DNS-Based Access Control for Dynamic IP Data Communication Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for controlling instant messaging applications in networks, such as proxy servers and firewalls, are inadequate for Small Office Home Office (SOHO) networks and low-end user networks due to the dynamic IP addresses used by IM servers, which make it difficult to maintain IP address-based access control lists and prevent unauthorized data transfer.
Innovation Solution
A system that collects DNS names of data communication applications, identifies corresponding IP addresses, and uses a firewall to control access based on these IP addresses, thereby restricting unauthorized data transfers and maintaining network security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a proxy server is used to control IM applications, then security policy enforcement is improved, but device complexity and cost increase making it unsuitable for SOHO networks
Solution Approach 1:
The patent introduces a router as an intermediary device that integrates firewall functionality directly into the network infrastructure. Instead of requiring a separate proxy server, the router acts as the mediating component that monitors and controls IM application traffic by examining DNS queries and blocking communications to known IM server addresses, thereby providing security policy enforcement without additional complex devices
Solution Approach 2:
The patent makes the router multi-functional by combining its existing network routing capabilities with IM application control functionality. The router performs both traditional packet forwarding and security monitoring by integrating DNS query analysis and IP address blocking capabilities into a single device, eliminating the need for separate proxy servers and reducing overall system complexity
2Reliability
If a firewall with IP address-based ACL is used to control IM applications, then access control is improved, but the dynamic IP addresses of IM servers make it difficult to maintain effective control
Solution Approach 1:
The patent applies preliminary action by proactively blocking DNS queries to IM server domains before the dynamic IP addresses are resolved and used for communication. The firewall monitors DNS query packets, identifies queries targeting IM application domains, and blocks these queries in advance, preventing clients from obtaining current IP addresses of IM servers and thus maintaining effective access control despite IP address changes
Solution Approach 2:
The patent implements feedback by continuously monitoring DNS query traffic and dynamically adjusting blocking decisions based on real-time analysis of query destinations. The system maintains a database of known IM application domains and uses this information to dynamically block or allow DNS queries, creating a feedback loop that adapts to changing IM server addresses while maintaining consistent security policy enforcement
3Adaptability or versatility
If IM servers use multiple dynamic IP addresses and ports, then communication flexibility is improved, but network security control deteriorates as firewalls can be easily bypassed
Solution Approach 1:
The patent positions the router as an intermediary that inspects and controls all DNS query traffic between clients and IM servers. By monitoring the DNS layer rather than attempting to block specific IP addresses or ports, the system maintains security control while allowing IM servers to use dynamic addresses and multiple ports for communication. The router mediates between the client's DNS requests and the IM server infrastructure, providing security without restricting communication flexibility
Solution Approach 2:
The patent replaces the traditional mechanical approach of blocking specific IP addresses and ports with a DNS-based control mechanism. Instead of maintaining complex ACLs that track individual IP addresses and port combinations, the system substitutes a higher-level DNS query monitoring approach that blocks communications based on domain names, thereby maintaining security control while accommodating the dynamic nature of IM server addresses and ports
Data Source
AI summary
A method and apparatus for controlling access to data communication applications is disclosed. According to the method, the DNS names of the servers of the data communication applications are identified. The identified DNS names are used to determine the IP addresses of the servers. Furthermore, the identified IP addresses are used to control access to the data communication applications for the requests going to the servers of the data communication applications.


