US 20150256424A1 · Kaliski, Jr. · 2015 [cited by examiner]
US 20160277438A1 · Xie · 2016 [cited by examiner]
US 20170163603A1 · Xu · 2017 [cited by applicant]
US 20170171242A1 · Akcin · 2017 [cited by examiner]
US 20180262520A1 · Xu · 2018 [cited by examiner]
US 20190253384A1 · Furuta · 2019 [cited by examiner]
US 20210250332A1 · Moore · 2021 [cited by applicant]
US 20210400061A1 · Antoniewicz · 2021 [cited by examiner]
US 20220182345A1 · Birch · 2022 [cited by examiner]
TW 202311994A · 2023 [cited by examiner]
Liu et al., Dangling Domains: Security Threats, Detection and Prevalence, Palo Alto Networks, Sep. 16, 2021, 14 pages, https://web.archive.org/web/20230531 001756/https://unit42.paloaltonetworks.com/dangling-domains/. [cited by applicant]
Chen, et al. “Client-side name collision vulnerability in the new gtld era: A systematic study.” Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. 2017. [cited by applicant]
Chen, et al. “MitM attack by name collision: Cause analysis and vulnerability assessment in the new gTLD era.” 2016 IEEE Symposium on Security and Privacy (SP). IEEE, 2016. [cited by applicant]