DNS Cache Bypass for Denial of Service Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Denial of Service (DOS) attacks on DNS servers disrupt the translation of domain names to IP addresses, impacting users' ability to access websites, as existing solutions focus on enabling alternate connections only after a DNS server becomes unresponsive or fails to provide data, rather than anticipating potential issues.

Innovation Solution

A method and computer program product that cache IP addresses of destinations, monitor connection times, and provide selectable cached addresses in a user interface when a DNS server connection is incomplete, allowing users to bypass the DNS server during a suspected DOS attack, thereby maintaining connectivity and anticipating network issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DNS servers are used to translate domain names to IP addresses, then users can access websites through domain names, but DOS attacks can overwhelm the DNS servers and disrupt this translation service

Engineering Contradiction:
ImproveDNS service availabilityVSAvoidDOS attack impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by proactively monitoring DNS response times and detecting potential DOS attacks before they completely disrupt service. The system establishes baseline performance metrics and continuously compares actual performance against these baselines, enabling early detection and switching to alternative DNS servers before complete failure occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies parameter changes by dynamically adjusting DNS server selection based on monitored performance parameters. When response time exceeds thresholds or anomaly detection indicates a DOS attack, the system changes the operational parameter of which DNS server is being used, switching from the primary server to alternative servers to maintain service availability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the system monitors and detects DOS attacks proactively, then service continuity can be maintained, but this requires additional monitoring infrastructure and processing

Engineering Contradiction:
Improveservice continuityVSAvoidmonitoring infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a monitoring system that performs multiple functions: it not only detects DOS attacks but also measures baseline performance metrics, compares actual performance against baselines, and automatically selects alternative DNS servers. This multi-functional approach consolidates what could be separate complex systems into a unified solution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies self-service by enabling the system to automatically detect DOS attacks, select alternative DNS servers, and maintain service continuity without requiring manual intervention or complex external monitoring infrastructure. The system uses its own operational data to make decisions about service maintenance.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11418539B2Denial of service attack mitigation through direct address connection
Publication Date: 2022.08.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11418539B2 patent drawing
  • US11418539B2 patent drawing
  • US11418539B2 patent drawing

AI summary

A method, computer program product, and a system where a processor(s) determines that a destination has been retained as a link in an application. The processor(s) monitors connections of the application to the destination retained as the link, where connecting is providing a locator of the destination to a server(s) to obtain an address for the destination. The processor(s) determines an average time period measured from providing the locator to the server(s) to obtaining the address. The processor(s) retains the returned address for each connection within a given time period. The processor(s) determines that the application has initiated a new connection to the destination and the new connection is incomplete after a time period calculated relative to the average time period has lapsed. The processor(s) provides selectable options in a user interface of the application that are the retained address(es).