Network addresses with encoded DNS-level information

US10616250B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10616250-B2
Application numberUS-201615389276-A
CountryUS
Kind codeB2
Filing dateDec 22, 2016
Priority dateOct 5, 2016
Publication dateApr 7, 2020
Grant dateApr 7, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods are described to enable a DNS service to encode information into a network address to be advertised by the DNS service. Information encoded by a DNS service may include, for example, an identifier of a content set to which the network address corresponds (e.g., a domain name) and validity information, such as a digital signature, that verifies the validity of the network address. On receiving a request to communicate with the network address, a destination device associated with the network address may decode the encoded information within the network address to assist in processing the request. In some instances, the encoded information may be used to identify malicious network transmissions, such as transmissions forming part of a network attack, potentially without reliance on other data, such as separate mappings or contents of the data transmission.

First claim

Opening claim text (preview).

What is claimed is: 1. A content delivery system configured to mitigate network attacks on a domain name, wherein the domain name is associated with content provided by the content delivery system, the content delivery system comprising: a domain name system (DNS) computing device comprising a processor configured with computer-executable instructions to: obtain one or more encoding rules for encoding DNS-level information into network addresses provided by the DNS computing device, wherein the one or more rules comprise multiple rule versions; obtain a request to resolve the domain name into a network address of a host device providing content associated with the domain name; encode, into the network address of the host device and according to the one or more encoding rules, the domain name and a version identifier associated with a rule version, of the multiple rule versions, utilized in encoding the encoded network address; and return the network address of the host device in response to the request; a computing device comprising a processor configured with computer-executable instructions to: obtain one or more decoding rules for decoding DNS-level information encoded into network addresses by the DNS computing device; detect a malicious data packet addressed to the network address of the host device, wherein the malicious data packet forms at least a part of a network attack on the content delivery system; decode, according to the one or more decoding rules, the domain name from the network address of the host device which the malicious data packet is addressed; and identify the domain name decoded from the network address of the host device to which the malicious data packet is addressed as a target of the network attack. 2. The content delivery system of claim 1 , wherein the network address is formatted as an Internet Protocol version 6 (Ipv6) address. 3. The content delivery system of claim 1 , wherein the one or more encoding rules specify information to be included within individual bits of the network addresses. 4. The content delivery system of claim 1 , wherein the network address comprises a first portion corresponding to routing information on a publically addressable network, and a second portion including encoded DNS-level information. 5. The content delivery system of claim 1 , wherein the computing device is at least one of a content server computing device or a networking routing computing device. 6. A computer-implemented method for providing DNS-level information within encoded network addresses, the computer-implemented method comprising: obtaining one or more rules for encoding DNS-level information into the encoded network addresses and decoding DNS-level information from the encoded network addresses, wherein the rules specify a format of the DNS-level information when encoded in the encoded network addresses and individual bits of the encoded network addresses to utilize in representing the DNS-level information; receiving a DNS request to resolve a domain name into a network address of a host device providing content associated with the domain name; using the one or more rules to encode DNS-level information associated with the DNS request into the network address of the host device, wherein one or more rules comprise multiple rule versions, and wherein using the one or more rules to encode the DNS-level information associated with the DNS request into the network address of the host device further comprising encoding into the network address a version identifier associated with a rule version, of the multiple rule versions, utilized in encoding the network address; returning the network address of the host device in response to the DNS request; receiving a network packet addressed to the network address of the host device; using the one or more rules to decode the DNS-level information from the network address of the host device; and routing data packet address to the network address based at least in part on the DNS-level information decoded from the network address of the host device. 7. The computer-implemented method of claim 6 , wherein the DNS-level information includes at least one of the domain name, security information associated with the domain name, timing information of the DNS request, information specifying a source of the DNS request, or validity information indicating a validity of the network address generated based at least in part on the DNS request. 8. The computer-implemented method of claim 6 , wherein the DNS-level information includes the domain name, the computer-implemented method further comprising: identifying the network packet as malicious and forming at least part of a network attack; and identifying the domain name decoded from the network address to which the malicious network packet is addressed as a target of the network attack. 9. The computer-implemented method of claim 6 , wherein the DNS-level information includes validity information, and wherein routing the data packet based at least in part on the DNS-level information decoded from the network address comprises: detecting that the validity information indicates that network packet is addressed to an invalid network address; and discarding the network packet. 10. The computer-implemented method of claim 6 , wherein the DNS-level information includes validity information, and wherein routing the data packet based at least in part on the DNS-level information decoded from the network address comprises: detecting that the validity information indicates that network packet is addressed to a valid network address; and routing the network packet to a content server associated with the domain name. 11. The computer-implemented method of claim 10 , wherein the validity information indicates a time of the DNS request, and wherein detecting that the validity information indicates that network packet is addressed to the valid network address includes detecting that a period of time between a current time and the time of the DNS request falls with a threshold time-to-live value. 12. The computer-implemented method of claim 10 , wherein the validity information includes a digital signature associated with a public key, and wherein detecting that the validity information indicates that network packet is addressed to the valid network address includes verifying the digital signature using the public key. 13. Non-transitory computer-readable media comprising computer-executable instructions for encoding DNS-level information within network addresses that, when executed, cause a computing system to: obtain one or more rules for encoding the DNS-level information into the network addresses and decoding the DNS-level information from the network addresses; obtain a request for an encoded network address of a host device providing content associated with a domain name, wherein the request includes DNS-level information associated with a DNS request to resolve the domain name into the encoded network address of the host device; encode the DNS-level information into the encoded network address of the host device according to at least the one or more rules, wherein one or more rules comprise multiple rule versions, and wherein the instructions further cause the computing system to encode into the network address a version identifier associated with a rule version, of the multiple rule versions, utilized in encoding the network address; return the encoded network address of the host device in response to the request; receive a network request associated with the encoded network address of the host device; decode the encoded netwo

Assignees

Inventors

Classifications

  • Denial of Service · CPC title

  • using cryptographic hash functions · CPC title

  • Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy · CPC title

  • using a plurality of keys or algorithms · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10616250B2 cover?
Systems and methods are described to enable a DNS service to encode information into a network address to be advertised by the DNS service. Information encoded by a DNS service may include, for example, an identifier of a content set to which the network address corresponds (e.g., a domain name) and validity information, such as a digital signature, that verifies the validity of the network add…
Who is the assignee on this patent?
Amazon Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 07 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).