DNS Anomaly Detection via Multi-Pass Outlier Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems face challenges in efficiently detecting anomalies and aberrant behavior in large volumes of DNS server queries due to high computational demands and difficulty in identifying subtle anomalies.
Innovation Solution
A method and system that identify dimensions and metrics for tracking, generate time series, detect outliers, and combine metrics to identify second outliers, using clipping levels and time series outlier detection algorithms to detect statistically significant outlier events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional systems process DNS queries using traditional analysis techniques, then complete query analysis is achieved, but computational time and resources become prohibitively high
Solution Approach 1:
The patent segments the analysis process into multiple passes: first pass identifies obvious outliers using single metrics, second pass combines multiple metrics to identify subtle anomalies. This segmentation allows the system to quickly filter obvious cases while dedicating more computational resources to subtle anomalies, resolving the contradiction between detection accuracy and processing time.
Solution Approach 2:
The system performs partial analysis on all queries (first pass outlier detection) and excessive/detailed analysis only on suspicious cases (second pass with metric combinations). This selective depth of analysis maintains high detection accuracy while significantly reducing overall computational time and resources.
2Productivity
If conventional systems use simple analysis techniques, then processing speed is maintained, but subtle anomalies become difficult to detect
Solution Approach 1:
The system dynamically adjusts analysis depth based on detected anomaly severity. Obvious outliers trigger standard investigation, while patterns suggesting subtle anomalies trigger enhanced multi-metric analysis. This dynamic approach maintains high throughput for normal queries while ensuring subtle anomalies receive the detailed analysis they require.
Solution Approach 2:
The patent transitions from single-dimension metric analysis to multi-dimension metric combination analysis when subtle anomalies are suspected. By adding dimensional complexity only when needed, the system maintains high processing speed for clear cases while achieving deep detection capability for subtle anomalies through dimensional expansion.
3Reliability
If comprehensive metric analysis is performed on all queries, then detection accuracy improves, but computational resources required increase significantly
Solution Approach 1:
The system performs preliminary filtering using single-metric outlier detection before applying computationally intensive multi-metric combinations. This preliminary action identifies and resolves obvious cases early, preventing wasteful consumption of computational resources on queries that don't require advanced analysis, while maintaining detection reliability for cases that do.
Solution Approach 2:
The analysis system serves itself by using results from the first pass to determine which queries require second-pass analysis. Queries clearly identified as normal by the first pass automatically receive no further analysis, while suspicious queries self-select for enhanced scrutiny. This self-service mechanism optimizes resource allocation and maintains reliability.
Data Source
AI summary
A method for detecting a predetermined behavior during a domain name registration or a domain resolution activity includes identifying one or more dimensions to be tracked. One or more metrics for each dimension is/are identified. A first time series for each of the metrics is generated. One or more first outliers in at least one of the first time series is detected. One or more sets of metrics is generated, each set including a combination of two or more of the metrics. A second time series for each of the metrics in the one or more sets of metrics is generated. One or more second outliers in at least one of the second time series is/are detected.


