DNS-Based Access Control for Dynamic IP Data Communication Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for controlling instant messaging applications in networks, such as proxy servers and firewalls, are inadequate for Small Office Home Office (SOHO) networks and low-end user networks due to the dynamic IP addresses used by IM servers, which make it difficult to maintain IP address-based access control lists and prevent unauthorized data transfer.

Innovation Solution

A system that collects DNS names of data communication applications, identifies corresponding IP addresses, and uses a firewall to control access based on these IP addresses, thereby restricting unauthorized data transfers and maintaining network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a proxy server is used to control IM applications, then security policy enforcement is improved, but device complexity and cost increase making it unsuitable for SOHO networks

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a router as an intermediary device that integrates firewall functionality directly into the network infrastructure. Instead of requiring a separate proxy server, the router acts as the mediating component that monitors and controls IM application traffic by examining DNS queries and blocking communications to known IM server addresses, thereby providing security policy enforcement without additional complex devices

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes the router multi-functional by combining its existing network routing capabilities with IM application control functionality. The router performs both traditional packet forwarding and security monitoring by integrating DNS query analysis and IP address blocking capabilities into a single device, eliminating the need for separate proxy servers and reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a firewall with IP address-based ACL is used to control IM applications, then access control is improved, but the dynamic IP addresses of IM servers make it difficult to maintain effective control

Engineering Contradiction:
Improveaccess controlVSAvoidadaptability to dynamic IP addresses
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by proactively blocking DNS queries to IM server domains before the dynamic IP addresses are resolved and used for communication. The firewall monitors DNS query packets, identifies queries targeting IM application domains, and blocks these queries in advance, preventing clients from obtaining current IP addresses of IM servers and thus maintaining effective access control despite IP address changes

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by continuously monitoring DNS query traffic and dynamically adjusting blocking decisions based on real-time analysis of query destinations. The system maintains a database of known IM application domains and uses this information to dynamically block or allow DNS queries, creating a feedback loop that adapts to changing IM server addresses while maintaining consistent security policy enforcement

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If IM servers use multiple dynamic IP addresses and ports, then communication flexibility is improved, but network security control deteriorates as firewalls can be easily bypassed

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidnetwork security control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent positions the router as an intermediary that inspects and controls all DNS query traffic between clients and IM servers. By monitoring the DNS layer rather than attempting to block specific IP addresses or ports, the system maintains security control while allowing IM servers to use dynamic addresses and multiple ports for communication. The router mediates between the client's DNS requests and the IM server infrastructure, providing security without restricting communication flexibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical approach of blocking specific IP addresses and ports with a DNS-based control mechanism. Instead of maintaining complex ACLs that track individual IP addresses and port combinations, the system substitutes a higher-level DNS query monitoring approach that blocks communications based on domain names, thereby maintaining security control while accommodating the dynamic nature of IM server addresses and ports

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS7673336B2Method and system for controlling access to data communication applications
Publication Date: 2010.03.02 CISCO TECHNOLOGY INC
  • US7673336B2 patent drawing
  • US7673336B2 patent drawing
  • US7673336B2 patent drawing

AI summary

A method and apparatus for controlling access to data communication applications is disclosed. According to the method, the DNS names of the servers of the data communication applications are identified. The identified DNS names are used to determine the IP addresses of the servers. Furthermore, the identified IP addresses are used to control access to the data communication applications for the requests going to the servers of the data communication applications.