Inline DNS Cache Poisoning Detection and Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The DNS protocol lacks effective security measures to prevent cache poisoning attacks, which can lead to significant disruptions and financial losses, and the implementation of DNSSEC introduces additional risks and costs that deter widespread adoption.

Innovation Solution

An inline detecting and blocking apparatus that collects, analyzes, and modifies DNS response packets to detect and block cache poisoning attacks, operating independently of DNSSEC, ensuring that poison data is not cached by recursive DNS servers without impacting legitimate traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DNSSEC is implemented to protect against cache poisoning attacks, then security is improved, but hardware requirements, operational costs, and service outages increase

Engineering Contradiction:
ImprovesecurityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary detection system that sits between DNS clients and DNS servers, analyzing DNS response packets for signs of cache poisoning attacks without requiring full DNSSEC implementation. This intermediary approach provides security protection while avoiding the hardware and operational overhead of DNSSEC.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent employs lightweight, software-based detection mechanisms that can be deployed quickly and removed easily, replacing the need for expensive, permanent DNSSEC infrastructure. The detection system uses simple packet analysis rules that require minimal computational resources.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If DNSSEC is implemented to protect against cache poisoning attacks, then security is improved, but operational costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidoperational costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The detection system uses inexpensive software-based solutions rather than costly DNSSEC infrastructure, reducing operational expenses while maintaining security effectiveness.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system performs self-validation of DNS responses through automated packet analysis, eliminating the need for expensive manual verification processes and reducing operational overhead.

Inventive Principle:
Principle #25Self-service

3Reliability

If DNSSEC is implemented to protect against cache poisoning attacks, then security is improved, but service outages increase

Engineering Contradiction:
ImprovesecurityVSAvoidservice outages
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The intermediary detection system operates independently of DNSSEC, providing security validation without the complexity and failure points inherent in DNSSEC implementation, thereby reducing service outages.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation of DNS responses before they are cached, preventing poisoned data from entering the cache without requiring the complex DNSSEC validation process that causes outages.

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If traditional DNS protocol is used without additional security measures, then device complexity is reduced, but vulnerability to cache poisoning attacks increases

Engineering Contradiction:
Improveprotocol simplicityVSAvoidvulnerability to attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The detection system acts as an intermediary layer that adds security protection to the simple DNS protocol without requiring changes to the protocol itself or increasing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses lightweight detection rules that can be applied to traditional DNS traffic without adding significant complexity, providing security protection while maintaining protocol simplicity.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8910280B2Detecting and blocking domain name system cache poisoning attacks
Publication Date: 2014.12.09 AT&T INTELLECTUAL PROPERTY I L P
  • US8910280B2 patent drawing
  • US8910280B2 patent drawing
  • US8910280B2 patent drawing

AI summary

Concepts and technologies for detecting and blocking Domain Name System (“DNS”) cache poisoning attacks are provided. An inline detector and blocker apparatus implements a detection algorithm to monitor DNS response packets and detects a DNS cache poisoning attack utilizing the detection algorithm. The inline detector and blocker apparatus detects the DNS cache poisoning attack by receiving a DNS response packet and determining that the response packet includes poison data. The poison data may be included within an additional section of the response packet and/or an answer section of the response packet. As appropriate, the inline detector and blocker apparatus removes the additional section and/or the answer section of the response packet to effectively block the poison data from being cached by a DNS caching resolver.