DNS Anomaly Detection via Fragment Count Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting malicious DNS activities are inefficient in identifying fleeting and evolving web-based security threats due to their reliance on traditional security measures that are costly and prone to false positives, making it difficult to detect malware operations effectively.
Innovation Solution
A system and method for detecting anomalies in DNS request streams by analyzing count values of DNS data fragments over a predetermined period, identifying trends that exceed a threshold value, and marking associated domain names, servers, or clients as potentially malicious, utilizing normalization and clustering techniques to reduce false positives and identify new types of malicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security measures (honeypots, infrastructure) are used to identify malicious activities, then detection capability is improved, but cost increases and false positives occur
Solution Approach 1:
The patent replaces traditional mechanical security infrastructure (honeypots, physical security measures) with an automated DNS request analysis system that uses algorithms to detect malicious patterns in DNS traffic, thereby reducing infrastructure costs while maintaining detection capability
Solution Approach 2:
The system enables self-service detection by automatically analyzing DNS requests and identifying malicious activities without requiring human intervention or maintenance of complex security infrastructure, reducing operational costs
2Reliability
If traditional security measures are used to identify malicious activities, then detection capability is improved, but false positives increase
Solution Approach 1:
The patent changes the detection parameters from traditional security indicators to DNS request pattern analysis, examining frequency, timing, and structural characteristics of DNS queries to distinguish malicious from legitimate traffic with higher precision and fewer false positives
Solution Approach 2:
The system applies local quality analysis by examining specific characteristics of individual DNS requests (such as query patterns, timing intervals, and domain structures) rather than relying on broad traditional security indicators, enabling more precise identification of malicious activities
3Reliability
If continuous security measures are maintained to detect malicious activities, then detection capability is improved, but operational complexity increases
Solution Approach 1:
The patent replaces complex manual security operations with automated DNS analysis algorithms that continuously monitor and analyze DNS traffic patterns, maintaining high detection capability while reducing operational complexity through automation
Data Source
AI summary
A computer-implemented method for detecting anomalies in DNS requests comprises receiving a plurality of DNS requests generated within a predetermined period. The predetermined period includes a plurality of DNS data fragments. The method further includes receiving a first DNS request and selecting a plurality of second DNS requests from the plurality of DNS requests such that each of the second DNS requests is a subset of the first DNS request. The method also includes calculating a count value for each of the DNS data fragments, where each of the count values represents a number of instances the second DNS requests appear within one of the DNS data fragments. In some embodiments, the count values for each of the DNS data fragments can be normalized. The method further includes determining an anomaly trend, for example, based on determining that at least one of the count values exceeds a predetermined threshold value.


