DNS Protection Agent for Leak Prevention and Tunneling Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional DNS systems face issues with visibility, privacy, and security, including exposure of user activities, potential malware detection, and vulnerabilities to attacks like DNS tunneling, which compromise network security and privacy.

Innovation Solution

Implementing a locally-installed DNS protection agent that intercepts and routes all DNS requests through a trusted DNS protection server, using secure protocols like DoH and DoT, and maintains control by blocking unauthorized communications and detecting potential DNS tunneling attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional DNS systems are used, then DNS resolution is transparent and automatic, but visibility of DNS requests is lost and users are exposed to malicious domains

Engineering Contradiction:
ImproveDNS securityVSAvoidDNS request visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a DNS protection agent as an intermediary component installed on client devices. This agent intercepts DNS requests before they reach external servers, allowing the system to maintain visibility of DNS traffic while protecting users from malicious domains. The agent acts as a mediator between applications and external DNS servers, enabling monitoring and security control without breaking DNS functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If DNS requests are routed through a protection agent, then visibility and control are maintained, but device complexity increases

Engineering Contradiction:
ImproveDNS request visibilityVSAvoidDNS protection agent
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The DNS protection agent is designed to perform multiple functions within a single component: intercepting DNS requests, monitoring DNS traffic, detecting tunneling attacks, and routing requests through secure channels. By consolidating these functions into one agent rather than separate systems, the patent reduces overall system complexity while maintaining comprehensive visibility and control capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If DNS tunneling protection is implemented, then security against malicious activities is improved, but detection capability requirements increase

Engineering Contradiction:
ImproveDNS tunneling protectionVSAvoidDNS tunneling detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where the DNS protection agent continuously monitors DNS request patterns and compares them against baseline behavior. When anomalies such as encoded commands or unusual query patterns indicative of tunneling are detected, the system provides feedback to trigger security responses. This feedback loop enables effective tunneling detection without requiring complex analysis systems.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12489735B2System and method for DNS tunneling protection
Publication Date: 2025.12.02 OPEN TEXT CORPORATION
  • US12489735B2 patent drawing
  • US12489735B2 patent drawing
  • US12489735B2 patent drawing

AI summary

Embodiments of systems and methods for DNS leak prevention and protection, including protection against DNS tunneling attacks, are disclosed herein. In particular, certain embodiments include a local DNS protection agent installed on a system and an associated trusted external DNS protection server. The DNS protection agent prevents DNS leaks from applications on the system such that all DNS requests from the system are confined to requests from the DNS protection agent to the associated DNS protection server. As the DNS leak prevention provided by the DNS protection agent stops applications on the system from circumventing the DNS protection server, all DNS requests originating from the system remain under the control of the DNS protection server and thus desired DNS protection (e.g., as implemented on the DNS protection server) may be maintained. Certain embodiments prevent applications from using certain DNS security protocols, such as DoH and DoT, without going through the DNS protection agent. Embodiments are also capable of detecting and addressing DNS tunneling attacks.