DNS Protection Agent for Leak-Free Request Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional DNS systems face issues with visibility, privacy, and security, exposing users and networks to potential malware, DNS exploits, and lack of control over DNS requests.

Innovation Solution

Implementing a locally-installed DNS protection agent that intercepts and routes all DNS requests through a trusted DNS protection server, using secure protocols like DoH and DoT, and maintains control by blocking unauthorized DNS queries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional DNS systems are used, then DNS resolution is simple and transparent, but network visibility and security are compromised

Engineering Contradiction:
Improvenetwork securityVSAvoidDNS resolution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a DNS protection agent as an intermediary component installed on client devices. This agent intercepts DNS requests before they reach external servers, routes them through a protected DNS resolution path, and monitors responses. The intermediary structure enables security monitoring and control while maintaining the simplicity of transparent DNS resolution for end users, as the agent operates transparently in the background without requiring user action or changing application behavior.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If DNS requests are made transparently by the operating system, then ease of operation is maintained, but privacy and visibility control are lost

Engineering Contradiction:
Improvetransparent DNS operationVSAvoidDNS request visibility
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The DNS protection agent operates autonomously by automatically intercepting DNS requests, resolving them through protected paths, and monitoring responses without requiring user intervention. The agent self-manages the DNS resolution process, maintaining transparent operation while simultaneously providing visibility control and privacy protection. The system serves itself by continuously monitoring and controlling DNS traffic without external intervention.

Inventive Principle:
Principle #25Self-service

3Reliability

If a DNS protection agent is installed to control DNS requests, then security and visibility are improved, but device complexity increases

Engineering Contradiction:
ImproveDNS securityVSAvoidDNS resolution architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple functions into a single DNS protection agent: DNS request interception, secure routing, response monitoring, and leak detection are combined in one component. This consolidation reduces the number of separate systems needed while maintaining comprehensive security control. The agent integrates with the operating system's existing DNS infrastructure, combining new security functionality with existing transparent resolution mechanisms to minimize architectural complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4165535B1System and method for leak prevention for domain name system requests
Publication Date: 2025.12.31 WEBROOT INCORPORATED
  • EP4165535B1 patent drawingFigure 1
  • EP4165535B1 patent drawingFigure 2
  • EP4165535B1 patent drawingFigure 3

AI summary

Embodiments of systems and methods for DNS leak prevention and protection are disclosed herein. In particular, certain embodiments include a local DNS protection agent installed on a system and an associated trusted external DNS protection server. The DNS protection agent prevents DNS leaks from applications on the system such that all DNS requests from the system are confined to requests from the DNS protection agent to the associated DNS protection server. As the DNS leak prevention provided by the DNS protection agent stops applications on the system from circumventing the DNS protection server, all DNS requests originating from the system remain under the control of the DNS protection server and thus desired DNS protection (e.g., as implemented on the DNS protection server) may be maintained. Certain embodiments prevent applications from using certain DNS security protocols, such as DoH and DoT, without going through the DNS protection agent.