DNS Traffic Baseline Learning for Accurate Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intrusion Detection Systems (IDS) face challenges in accurately distinguishing between regular and anomalous DNS traffic, leading to missed threats or false alarms, compromising network integrity and increasing vulnerability to cyber threats.

Innovation Solution

A system and method that receives DNS traffic data in real-time, compares it with historical data, generates alerts for servers outside a predefined learning period, and adds them to a baseline database for improved anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional IDS methods are used to monitor DNS traffic, then the system can detect potential threats, but the accuracy of distinguishing regular from anomalous DNS traffic is poor leading to false alarms and missed threats

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidnetwork security integrity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary learning during a baseline period to establish normal DNS traffic patterns before actual security monitoring begins. This preliminary action of learning and adapting to network-specific DNS behavior enables more accurate anomaly detection later, reducing both false positives and missed threats while maintaining reliable security monitoring

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously compares real-time DNS traffic against the established baseline and provides feedback by generating alerts for anomalous activity. This feedback mechanism allows the system to maintain high detection accuracy while ensuring network security integrity through continuous monitoring and alerting of deviations from normal behavior

Inventive Principle:
Principle #23Feedback

2Measurement precision

If the IDS adapts to patterns of each specific network to improve detection accuracy, then anomaly detection precision increases, but the system complexity increases making it difficult to adapt to diverse network configurations

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsystem adaptability complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary learning during a baseline period to establish normal DNS traffic patterns before actual security monitoring begins. This preliminary action of learning and adapting to network-specific DNS behavior enables more accurate anomaly detection later, reducing both false positives and missed threats while maintaining reliable security monitoring

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system captures key parameters and characteristics of DNS traffic during the baseline period, such as query types, response codes, timing patterns, and domain structures. By storing and comparing these specific parameters against the established baseline, the system achieves high detection accuracy across diverse network configurations without requiring complex adaptive algorithms for each network

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260006049A1System and method for detecting anomalies within a domain name system (DNS) traffic
Publication Date: 2026.01.01 HONEYWELL INTERNATIONAL INC
  • US20260006049A1 patent drawing
  • US20260006049A1 patent drawing
  • US20260006049A1 patent drawing

AI summary

A method and system for detecting anomalies within a domain name system (DNS) traffic is disclosed. Through the utilization of at least one processor, the method comprises receiving DNS traffic data from each of one or more DNS servers in real time, comparing the DNS traffic data with a data stored in a database. Furthermore, the method comprises determining a status of each of one or more DNS servers based on comparison. Further, the method comprises generating an alert for one or more users, based at least on the status. Furthermore, the method comprises determining whether each of one or more DNS servers outside a predefined learning period is queried by one or more DNS hosts. Thereafter, the method comprises adding each of one or more DNS servers to a baseline database upon determining that each of one or more DNS servers outside the predefined learning period is queried.