Inline DNS Cache Poisoning Detection and Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The DNS protocol lacks effective security measures to prevent cache poisoning attacks, which can lead to significant disruptions and financial losses, and the implementation of DNSSEC introduces additional risks and costs that deter widespread adoption.
Innovation Solution
An inline detecting and blocking apparatus that collects, analyzes, and modifies DNS response packets to detect and block cache poisoning attacks, operating independently of DNSSEC, ensuring that poison data is not cached by recursive DNS servers without impacting legitimate traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DNSSEC is implemented to protect against cache poisoning attacks, then security is improved, but hardware requirements, operational costs, and service outages increase
Solution Approach 1:
The patent introduces an intermediary detection system that sits between DNS clients and DNS servers, analyzing DNS response packets for signs of cache poisoning attacks without requiring full DNSSEC implementation. This intermediary approach provides security protection while avoiding the hardware and operational overhead of DNSSEC.
Solution Approach 2:
The patent employs lightweight, software-based detection mechanisms that can be deployed quickly and removed easily, replacing the need for expensive, permanent DNSSEC infrastructure. The detection system uses simple packet analysis rules that require minimal computational resources.
2Reliability
If DNSSEC is implemented to protect against cache poisoning attacks, then security is improved, but operational costs increase
Solution Approach 1:
The detection system uses inexpensive software-based solutions rather than costly DNSSEC infrastructure, reducing operational expenses while maintaining security effectiveness.
Solution Approach 2:
The system performs self-validation of DNS responses through automated packet analysis, eliminating the need for expensive manual verification processes and reducing operational overhead.
3Reliability
If DNSSEC is implemented to protect against cache poisoning attacks, then security is improved, but service outages increase
Solution Approach 1:
The intermediary detection system operates independently of DNSSEC, providing security validation without the complexity and failure points inherent in DNSSEC implementation, thereby reducing service outages.
Solution Approach 2:
The system performs preliminary validation of DNS responses before they are cached, preventing poisoned data from entering the cache without requiring the complex DNSSEC validation process that causes outages.
4Device complexity
If traditional DNS protocol is used without additional security measures, then device complexity is reduced, but vulnerability to cache poisoning attacks increases
Solution Approach 1:
The detection system acts as an intermediary layer that adds security protection to the simple DNS protocol without requiring changes to the protocol itself or increasing device complexity.
Solution Approach 2:
The system uses lightweight detection rules that can be applied to traditional DNS traffic without adding significant complexity, providing security protection while maintaining protocol simplicity.
Data Source
AI summary
Concepts and technologies for detecting and blocking Domain Name System (“DNS”) cache poisoning attacks are provided. An inline detector and blocker apparatus implements a detection algorithm to monitor DNS response packets and detects a DNS cache poisoning attack utilizing the detection algorithm. The inline detector and blocker apparatus detects the DNS cache poisoning attack by receiving a DNS response packet and determining that the response packet includes poison data. The poison data may be included within an additional section of the response packet and/or an answer section of the response packet. As appropriate, the inline detector and blocker apparatus removes the additional section and/or the answer section of the response packet to effectively block the poison data from being cached by a DNS caching resolver.


