DNS Anomaly Detection via Multi-Pass Outlier Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems face challenges in efficiently detecting anomalies and aberrant behavior in large volumes of DNS server queries due to high computational demands and difficulty in identifying subtle anomalies.

Innovation Solution

A method and system that identify dimensions and metrics for tracking, generate time series, detect outliers, and combine metrics to identify second outliers, using clipping levels and time series outlier detection algorithms to detect statistically significant outlier events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional systems process DNS queries using traditional analysis techniques, then complete query analysis is achieved, but computational time and resources become prohibitively high

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidquery processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the analysis process into multiple passes: first pass identifies obvious outliers using single metrics, second pass combines multiple metrics to identify subtle anomalies. This segmentation allows the system to quickly filter obvious cases while dedicating more computational resources to subtle anomalies, resolving the contradiction between detection accuracy and processing time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial analysis on all queries (first pass outlier detection) and excessive/detailed analysis only on suspicious cases (second pass with metric combinations). This selective depth of analysis maintains high detection accuracy while significantly reducing overall computational time and resources.

Inventive Principle:
Principle #16Partial or excessive action

2Productivity

If conventional systems use simple analysis techniques, then processing speed is maintained, but subtle anomalies become difficult to detect

Engineering Contradiction:
Improvequery processing throughputVSAvoidsubtle anomaly detection capability
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system dynamically adjusts analysis depth based on detected anomaly severity. Obvious outliers trigger standard investigation, while patterns suggesting subtle anomalies trigger enhanced multi-metric analysis. This dynamic approach maintains high throughput for normal queries while ensuring subtle anomalies receive the detailed analysis they require.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent transitions from single-dimension metric analysis to multi-dimension metric combination analysis when subtle anomalies are suspected. By adding dimensional complexity only when needed, the system maintains high processing speed for clear cases while achieving deep detection capability for subtle anomalies through dimensional expansion.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If comprehensive metric analysis is performed on all queries, then detection accuracy improves, but computational resources required increase significantly

Engineering Contradiction:
Improveanomaly detection reliabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary filtering using single-metric outlier detection before applying computationally intensive multi-metric combinations. This preliminary action identifies and resolves obvious cases early, preventing wasteful consumption of computational resources on queries that don't require advanced analysis, while maintaining detection reliability for cases that do.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The analysis system serves itself by using results from the first pass to determine which queries require second-pass analysis. Queries clearly identified as normal by the first pass automatically receive no further analysis, while suspicious queries self-select for enhanced scrutiny. This self-service mechanism optimizes resource allocation and maintains reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11190479B2Detection of aberrant domain registration and resolution patterns
Publication Date: 2021.11.30 VERISIGN INC
  • US11190479B2 patent drawing
  • US11190479B2 patent drawing
  • US11190479B2 patent drawing

AI summary

A method for detecting a predetermined behavior during a domain name registration or a domain resolution activity includes identifying one or more dimensions to be tracked. One or more metrics for each dimension is/are identified. A first time series for each of the metrics is generated. One or more first outliers in at least one of the first time series is detected. One or more sets of metrics is generated, each set including a combination of two or more of the metrics. A second time series for each of the metrics in the one or more sets of metrics is generated. One or more second outliers in at least one of the second time series is/are detected.