DNS Anomaly Detection via Fragment Count Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting malicious DNS activities are inefficient in identifying fleeting and evolving web-based security threats due to their reliance on traditional security measures that are costly and prone to false positives, making it difficult to detect malware operations effectively.

Innovation Solution

A system and method for detecting anomalies in DNS request streams by analyzing count values of DNS data fragments over a predetermined period, identifying trends that exceed a threshold value, and marking associated domain names, servers, or clients as potentially malicious, utilizing normalization and clustering techniques to reduce false positives and identify new types of malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (honeypots, infrastructure) are used to identify malicious activities, then detection capability is improved, but cost increases and false positives occur

Engineering Contradiction:
Improvedetection capabilityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces traditional mechanical security infrastructure (honeypots, physical security measures) with an automated DNS request analysis system that uses algorithms to detect malicious patterns in DNS traffic, thereby reducing infrastructure costs while maintaining detection capability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service detection by automatically analyzing DNS requests and identifying malicious activities without requiring human intervention or maintenance of complex security infrastructure, reducing operational costs

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional security measures are used to identify malicious activities, then detection capability is improved, but false positives increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent changes the detection parameters from traditional security indicators to DNS request pattern analysis, examining frequency, timing, and structural characteristics of DNS queries to distinguish malicious from legitimate traffic with higher precision and fewer false positives

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies local quality analysis by examining specific characteristics of individual DNS requests (such as query patterns, timing intervals, and domain structures) rather than relying on broad traditional security indicators, enabling more precise identification of malicious activities

Inventive Principle:
Principle #3Local quality

3Reliability

If continuous security measures are maintained to detect malicious activities, then detection capability is improved, but operational complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex manual security operations with automated DNS analysis algorithms that continuously monitor and analyze DNS traffic patterns, maintaining high detection capability while reducing operational complexity through automation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10587646B2Analyzing DNS requests for anomaly detection
Publication Date: 2020.03.10 AKAMAI TECHNOLOGIES INC
  • US10587646B2 patent drawing
  • US10587646B2 patent drawing
  • US10587646B2 patent drawing

AI summary

A computer-implemented method for detecting anomalies in DNS requests comprises receiving a plurality of DNS requests generated within a predetermined period. The predetermined period includes a plurality of DNS data fragments. The method further includes receiving a first DNS request and selecting a plurality of second DNS requests from the plurality of DNS requests such that each of the second DNS requests is a subset of the first DNS request. The method also includes calculating a count value for each of the DNS data fragments, where each of the count values represents a number of instances the second DNS requests appear within one of the DNS data fragments. In some embodiments, the count values for each of the DNS data fragments can be normalized. The method further includes determining an anomaly trend, for example, based on determining that at least one of the count values exceeds a predetermined threshold value.