IP Library Granted Patent US 12,732,521
Granted Patent B2
US 12,732,521 · App. 18/894,907 · Granted Sep 8, 2026

Inline detect and block relayed DNS tunneling traffic

Inventors: Ruian Duan (Fremont, CA); Shu Wang (San Jose, CA); Daiping Liu (Sunnyvale, CA); Fan Fei (Pleasanton, CA); Qi Zhang (Saratoga, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1425H04L63/1416H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,521
App. No.
18/894,907
Granted
Sep 8, 2026
Kind
B2
Abstract

The present application discloses a method, system, and computer system for detecting DNS tunneling traffic. The method includes (i) obtaining non-DNS network traffic across an enterprise network, (ii) obtaining a hostname comprised in the non-DNS network traffic, (iii) querying a security service for a Domain Name System (DNS) tunneling attack verdict based at least in part on the hostname, (iv) determining whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict, and (v) handling the non-DNS network traffic based at least in part on a determination of whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict.

Claims (59)

1 . A system, comprising:

one or more processors configured to:

obtain web traffic across an enterprise network;

obtain a hostname comprised in the web traffic;

query a security service for a Domain Name System (DNS) tunneling attack verdict based at least in part on the hostname;

determine whether the web traffic is malicious traffic based at least in part on the DNS tunneling attack verdict; and

handle the web traffic based at least in part on a determination of whether the web traffic is malicious traffic based at least in part on the DNS tunneling attack verdict; and

a memory coupled to the one or more processors and configured to provide the one or more processors with instructions.

2 . The system of claim 1 , wherein obtaining the web traffic across the enterprise network based on detecting the web traffic based at least in part on an application identifier associated with the web traffic.

3 . The system of claim 2 , wherein the one or more processors are further configured to:

determine, based at least in part on the application identifier, whether the web traffic is HTTP traffic, HTTPS traffic, or SMTP traffic.

4 . The system of claim 1 , wherein the web traffic is obtained by a firewall comprised in the enterprise network.

5 . The system of claim 1 , wherein the web traffic comprises a request and response communicated to/from the enterprise network.

6 . The system of claim 1 , wherein obtaining the web traffic comprises:

receiving the web traffic; and

decrypting the web traffic based at least in part on an SSL decryption.

7 . The system of claim 1 , wherein obtaining the web traffic comprises:

receiving the web traffic;

determining that the web traffic is encrypted using a non-standard encryption technique; and

in response to determining that the web traffic is encrypted using the non-standard encryption technique, deeming the web traffic as malicious or suspicious traffic.

8 . The system of claim 7 , wherein the non-standard encryption technique is a non-SSL encryption technique.

9 . The system of claim 1 , wherein obtaining the hostname comprised in the web traffic comprises:

extracting the hostname from metadata associated with the web traffic.

10 . The system of claim 1 , wherein the security service comprises a DNS cloud service.

11 . The system of claim 1 , wherein handling the web traffic based at least in part on the determination of whether the web traffic malicious comprises:

blocking the web traffic in response to determining that the web traffic is malicious.

12 . The system of claim 1 , wherein the security service returns the DNS tunneling verdict in response in response to processing the query based at least in part on the hostname.

13 . The system of claim 1 , wherein the DNS tunneling attack verdict is generated in near real time with interception of the web traffic by a firewall.

14 . The system of claim 1 , wherein the one or more processors are further configured to:

provide a notification to an administrator for the enterprise network in response to determining that the web traffic is malicious.

15 . The system of claim 14 , wherein the notification indicates one or more hosts compromised with an exploit associated with the web traffic.

16 . The system of claim 1 , wherein:

obtaining the hostname comprised in the web traffic comprises:

extracting header information from HTTP or HTTP web traffic; and

the header information comprises the hostname.

17 . The system of claim 1 , wherein:

obtaining the hostname comprised in the web traffic comprises:

extracting header information from SMTP web traffic; and

the header information comprises the hostname.

18 . The system of claim 1 , wherein:

obtaining the hostname comprised in the web traffic comprises:

extracting information from an Server Name Indication (SNI) field from TLS web traffic; and

the information extracted from the SNI field comprises the hostname.

19 . The system of claim 1 , wherein the DNS tunneling attack verdict indicates whether the hostname corresponds to a relayed DNS tunneling attack.

20 . The system of claim 1 , wherein the security service comprises a DNS cloud service that includes a DNS tunneling detector configured to generate the DNS tunneling attack verdict based at least in part on the hostname.

21 . The system of claim 1 , wherein the one or more processors are further configured to:

determine that the web traffic corresponds to a relayed DNS tunneling attack that abuses a reputable web service or an internal web service as a proxy to route DNS tunneling requests toward an attacker-controlled nameserver.

22 . A method, comprising:

obtaining web traffic across an enterprise network;

obtaining a hostname comprised in the web traffic;

querying a security service for a Domain Name System (DNS) tunneling attack verdict based at least in part on the hostname;

determining whether the web traffic is malicious traffic based at least in part on the DNS tunneling attack verdict; and

handling the web traffic based at least in part on a determination of whether the web traffic is malicious traffic based at least in part on the DNS tunneling attack verdict.

23 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

obtaining web traffic across an enterprise network;

obtaining a hostname comprised in the web traffic;

querying a security service for a Domain Name System (DNS) tunneling attack verdict based at least in part on the hostname;

determining whether the web traffic is malicious traffic based at least in part on the DNS tunneling attack verdict; and

handling the web traffic based at least in part on a determination of whether the web traffic is malicious traffic based at least in part on the DNS tunneling attack verdict.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2024
From: DUAN, RUIAN; WANG, SHU; LIU, DAIPING; FEI, FAN; ZHANG, QI
To: PALO ALTO NETWORKS, INC.
Reel/Frame 069308/0056 →
Continuity (1)
Related Publication 20260089178A1 · Mar 26, 2026
References Cited (27)
US 9794229B2 · Yu · 2017 [cited by applicant]
US 10097568B2 · Baughman · 2018 [cited by applicant]
US 10348767B1 · Lee · 2019 [cited by examiner]
US 10412107B2 · Brutzkus · 2019 [cited by applicant]
US 11606385B2 · Meyer · 2023 [cited by applicant]
US 11902250B2 · Moore · 2024 [cited by applicant]
US 12495071B2 · Sarakas · 2025 [cited by examiner]
US 12495073B2 · Kothari · 2025 [cited by examiner]
US 20180013775A1 · Jee · 2018 [cited by examiner]
US 20180124072A1 · Hamdi · 2018 [cited by examiner]
US 20180124094A1 · Hamdi · 2018 [cited by examiner]
US 20190058718A1 · Pangeni · 2019 [cited by examiner]
US 20200351244A1 · Moore · 2020 [cited by examiner]
US 20200351245A1 · Moore · 2020 [cited by examiner]
US 20200358858A1 · Shribman · 2020 [cited by examiner]
US 20200389469A1 · Litichever · 2020 [cited by examiner]
US 20220247678A1 · Atwal · 2022 [cited by examiner]
US 20220329442A1 · Bulusu · 2022 [cited by examiner]
US 20230370495A1 · Desai · 2023 [cited by examiner]
US 20240022600A1 · Zhang · 2024 [cited by examiner]
US 20240205240A1 · Duan · 2024 [cited by examiner]
CN 103326894 · 2013 [cited by applicant]
Alenezi, Rafa; Ludwig, Simone A. Classifying DNS Tunneling Tools For Malicious DoH Traffic. 2021 IEEE Symposium Series on Computational Intelligence (SSCI). https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=96601… [cited by examiner]
Sanjay et al. DNS Amplification & DNS Tunneling Attacks Simulation, Detection and Mitigation Approaches. 2020 International Conference on Inventive Computation Technologies (ICICT). https://ieeexplore.ieee.org/stamp/sta… [cited by examiner]
Boonyopakorn, Pongsarun; Changsan, Ukid. Malicious Traffic Detection in DNS Over HTTPS (DoH): Edge Prediction with Graph Convolutional Network. 2024 (ITC-CSCC). https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=1… [cited by examiner]
Nuojua et al. DNS Tunneling Detection Techniques—Classification, and Theoretical Comparison in Case of a Real APT Campaign. 2017. [cited by applicant]
Taner et al. Robust Edge Weight Synthesis for LPV Multi-Agent Systems with Integral Quadratic Constraints. Mar. 2023. [cited by applicant]