Efficient Provisioning of Internet Lines and Secure Domain Name Systems

The system efficiently provisions Internet circuits and implements a secure DNS firewall, addressing the technical challenges faced by small businesses in managing their Internet access and online security.

JP2025518699APending Publication Date: 2025-06-19LEVEL 3 COMMUNICATIONS LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024570297
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-06-05
Filing Date
2023-06-02
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Small business owners lack the technical expertise to configure Internet equipment and securely manage their employees' online activities, leading to potential unauthorized access and reckless internet usage.

Method used

A system and method for efficiently provisioning Internet circuits and implementing a secure Domain Name System (DNS) firewall, which allows customers to request Internet services and DNS firewall configurations through a network provider configuration system, automatically allocating IP addresses and configuring customer premises equipment to route DNS requests through the DNS firewall system for filtering.

Benefits of technology

The solution enables small businesses to efficiently and securely manage their Internet access by automatically provisioning Internet circuits and configuring DNS firewalls, thereby protecting their networks from unauthorized access and ensuring compliance with desired online usage policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025518699000001_ABST
    Figure 2025518699000001_ABST
Patent Text Reader

Abstract

This application describes a system and method for automatically provisioning a domain name system (DNS) firewall service for an Internet connection. In an example, customer premise equipment and a DNS firewall system are automatically configured to operate with an Internet connection without requiring technical knowledge or customer intervention.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application claims the benefit of U.S. Provisional Application No. 63 / 365,866, filed Jun. 5, 2022, entitled “Efficient Provisioning of Internet Circuit and Secure Domain Name System,” which is hereby incorporated by reference in its entirety.

Background Art

[0002] Many small businesses rely on computing and Internet access to compete in the modern marketplace. Additionally, protection from unauthorized or reckless access from a company's network to prohibited websites is desirable. However, many small business owners lack the technical expertise to configure equipment or safely control their employees' online activities. Aspects of the present application may relate to this general technical environment.

Summary of the Invention

[0003] This application describes systems and methods for the efficient provisioning of Internet circuits and secure domain name systems.

[0004] For example, an aspect of the present application is a method comprising receiving, in a network provider configuration system, a request from a customer to provision an Internet line and to provision a Domain Name System (DNS) firewall system for the Internet line, where the request includes customer information; allocating an Internet Protocol (IP) address space to the Internet line; using the customer information and the allocated IP address space to cause the Internet line to be provisioned; causing tenant data for the customer to be automatically stored in the DNS firewall system based on receiving the request to provision the DNS firewall system for the Internet line, where the tenant data includes at least the allocated IP address space; and causing DNS requests received from the allocated IP address space to be processed by the DNS firewall system.

[0005] In another example, an aspect of the present application is a method comprising receiving, in a DNS firewall system for an Internet connection, a request from a network provider configuration system to instantiate the DNS firewall system, where the request includes customer information and an Internet Protocol (IP) address space assigned to the Internet connection; automatically extracting the customer information and the assigned IP address space from the request; automatically storing tenant data for the customer in the DNS firewall system, where the tenant data includes at least the assigned IP address space; receiving, by the DNS firewall system, a first DNS request from the assigned IP address space; and processing, by the DNS firewall system, the first DNS request, where the processing includes determining that the first DNS request includes a first domain within a first category; determining whether the first category is permitted for the customer; if the first category is permitted for the customer, causing the first DNS request to be resolved to a first IP address associated with the first domain; and if the first category is not permitted for the customer, causing the first DNS request to be rejected.

[0006] In another example, an aspect of the present application is a system comprising at least one processor; and a memory operably connected to the at least one processor and storing instructions that, when executed by the at least one processor, cause the system to perform a method. In the example, the method includes receiving, in a network provider configuration system, a request from a customer to provision an Internet line and to provision a Domain Name System (DNS) firewall system for the Internet line, where the request includes customer information; allocating an Internet Protocol (IP) address space to the Internet line; using the customer information and the allocated IP address space to cause the Internet line to be provisioned; causing tenant data for the customer to be automatically stored in the DNS firewall system based on receiving the request to provision the DNS firewall system for the Internet line, where the tenant data includes at least the allocated IP address space; and causing DNS requests received from the allocated IP address space to be processed by the DNS firewall system.

[0007] This summary is provided to introduce a selected simplified form of concepts that are further described in the detailed description below. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

Brief Description of the Drawings

[0008] Non-limiting and non-exhaustive examples are described with reference to the following figures.

[0009]

Figure 1

[0010]

Figure 2

[0011]

Figure 3

[0012]

Figure 4

[0013]

Figure 5

[0014]

Figure 6

Mode for Carrying Out the Invention

[0015] In the following detailed description, reference is made to the accompanying drawings, which form a part hereof and in which specific embodiments or examples are shown by way of illustration. Without departing from the present disclosure, these aspects may be combined, other aspects may be utilized, and structural changes may be made. The examples may be implemented as a method, system, or device. Thus, the examples may take the form of a hardware implementation, a completely software implementation, or an implementation combining software and hardware aspects. In addition, all systems described with respect to the figures may include one or more machines or devices operably connected to cooperate to provide the functionality of the described systems. Accordingly, the following detailed description should not be construed in a limiting sense, and the scope of the present disclosure is defined by the appended claims and their equivalents.

[0016] FIG. 1 discloses an exemplary system 100 according to an aspect of the present disclosure. A provider configuration system 102 may be provided by an Internet service provider or other network provider to arrange for a customer network connection (e.g., an Internet line 103 between a customer network 104 and a provider edge router 105 on a network 101 so that a customer device 106 operating on or connected to the customer network 104 can access a wide area network such as the Internet 109). It is understood that all connections between the systems shown with respect to FIG. 1 may be wired or wireless and may include various intervening devices and systems.

[0017] The provider configuration system 102 may provide a customer portal including a user interface to enable an Internet connection to be ordered by a customer and then provisioned to the customer. For example, the provider configuration system 102 may be operably connected to one or more customer devices 106 (e.g., through a third-party wired or wireless connection, before the customer Internet line 103 is provisioned). In an example, after the customer Internet line 103 is provisioned, the same or different customer devices 106 may be connected to the Internet 109 through the customer network 104, the customer Internet line 103, and the provider edge router 105. In an example, the customer network 104 may include at least one device referred to as customer premises equipment (CPE) 107. In an example, the CPE 107 may include a network address translation (NAT) device (or a router having a NAT function) that assigns an Internet protocol (IP) address to customer devices 106 on the customer network 104 and routes messages to and from the customer network 104.

[0018] In an example, provider network 101 may also provide a domain name system (DNS) firewall system 108. The DNS firewall system 108 may provide, in an example, a DNS firewall service for filtering DNS requests from a customer network such as customer network 104. The DNS firewall system 108 may permit or deny access by customer device 106 to a particular Internet site (or other network location). For example, the DNS firewall system 108 may maintain a customizable configuration for a plurality of customers, each customer being a tenant of the DNS firewall system 108. The configuration may include customer-specific instructions regarding categories of Internet sites such as social media, news, sports, entertainment, and the like. For example, a first customer may permit customer devices connected to its network to access social media sites, while another customer may choose to prohibit such access from its customer network.

[0019] When a customer device attempts to access the Internet 109 via the Internet line 103, the browser on the customer device may issue a DNS request to convert a domain name (e.g., www.example.com) to a specific IP address so as to reach the desired site. When the DNS firewall system 108 receives a DNS request from the customer network 104 to resolve a specific domain name to an IP address, the DNS firewall system first determines the category for the specific domain name and determines whether the category of that domain is permitted to be accessed by that customer network, and either (e.g., by returning an IP address for that domain) allows the request to be resolved or (if the domain falls into a category prohibited for that customer network) rejects the request. The DNS firewall system 108 may also be operably connected to a threat intelligence system 110 and / or one or more separate DNS systems 111, as further contemplated herein.

[0020] A non-exclusive example of the provider configuration system 102 is shown in FIG. 2. In an exemplary provider configuration system 102, an order system 202, a customer information system 204, a line information system 206, and a configuration system 208 may be provided. As contemplated, any system of the provider configuration system 102 may be combined or distributed across one or multiple physical devices operably connected by a wired or wireless connection in an implementation combining software and hardware.

[0021] In an example, the order system 202 may include a customer portal that enables customers of the network 101 to order specific products and services. For example, the order system 202 may provide one or more user interfaces for display on a device (e.g., the customer device 106). In an example, a customer may provide customer information such as the customer name, the physical location of the customer, whether the customer provides its own customer premise equipment 107, or whether it needs to be delivered to the customer as part of the ordered service, through such a user interface. In particular, the order system 202 may collect the necessary information from the customer to provision a new Internet line 103 between the provider edge router 105 of the network 101 and the customer network 104 (including CPE 107).

[0022] The customer information system 204 may include one or more data stores for storing customer information, such as customer information received through the order system 202. In some examples, the customer information stored in the customer information system 204 may be received or obtained from other computing systems of the provider. For example, if a customer is ordering an Internet line 103 from the provider using the order system 202, the customer may already be a customer of other products / services of that provider, and information about that customer may already be stored in or available to the customer information system 204. For example, a customer may already have an Internet line, but may order an additional Internet line 103. In this case, the order system may obtain customer information from the customer information system 204 (e.g., based on a previously stored account identifier) as part of the order process for the new Internet line 103.

[0023] The line information system 206 may store information about the network 101, for example, including an existing Internet line, available ports on the provider edge router 105, an IP address space available for assignment to the new Internet line 103, etc., or may be configured to obtain it from one or more other network systems. The line information system 206 may be used by the order system 202 to provide information about the nearest available provider edge router 105 for a particular customer (e.g., based on customer information received through the order system 202). The line information system 206 may also cooperate with the configuration system 208 as described below.

[0024] In an example, the configuration system 208 may cause a service ordered through the order system 202 to be provisioned within the network 101. For example, when the order system 202 receives a request from a customer for a new Internet line 103, the configuration system 208 may collaborate with the line information system 206 to determine the most advantageous way to provision the new Internet line 103. For example, in an example, the configuration system 208 may identify one or more available ports on the existing provider edge router 105 for the new Internet line 103. In other examples, the configuration system 208 may determine that a new provider edge router 105 should be added to the network 101 (either at a new location or an existing location) to accommodate the new Internet line 103. The configuration system 208 may also cause one or more workflows to be initiated to have the new Internet line 103 designed or implemented by a technician. The configuration system 208 may also assign an IP address space to the new Internet line 103 (e.g., assign the first IP address of the assigned IP address space to the CPE 107 and the second IP address of the assigned IP address space to the provider edge router 105). In an example, the configuration system 208 may cause the provider edge router 105 to be automatically configured to advertise the IP addresses of the assigned IP address space.

[0025] In an example, the configuration system 208 may also cause the CPE 107 to be automatically configured. In some examples, the provider of the network 101 may also provide the customer with the CPE 107, and the identification information of the CPE (e.g., device type, MAC address, etc.) may be assigned by the configuration system 208 and stored in the customer information system 204. For example, if the provider of the network 101 also provides the customer with the CPE 107 as part of an order for a new Internet line 103, the CPE 107 may be preconfigured to "call home" to the configuration system 208 to receive configuration information. The configuration information provided to the CPE 107 may include, for example, one or more IP addresses for the CPE 107. The configuration information may also include one or more IP addresses for one or more provider edge routers 105 that the CPE 107 will use when routing traffic from the customer network 104 to the network 101. In some examples, the configuration information is stored in the customer information system 204 and / or the line information system 206.

[0026] As examined, using the order system 202, a customer may order a new Internet line 103. The order system 202 may be available to an automation process through an application programming interface (API). In some examples, the order system 202 may also provide the customer with an easy option to order a DNS firewall service for the new Internet line 103. For example, in the same user interface used to order the Internet line 103 (e.g., on the same web page presented to the customer before an action equivalent to where the order is submitted or through an API-based order system, or on a series of related web pages presented to the user), the customer may be permitted to optionally add a DNS firewall service. In an example, the DNS firewall service (e.g., provided by the DNS firewall system 108) enables the customer to restrict the domains that the customer device 106 is permitted to access from the customer network 104.

[0027] In an example, by combining a process for ordering and provisioning a new Internet line 103 with a DNS firewall system 108 for that line, efficiencies and functionality not achievable using a separate order / provisioning process are made possible. As a non-exclusive example, the configuration system 208 may automatically configure the CPE 107 so that DNS requests are sent from the customer device 106 addressed to the DNS firewall system 108. For example, the CPE 107 may be programmed to provide a DNS firewall system IP address configuration to individual customer devices 106 (e.g., using Dynamic Host Configuration Protocol (DHCP) configuration settings), and then this customer device 106 will use the DNS firewall system 108 for DNS resolution. In particular, the CPE 107 may be automatically and remotely configured by the configuration system 208 (e.g., when the CPE 107 "calls home" to receive configuration information) to configure DNS settings in its DHCP configuration, and then those DNS settings are used by the customer device 106 to obtain an IP address advertised by the DNS firewall system 108. In some examples, remote configuration of the CPE 107 may be accomplished by sending a configuration from the configuration system 208 to the CPE 107 using an executable configuration script. The executable configuration script may be specific to the type of device (e.g., manufacturer, model, etc.) that includes the CPE 107, and it may be operable to configure the CPE 107 to apply the correct DNS firewall system IP address configuration to the customer device 106.In some examples, CPE 107 may also be configured by configuration system 208 to permit such requests only when DNS requests from customer device 106 are sent addressed to DNS firewall system 108 for DNS resolution, thereby reducing the risk that some techniques used by a user or malicious actor of customer device 106 will circumvent the use of DNS firewall system 108 for DNS resolution.

[0028] Configuration system 208 may also communicate with DNS firewall system 108 to automatically configure the customer as a new tenant of the DNS firewall service and alert DNS firewall system 108 that DNS requests from the IP address space assigned to new Internet link 103 should be filtered using the DNS firewall service. In some examples, configuration system 208 does not directly configure CPE 107 to send all DNS requests from customer device 106 addressed to DNS firewall system 108. Instead, it communicates with CPE 107 such that an automated process is initiated in DNS firewall system 108 to effect such a configuration. In other examples, CPE 107 need not be managed by the provider of network 101. Thus, instead, configuration system 208 may cause a notification to be sent to the customer along with instructions on how to configure CPE 107 to send all DNS requests from customer device 106 addressed to DNS firewall system 108.

[0029] An exemplary DNS firewall system 108 (used to provide DNS firewall services) is described with respect to FIG. 3. In some examples, the DNS firewall system may be co-located with the provider edge router 105, for example, at an edge computing site of the network 101. In an example, the DNS firewall system may include a filter system 302, a tenant data system 304, a category information system 306, and a DNS server 308. The filter system 302 may be configured to reject DNS requests sent to domains that are not permitted access by customer devices 106 on the customer network 104, for example. In an example, rejecting a DNS request may include dropping the request (without resolving the domain in the request to an IP address) and returning a notification (through the CPE 107) to the customer device 106 indicating that the domain the customer device 106 was attempting to reach is not permitted according to the rules of the customer network 104. In other examples, rejecting a DNS request may include resolving the domain to the IP address of a site that displays such a notification rather than the IP address of the requested site.

[0030] The tenant data system 304 may store tenant information about the tenants of the DNS firewall system 108 or may be configured to obtain it from one or more other network systems. In an example, the tenant information may comprise a portion of customer information received from the provider configuration system 102 when a new Internet line 103 is ordered with DNS firewall service. For example, the tenant information stored (or obtainable) by the tenant data system 304 may include the customer name and location, customer contact information, the type of equipment comprising the CPE 107, and the IP address space assigned to the Internet line 103 for that customer and for which the DNS firewall service is subscribed. The tenant data may also include tenant configuration information for a particular customer regarding the domains (or categories of domains) for which DNS requests should be rejected (or permitted) by the filter system 302.

[0031] In some examples, when a new Internet line 103 is ordered with the DNS firewall service for that line, the tenant data system 304 receives a request from the provider configuration system 102. In an example, the tenant data system 304 automatically extracts customer information from the received request and automatically provisions the customer as a new tenant (if the customer is not already a tenant of the DNS firewall system 108). In an example, the request from the provider configuration system 102 also includes the IP address space associated with the new Internet line. The tenant data system 304 may, in an example, associate the IP address space with the newly created tenant (based on the customer information) or with the previously stored tenant information (if the customer is already a tenant).

[0032] In addition, requests from the provider configuration system 102 also cause the tenant data system 304 to initiate a configuration process for the DNS firewall service. For example, the tenant data system 304 may send a message (e.g., an email) to start a process for the customer to select a category of domains for which DNS requests will be rejected by the filtering system 302 using the customer contact information included in the request from the provider configuration system. In an example, the tenant data system 304 provides a user interface (e.g., selectable via a link in an email to the customer) to turn filtering on or off for a particular category of domains. In other examples, such a link may direct the customer to a portal within a control center associated with the DNS firewall system 108. In other examples, the customer may navigate individually to such a control center to customize the DNS firewall service configuration. In other examples, the customer may utilize an API associated with the DNS firewall system 108 to customize the DNS firewall service configuration. In an example, the tenant data system 304 provides a default selection (e.g., based on the majority preference trends of most other DNS firewall service tenants or otherwise) and uses that default selection if no other instructions are received from the customer. In some examples, such a default selection is provided as a starting point in the user interface of the tenant data system 304 to all customers, and then the customer can customize that particular selection for filtering from the default selection. In an example, the user interface presented by the tenant data system 304 may also allow the customer to specifically specify particular domains on an access allow list and an access deny list, and each of the access allow list and the access deny list may override a decision made for category information in the absence of such a specification. The tenant configuration data stored in the tenant data system 304 may specify the domains or categories of domains for which DNS requests should be filtered (or permitted).Tenant configuration data may be applied to all Internet lines of a tenant. In other examples, tenant configuration data may be specific to a tenant, a group of end users of that tenant, and a particular Internet line of an individual end user.

[0033] In an example, the filter system 302 and the tenant data system 304 may cooperate with a category information system 306, and the category information system 306 may store current information about domain categories or may be configured to obtain it from one or more other network systems. For example, the category information system 306 may store a list of known domain names and may associate one or more categories with such domain names. For example, a domain such as example1.com may be classified by the category information system 306 as a social media site, while another domain such as example2.com may be classified as a video streaming site. In some cases, a particular domain may be associated with multiple categories.

[0034] The category information system 306 may receive (or obtain) data from third-party services and may be continuously updated when new sites are added or discovered. In an example, the category information system 306 may communicate with the threat intelligence system 110. The threat intelligence system 110 may maintain a list of known malicious sites. Such a list may be used individually by the threat intelligence system 110 (e.g., in conjunction with other network elements of the threat mitigation system) to mitigate the impact of such sites (e.g., by dropping any packets received from the source IP address associated with such a site). The threat intelligence system 110 may provide such a list of known malicious sites to the category information system 306. If the threat intelligence system 110 identifies a particular domain as participating in malicious activity on the network 101, the category information system 306 may create a category for the known malicious domain and associate such identified domains with that category by the threat intelligence system 110. The tenant data system 304 may default to storing configuration data that selects the category of known malicious domains to be removed (rejected) by filtering by the filter system 302. In some examples, the category of known malicious domains may not be unfiltered by the customer through the user interface presented by the tenant data system 304. However, as discussed, in some examples, the customer may specifically add a particular domain to the access permission list (and override any categorization). In some examples, when a particular number or percentage of customers add domains that appear in the known malicious domain category to the access permission list, the tenant data system 304 and / or the category information system 306 may cooperate to alert the threat intelligence system 110.In some examples, this enables the threat intelligence system 110 (either automatically or through its administrator) to re-investigate the site and determine whether to leave it on a list of known malicious domains in the threat intelligence system 110. In other examples, the DNS firewall system 108 may communicate other filtering information, such as log information indicating the frequency with which DNS requests are rejected (and information about the specific domains or categories for which DNS requests are being rejected), when a certain number or percentage of tenants add a domain to a deny list, to the threat intelligence system 110.

[0035] In some examples, the DNS firewall system 108 may also include a DNS server 308. For example, the DNS server 308 may operate as a DNS resolver that communicates with DNS root servers, top-level domain servers, and / or authoritative name servers (and associated caches or other devices) to resolve any DNS requests that are not removed by filtering by the filtering system 302. As an example, if a DNS request to resolve www.example.com is received by the DNS firewall system from the CPE 107 through the provider edge router 105, the filtering system 302 may extract the domain (example.com) from the DNS request and query the category information system 304 for all categories associated with example.com. The filtering system 302 may also query the tenant information system to determine (a) whether the IP address space of the source of the DNS request is currently associated with a tenant of the DNS firewall service; and (b) if associated, whether the tenant information indicates that the domain for any of the identified categories is subject to filtering for the identified tenant. If the filtering system 302 determines that the DNS request should not be filtered (rejected), it may pass the request through to the DNS server 308 so that a resolution to an IP address for the requested domain can be obtained. In other examples, the DNS firewall system 108 does not include a dedicated DNS server, and the filtering system 302 may pass any DNS requests that are not rejected through to a separate DNS server 111.

[0036] In addition, in some examples, CPE 107 may be configured to send DNS requests to DNS firewall system 108, but the customer may ultimately discontinue the DNS firewall service for a particular Internet line 103. In some examples, tenant data system 304 may communicate with configuration system 208 to automatically reconfigure CPE 107 to address sent DNS requests to an IP address not associated with DNS firewall system 108. However, in other examples, CPE 107 may not be automatically (or otherwise) reconfigured and may continue to send DNS requests to DNS firewall system 108. In some examples, filter system 302 may (a) receive a request; (b) determine that Internet line 103 is no longer associated with a tenant of the DNS firewall service; and (c) either reject the DNS request or forward the request to a different DNS server, such as DNS server 111. In some examples, filter system 302 may also notify the customer that the DNS request has been rejected and that CPE 107 needs to be reconfigured to address the DNS request elsewhere. In some examples, filter system 302 may forward such DNS requests to DNS server 111 only for a certain period following the end of the DNS firewall service for Internet line 103, after which such DNS requests may be dropped. In some examples, the notification to the customer may include the amount of remaining time before such DNS requests begin to be rejected if CPE 107 is not reconfigured to address the DNS requests to a different DNS server (such as DNS server 111).

[0037] An exemplary method 400 according to the present application is described with respect to FIG. 4. In an example, some or all of the operations of method 400 are performed by the provider configuration system 102. In operation 402, a user interface for ordering an Internet line and DNS firewall service is presented. For example, the ordering system 202 may cause a user interface to be displayed on the customer device 106. The user interface may include a web page (or a series of related web pages) that enables the customer to submit an order for a new Internet line 103 to connect the customer network 104 to the Internet 109. The user interface for ordering the Internet line 103 may also include an option (e.g., a checkbox, or other selectable user interface element) to select a DNS firewall service for the newly ordered Internet line 103. The user interface may also be published in the form of an API that enables automation when ordering services.

[0038] In operation 404, a request for provisioning an Internet line and providing a DNS firewall service is received. For example, the ordering system 202 may receive an indication through the user interface that the customer has submitted an order for the Internet line 103 and associated DNS firewall service. In an example, this may include receiving a selection of a selectable user interface element such as a "submit" button or the like.

[0039] In operation 406, IP address space is allocated to the Internet line. For example, the configuration system 208 may allocate IP address space to the Internet line 103 (e.g., allocate the first IP address of the allocated IP address space to the CPE 107 and the second IP address of the allocated IP address space to the provider edge router 105).

[0040] The flow proceeds to operation 408, where the Internet line is provisioned using the assigned IP address space. For example, the configuration system 208 may collaborate with the line information system 206 to determine the most advantageous way to provision a new Internet line 103. For example, the configuration system 208 may identify, in an example, one or more available ports on an existing provider edge router 105 for the new Internet line 103. In other examples, the configuration system 208 may determine that a new provider edge router 105 should be added to the network 101 (either at a new location or an existing location) to accommodate the new Internet line 103. The configuration system 208 may also initiate one or more workflows to have the new Internet line 103 designed or implemented by a technician. In an example, the configuration system 208 may cause the provider edge router 105 to be automatically configured, for example, to advertise the IP addresses of the assigned IP address space.

[0041] In an example, the configuration system 208 may also cause the CPE 107 to be automatically configured. For example, if the provider of the network 101 also provides the customer with the CPE 107 as part of an order for a new Internet line 103, the CPE 107 may be preconfigured to "call home" to the configuration system 208 to receive configuration information. The configuration information provided to the CPE 107 may include, for example, one or more IP addresses for the CPE 107 to advertise. The configuration information may also include one or more IP addresses for one or more provider edge routers 105 that the CPE 107 will use when routing traffic from the customer network 104 to the network 101.

[0042] In operation 410, tenant data is automatically stored in the DNS firewall system. For example, the provider configuration system 102 may automatically send a request to the DNS firewall system 108 to store the tenant data in the tenant data system 304. In the example, the tenant data may include some or all of the customer information received by the provider configuration system 102 in the order for the new Internet line 103, such as customer identification information, customer location, and customer contact information. The tenant data included in the request from the provider configuration system 102 may also include the IP address space assigned to the Internet line 103, the identification information of the CPE 107 (and / or the type of the device including the CPE 107), and other information.

[0043] In operation 412, the CPE is automatically programmed to send DNS requests addressed to the DNS firewall system. For example, the configuration system 208 may automatically configure the CPE107 to operate with the DNS firewall system 108. In particular, when the CPE107 "calls home" to receive configuration information, the CPE107 may be automatically configured by the configuration system 208. As a non-exclusive example, the configuration system 208 may automatically configure the CPE107 so that DNS requests are sent addressed from the customer device 106 to the DNS firewall system 108. For example, the CPE107 may be programmed to provide the DNS firewall system IP address configuration to individual customer devices 106 (e.g., using DHCP configuration settings), and then this customer device 106 will use the DNS firewall system 108 for DNS resolution. In some examples, the remote configuration of the CPE107 may be achieved by sending the configuration from the configuration system 208 to the CPE107 using an executable configuration script. The executable configuration script may be specific to the type of device (e.g., manufacturer, model, etc.) that includes the CPE107, and it may be operable to configure the CPE107 to apply the correct DNS firewall system IP address configuration to the customer device 106. In some examples, the configuration system 208 does not directly configure the CPE107 to send all DNS requests from the customer device 106 addressed to the DNS firewall system 108. Instead, an automatic process is initiated in the DNS firewall system 108 to communicate with the CPE107 and cause such a configuration to occur. In other examples, the CPE107 may not be managed by the provider of the network 101. Therefore, instead, the configuration system 208 may cause a notification to be sent to the customer along with instructions on how to configure the CPE107 to send all DNS requests from the customer device 106 addressed to the DNS firewall system 108.In some examples, CPE 107 may also be configured by configuration system 208 to permit such requests only when DNS requests from customer device 106 are sent addressed to DNS firewall system 108 for DNS resolution, thereby reducing the risk that some techniques used by a user or malicious actor of customer device 106 will avoid use of DNS firewall system 108 for DNS resolution.

[0044] In operation 414, DNS requests from the assigned IP address space are processed by the DNS firewall system. For example, configuration system 208 may communicate with DNS firewall system 108 to automatically configure the customer as a new tenant of the DNS firewall service and alert DNS firewall system 108 that DNS requests from the IP address space assigned to new Internet line 103 should be filtered using the DNS firewall service. In an example, if the customer is already a tenant of DNS firewall system 108, configuration system 208 may cause DNS firewall system 108 to associate the new Internet line with the existing tenant account for that customer in DNS firewall system 108. Then, DNS requests on Internet line 103 are processed by DNS firewall system 108 as contemplated, unless the customer no longer subscribes to the DNS firewall service for that Internet line.

[0045] An exemplary method 500 according to the present application is described with respect to FIG. 5. In an example, some or all of the operations of method 500 are performed by the DNS firewall system 108. The flow begins at operation 502, where a request is received from a provider configuration system to instantiate a DNS firewall service for an Internet line. For example, a request from the provider configuration system 102 to provide a DNS firewall service for DNS requests received from an IP address space assigned to the Internet line 103 may be received at the DNS firewall system 108.

[0046] The flow proceeds to operation 504, where customer information and the assigned IP address space are extracted from the request received at operation 502. The extracted customer information may include a customer name and location, and customer contact information. Other information extracted from the request may include the type of device with the CPE 107, and the IP address space assigned to the Internet line 103 for that customer and for which the DNS firewall service is subscribed. In some examples, when a new Internet line 103 is ordered along with a DNS firewall service for that line, the tenant data system 304 may receive a request from the provider configuration system 102. In an example, the tenant data system 304 automatically extracts customer information from the received request and automatically provisions the customer as a new tenant (if the customer is not already a tenant of the DNS firewall system 108).

[0047] In operation 506, tenant data including the assigned IP address space is automatically stored. For example, the customer information and other information extracted in operation 504 may be stored in the tenant data system 304 as tenant data. For example, the tenant data system 304 may store the IP address space in association with a newly created tenant (based on the customer information) or with previously stored tenant information (if the customer is already a tenant).

[0048] In operation 508, category information and tenant configuration data are received. For example, as discussed, the category information system 306 may receive information about known domains and one or more categories associated with such domains. Further, the tenant information system 304 may receive tenant configuration data that specifies whether a particular domain or category of domains for a tenant (or for a particular Internet line 103 of the tenant) is subject to filtering by the filtering system 302. As discussed, the tenant configuration data may include a default configuration set by the provider of the network 111, unless changed by the customer.

[0049] In operation 510, a DNS request is received. For example, the DNS firewall system 108 may receive DNS requests resulting from the use of a browser operating on the customer device 106 through the CPE 107 and the provider edge router 105. The DNS request may include a request to resolve a domain name (e.g., www.example.com) to a routable IP address for the desired web resource.

[0050] In operation 512, a determination is made as to whether there is a subscription currently applicable to the DNS firewall service with respect to the request. For example, the DNS firewall system 108 may extract information regarding the IP address space of the Internet line 103 that received the request from the request. If the IP address space of the Internet line 103 is determined not to be associated with the current tenant of the DNS firewall service (e.g., by querying the tenant data system 304), the flow proceeds to operation 514 with a "no", where the DNS request may be rejected or redirected and a notification to the customer may be provided. In some examples, in operation 514, the DNS request is simply dropped. In other examples, the DNS request may be redirected to a web page indicating that the DNS request cannot be completed and that the CPE 107 needs to be reconfigured to direct the DNS request to a different DNS server. In yet some other examples, in operation 514, the DNS request may be automatically redirected to a different DNS server 111, and a notification that the CPE 107 needs to be reconfigured to direct the DNS request to a different DNS server may be provided to the customer. In some examples, the redirect to the different DNS server 111 may be performed only for a certain period of time after the customer (or the customer's specific Internet line) has canceled the subscription to the DNS firewall service, and the notification to the customer may indicate the amount of time remaining in such a period before the DNS request is simply rejected.

[0051] In operation 512, if it is determined that the current subscription of the DNS firewall service is applied to the Internet line that received the DNS request, the flow proceeds to operation 516 with "Yes". In operation 516, it is determined whether the domain of the DNS request is permitted to be resolved for that Internet line. For example, the filter system 302 may query the category information system 306 to determine one or more categories (such as social media, video streaming, news, sports, etc.) associated with the domain. The filter system 302 may also query the tenant data system 304 to determine whether any of the categories associated with the domain are not prohibited for the tenant associated with the Internet line that received the DNS request. As discussed, in some examples, a tenant may define one set of category rules for application to the allow / deny decision for all Internet lines of that tenant, and in other examples, the rules may be specific to one or more particular Internet lines of that tenant. Additionally, in some examples, a tenant may also define an "access allowed list" of domains that are always permitted to be resolved on that Internet line regardless of category, and an "access denied list" of domains that are always prohibited to be resolved on that Internet line regardless of category.

[0052] In operation 516, if a determination is made that the domain is not permitted, the flow proceeds to operation 518 with "No", where the DNS request is rejected. In an example, rejecting a DNS request may include dropping the request (without resolving the domain within the request to an IP address) and returning (through CPE 107) to the customer device 106 a notification indicating that the domain the customer device 106 attempted to reach is not permitted according to the rules of the customer network 104. In other examples, rejecting a DNS request may include resolving the domain to the IP address of a landing site that displays such a notification rather than the IP address of the requested site. In the latter case, the IP address of the landing site is returned to the customer device 106 through CPE 107.

[0053] In operation 516, if a determination is made that the domain is permitted, the flow proceeds to operation 520 with "Yes", where the DNS request is resolved. For example, if the filter system 302 determines that the domain of the DNS request is permitted, it may forward the DNS request to the DNS server 308. The DNS server 308 may operate as a DNS resolver that communicates with DNS root servers, top-level domain servers, and / or authoritative name servers (and associated caches or other devices) to resolve any DNS request not removed by filtering by the filter system 302. In other examples, the DNS firewall system 108 does not include a dedicated DNS server, and the filter system 302 may pass any DNS request that has not been rejected to a separate DNS server 111. When the DNS server (e.g., DNS server 308 or DNS server 111) determines the IP address of the requested domain, it may be returned to the customer device 106 through CPE 107. Then, the flow returns to operation 510, where further DNS requests may be received, and operations 510 - 520 may be repeated as necessary.

[0054] In addition, in an example, the flow may proceed from any or all of operations 514, 518, and 520 to operation 522, where filtering information may be returned to the threat intelligence system. For example, a customer may specifically add a particular domain to the access allow list (and override any category determination). In some examples, when a particular number or percentage of customers add a domain that appears in a known malicious domain category to the access allow list, the tenant data system 304 and / or the category information system 306 may cooperate to alert the threat intelligence system 110. In some examples, as a result, the threat intelligence system 110 may (automatically or through its administrator) re-investigate the domain to determine whether it should remain in the known malicious domain list in the threat intelligence system 110. In other examples, the DNS firewall system 108 may communicate other filtering information, such as log information indicating the frequency of DNS requests being rejected (and information about the particular domain or category for which DNS requests are being rejected), to the threat intelligence system 110 when a particular number or percentage of tenants add a domain to the access deny list. In an example, an update by the DNS firewall system 108 to the threat intelligence system 110 may be performed after every DNS allow / deny decision, may be performed periodically based on a regular schedule, may be performed only when a certain threshold is met for the number of DNS requests or the number / percentage of such requests being rejected for a particular reason, or may be performed otherwise.

[0055] FIG. 6 is a block diagram showing the physical components (i.e., hardware) of a computing device 600 in which an example of the present disclosure may be implemented. The components of the computing device described below may be suitable for a client device that implants one or more of the provider configuration system 102, the DNS firewall system 108, or other components of FIGS. 1-3. In a basic configuration, the computing device 600 may include at least one processing unit 602 and a system memory 604. The processing unit (e.g., a processor) may be referred to as a processing system. Depending on the configuration and type of the computing device, the system memory 604 may comprise volatile storage (e.g., random access memory), non-volatile storage (e.g., read-only memory), flash memory, or any combination of such memories, but is not limited thereto. The system memory 604 may include an operating system 605 and one or more program modules 606 suitable for executing a software application 650 to implement one or more of the systems described above with respect to FIGS. 1-3.

[0056] The operating system 605 may be suitable for controlling, for example, the operation of the computing device 600. Further, aspects of the present invention may be implemented in conjunction with a graphics library, other operating systems, or any other application program and are not limited to any particular application or system. This basic configuration is shown in FIG. 6 by these components within the dashed line 608. The computing device 600 may have additional features or functionality. For example, the computing device 600 may also include additional data storage devices (removable and / or non-removable), such as, for example, magnetic disks, optical disks, or tapes. Such additional storage is shown in FIG. 6 by a removable storage device 609 and a non-removable storage device 610.

[0057] As described above, some program modules and data files may be stored in the system memory 604. While being executed on the processing unit 602, the program module 606 may perform a process including one or more of the operations of the methods shown in FIGS. 4 to 5, but not limited thereto. Other program modules that may be used in the examples of the present invention may include applications such as email and communication applications, word processing applications, spreadsheet applications, database applications, slide presentation applications, drawing or computer-aided application programs.

[0058] Furthermore, the examples of the present invention may be implemented in an electrical circuit including discrete electronic elements, a packaged or integrated electronic chip including logic gates, a circuit using a microprocessor, or a single chip including electronic elements or a microprocessor. For example, the examples of the present invention may be implemented via a system-on-chip (SOC) in which each or many of the components shown in FIG. 6 may be integrated into a single integrated circuit. Such an SOC device may include one or more processing units, a graphics unit, a communication unit, a system virtualization unit, and various application functions, all of which are integrated (or "burned") on a chip substrate as a single integrated circuit. When operating via the SOC, the functionality described herein with respect to the generation of the suggested queries may be operated via application-specific logic integrated with other components of the computing device 600 on a single integrated circuit (chip). The examples of the present disclosure may also be implemented using other techniques capable of performing logical operations such as AND, OR, and NOT, including but not limited to mechanical, optical, fluid, and quantum technologies.

[0059] Computing device 600 may also include one or more input devices 612, such as a keyboard, mouse, pen, voice input device, touch input device, etc. Output devices 614, such as a display, speaker, printer, etc. may also be included. The devices described above are examples, and other ones may be used. Computing device 600 may include one or more communication connections 616 that enable communication with other computing devices 618. Examples of suitable communication connections 616 include, but are not limited to, RF transmitter, receiver, and / or transceiver circuitry; Universal Serial Bus (USB), parallel and / or serial ports.

[0060] As used herein, the term computer-readable medium may include computer storage media. Computer storage media may include volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information such as computer-readable instructions, data structures, or program modules. System memory 604, removable storage device 609, and non-removable storage device 610 are all examples of computer storage media (i.e., memory storage). Computer storage media may include RAM, ROM, electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disk (DVD), or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage, or other magnetic storage devices, or any other manufactured article that can be used to store information and is accessible by computing device 600. Any such computer storage media may be part of computing device 600. Computer storage media may be non-transitory and tangible and does not include carrier waves or other propagated data signals.

[0061] A communication medium may be embodied by computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and includes any information delivery medium. The term "modulated data signal" may be described as a signal having one or more characteristics set or changed to encode information in the signal. By way of example and not limitation, a communication medium may include wired media such as a wired network or direct wired connection, and wireless media such as acoustic, radio frequency (RF), infrared, and other wireless media.

[0062] For example, aspects of the present invention have been described above with reference to block diagrams and / or operational diagrams of methods, systems, and computer programming products according to aspects of the present invention. The functions / operations noted in the blocks may be performed in a different order than that shown in any flowchart. For example, depending on the functionality / operation involved, two blocks shown in succession may in fact be executed substantially simultaneously, or the blocks may be executed in the reverse order in some cases. Further, as used in this specification and the claims, the phrase "at least one of element A, element B, or element C" is intended to convey any of element A, element B, element C, element A and B, element A and C, element B and C, and element A, B, and C.

[0063] The description and illustration of one or more aspects provided in this application are not intended to limit or restrict the scope of the claimed disclosure in any way. The aspects, examples, and details provided in this application are considered to be sufficient to convey ownership and enable others to make and use the best mode of the claimed disclosure. The claimed disclosure should not be considered limited to any aspect, example, or detail provided in this application. Various features (both structural and methodological), whether shown and described in combination or individually, are intended to be selectively rearranged, included, or removed to produce an embodiment having a particular set of features. Although the description and illustration of this application are provided, those skilled in the art can envision variations, modifications, and other aspects that fall within the spirit of the broader aspects of the overall inventive concept embodied in this application without departing from the broader scope of the claimed disclosure.

Claims

1. Receiving, in a network provider configuration system, a request from a customer to provision an Internet connection and a Domain Name System (DNS) firewall system for the Internet connection, where the request includes customer information; Allocating an Internet Protocol (IP) address space to the Internet connection; Using the customer information and the allocated IP address space to cause the Internet connection to be provisioned; Causing tenant data for the customer to be automatically stored in the DNS firewall system based on receiving the request to provision the DNS firewall system for the Internet connection, where the tenant data includes at least the allocated IP address space; and Causing DNS requests received from the allocated IP address space to be processed by the DNS firewall system A method comprising.

2. The DNS firewall system advertises at least a first IP address on the network, and the method further Causing customer premise equipment to be automatically programmed to send the DNS request addressed to the first IP address based on receiving the request to provision the DNS firewall system for the Internet connection The method according to claim 1, comprising.

3. The method according to claim 2, wherein the step of causing customer premise equipment to be automatically programmed to send the DNS request addressed to the first IP address includes remotely configuring the customer premise equipment.

4. The step of remotely configuring the customer facility equipment is performed in response to receiving a notification that the customer facility equipment is installed at the customer, according to the method of claim 3.

5. The step of providing programmatic access to the order system via the API by the provider configuration system, which publishes an application programming interface (API) to enable programmatic ordering of the Internet line, provides user information, and requests that the DNS firewall system be provisioned for the Internet line; or The step of causing a user interface to be presented by the provider configuration system, where the user interface provides options selectable by the user for the customer to order the Internet line, provide the user information, and request that the DNS firewall system be provisioned for the Internet line. The method of claim 1, further comprising at least one of the above.

6. The allocated IP address space includes at least a first IP address and a second IP address, and the method further comprises: Allocating the first IP address to an edge router and the second IP address to the customer facility equipment. The method of claim 2, comprising the above.

7. Receiving, at the DNS firewall system, a request from a network provider configuration system to instantiate a domain name system (DNS) firewall system for the Internet line, where the request includes customer information and an Internet protocol (IP) address space allocated to the Internet line; Automatically extracting the customer information and the allocated IP address space from the request; Automatically storing the tenant data for the customer in the DNS firewall system, where the tenant data includes at least the assigned IP address space; Receiving, by the DNS firewall system, a first DNS request from the assigned IP address space; and Processing, by the DNS firewall system, the first DNS request, where the processing step Determining that the first DNS request includes a first domain within a first category; Determining whether the first category is permitted for the customer; If the first category is permitted for the customer, causing the first DNS request to be resolved to a first IP address associated with the first domain; and If the first category is not permitted for the customer, causing the first DNS request to be rejected having, A method comprising. **Claim 8** The method according to claim 7, further comprising reporting filtering information by the DNS firewall system to a threat intelligence system. **Claim 9** The method according to claim 8, wherein the filtering information includes information regarding any domain that the customer includes in at least one of an access permission list or an access denial list. **Claim 10** The method according to claim 8, further comprising receiving, from the threat intelligence system, a list of known malicious domains, wherein the first category includes the list of known malicious domains, and the DNS firewall system automatically prohibits the first category from being permitted for the customer. **Claim 11** The DNS firewall system receives a second DNS request from the assigned IP address space and determines, based on the tenant data, whether the customer is currently subscribed to the DNS firewall system for the Internet line; If the customer is currently subscribed to the DNS firewall system for the Internet line, the DNS firewall system processes the second DNS request; and If the customer is not currently subscribed to the DNS firewall system for the Internet line, the second DNS request is discarded The method according to claim 8, further comprising.

12. The DNS firewall system receives a second DNS request from the assigned IP address space and determines, based on the tenant data, whether the customer is currently subscribed to the DNS firewall system for the Internet line; If the customer is currently subscribed to the DNS firewall system for the Internet line, the DNS firewall system processes the second DNS request; and If the customer is not currently subscribed to the DNS firewall system for the Internet line, the second DNS request is transferred to a separate DNS system The method according to claim 8, further comprising.

13. The separate DNS system is associated with a second IP address, and the method further comprises If the customer is not currently subscribed to the DNS firewall system for the Internet line, sending a notification to the customer instructing the customer to change the IP address in the customer premise equipment to the second IP address. The method according to claim 12.

14. If the customer is not currently subscribed to the DNS firewall system for the Internet line, and the second DNS request is received within a predetermined period after the customer was last subscribed to the DNS firewall system, transfer the second DNS request to a separate DNS system; otherwise, discard the second DNS request. The method according to claim 12, further comprising the step of:

15. A system, comprising: At least one processor; and A memory operably connected to the at least one processor and storing instructions for causing the system to execute a method when executed by the at least one processor. The method comprising: Receiving, in a network provider configuration system, a request from a customer for provisioning an Internet line and for provisioning a domain name system (DNS) firewall system for the Internet line, wherein the request includes customer information; Assigning an Internet protocol (IP) address space to the Internet line; Using the customer information and the assigned IP address space to cause the Internet line to be provisioned; Based on receiving the request for provisioning the DNS firewall system for the Internet line, causing tenant data for the customer to be automatically stored in the DNS firewall system, wherein the tenant data includes at least the assigned IP address space; and Causing DNS requests received from the assigned IP address space to be processed by the DNS firewall system. A system comprising the steps of:

16. The DNS firewall system advertises at least a first IP address on the network, and the method further automatically programming the customer premise equipment to send the DNS request addressed to the first IP address based on receiving the request for provisioning the DNS firewall system for the Internet connection The system according to claim 15, comprising:

17. The system according to claim 16, wherein the step of automatically programming the customer premise equipment to send the DNS request addressed to the first IP address includes remotely configuring the customer premise equipment.

18. The step of remotely configuring the customer premise equipment is performed in response to receiving a notification that the customer premise equipment is installed at the customer, and the step of remotely configuring the customer premise equipment includes: automatically sending an instruction for configuring the customer premise equipment; or automatically sending an executable script for configuring the customer premise equipment, where the executable script is specific to the customer premise equipment. The system according to claim 17, including at least one of the above.

19. The method further includes: The provider configuration system exposes an application programming interface (API), provides user information, and requests that the DNS firewall system be provisioned for the Internet connection to enable a programmatic order for the Internet connection, thereby providing programmatic access to an order system via the API; or Causing a user interface to be presented by the provider configuration system, where the user interface provides user-selectable options for the customer to order the Internet connection, provide the user information, and request that the DNS firewall system be provisioned for the Internet connection. The system according to any one of claims 15 to 18, further comprising at least one of the following. **Claim 20** The assigned IP address space includes at least a first IP address and a second IP address, and the method further comprises: Assigning the first IP address to an edge router and assigning the second IP address to the customer premise equipment. The system according to claim 16, comprising: