US2022368669A1PendingUtilityA1

Filtering and organizing process for domain name system query collection

Assignee: AT & T IP I LPPriority: May 23, 2019Filed: Aug 1, 2022Published: Nov 17, 2022
Est. expiryMay 23, 2039(~12.8 yrs left)· nominal 20-yr term from priority
H04L 61/251H04L 67/1038H04L 61/4511H04L 2101/659H04L 67/1036
62
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for filtering, distributing, and organizing domain name system queries in a communications network may include receiving a first domain name system query from a first endpoint device connected to the network, identifying a first network address of the first endpoint device from the first domain name system query, classifying the first domain name system query into a first class of a plurality of classes, wherein each class of the plurality of classes is associated with one predefined numerical range of a plurality of predefined numerical ranges, and wherein a target address unit of the first network address falls into the predefined numerical range associated with the first class, and forwarding the first domain name system query to a first collection server of a plurality of collection servers, wherein the first collection server is dedicated for collecting domain name system queries that are classified into the first class.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving, by a processing system in a communications network, a first domain name system query from an edge router connected to the communications network, where the first domain name system query is associated with a first endpoint device;   identifying, by the processing system, a first network address of the first endpoint device from the first domain name system query;   classifying, by the processing system, the first domain name system query into a first class of a plurality of classes, wherein each class of the plurality of classes is associated with one predefined numerical range of a plurality of predefined numerical ranges, and wherein a target address unit of the first network address falls into a first predefined numerical range of the plurality of predefined numerical ranges that is associated with the first class; and   forwarding, by the processing system, the first domain name system query to a first repository of a plurality of repositories, wherein the first repository is dedicated for storing domain name system queries that are classified into the first class.   
     
     
         2 . The method of  claim 1 , wherein the first domain name system query is duplicated by the edge router in the communications network prior to being received by the processing system. 
     
     
         3 . The method of  claim 1 , wherein the first network address is an internet protocol address. 
     
     
         4 . The method of  claim 3 , wherein the target address unit of the first network address is a last address unit of the internet protocol address. 
     
     
         5 . The method of  claim 3 , wherein the internet protocol address is an internet protocol version 4 address, and the target address unit is an octet of the internet protocol address. 
     
     
         6 . The method of  claim 5 , wherein the plurality of classes comprises two classes, and the first predefined numerical range comprises a range from one to 255. 
     
     
         7 . The method of  claim 6 , further comprising:
 receiving, by the processing system, a second domain name system query from the edge router connected to the communications network, where the second domain name system query is associated with a second endpoint device;   identifying, by the processing system, a second network address of the second endpoint device from the second domain name system query;   classifying, by the processing system, the second domain name system query into a second class of the plurality of classes, wherein a target address unit of the second network address falls into a second predefined numerical range of the plurality of predefined numerical ranges associated with the second class; and   forwarding, by the processing system, the second domain name system query to a second repository of the plurality of repositories, wherein the second repository is dedicated for collecting domain name system queries that are classified into the second class.   
     
     
         8 . The method of  claim 7 , wherein the second predefined numerical range comprises a range greater than 255. 
     
     
         9 . The method of  claim 3 , wherein the internet protocol address is an internet protocol version 6 address, and the target address unit is a hextet of the internet protocol address. 
     
     
         10 . The method of  claim 1 , wherein a number of the plurality of repositories is a power of two. 
     
     
         11 . The method of  claim 10 , wherein a number of the plurality of classes is equal to the number of the plurality of repositories. 
     
     
         12 . The method of  claim 1 , wherein each repository of the plurality of repositories corresponds to a different data lake. 
     
     
         13 . The method of  claim 1 , wherein the processing system is implemented in a switch. 
     
     
         14 . The method of  claim 1 , wherein the processing system is implemented in a collection server that is independent of the plurality of repositories. 
     
     
         15 . The method of  claim 1 , wherein the processing system is implemented in a load balancer. 
     
     
         16 . A non-transitory computer-readable medium storing instructions which, when executed by a processing system in a communications network, cause the processing system to perform operations, the operations comprising:
 receiving a first domain name system query from an edge router connected to the communications network, where the first domain name system query is associated with a first endpoint device;   identifying a first network address of the first endpoint device from the first domain name system query;   classifying the first domain name system query into a first class of a plurality of classes, wherein each class of the plurality of classes is associated with one predefined numerical range of a plurality of predefined numerical ranges, and wherein a target address unit of the first network address falls into a first predefined numerical range of the plurality of predefined numerical ranges that is associated with the first class; and   forwarding the first domain name system query to a first repository of a plurality of repositories, wherein the first repository is dedicated for collecting domain name system queries that are classified into the first class.   
     
     
         17 . The non-transitory computer-readable medium of  claim 16 , wherein the first network address is an internet protocol address. 
     
     
         18 . The non-transitory computer-readable medium of  claim 17 , wherein the target address unit of the first network address is a last address unit of the internet protocol address. 
     
     
         19 . The non-transitory computer-readable medium of  claim 18 , wherein the internet protocol address is an internet protocol version 4 address, the plurality of classes comprises two classes, and the first predefined numerical range comprises a range from one to 255. 
     
     
         20 . A device comprising:
 a processing system including at least one processor; and   a non-transitory computer-readable medium storing instructions which, when executed by the processing system when deployed in a communications network, cause the processing system to perform operations, the operations comprising:
 receiving a first domain name system query from an edge router connected to the communications network, where the first domain name system query is associated with a first endpoint device; 
 identifying a first network address of the first endpoint device from the first domain name system query; 
 classifying the first domain name system query into a first class of a plurality of classes, wherein each class of the plurality of classes is associated with one predefined numerical range of a plurality of predefined numerical ranges, and wherein a target address unit of the first network address falls into a first predefined numerical range of the plurality of predefined numerical ranges that is associated with the first class; and 
 forwarding the first domain name system query to a first repository of a plurality of repositories, wherein the first repository is dedicated for collecting domain name system queries that are classified into the first class.

Join the waitlist — get patent alerts

Track US2022368669A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.