DNS Contextual Flows for Encrypted Session Malicious Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face challenges in detecting malicious traffic, particularly in encrypted sessions, as they lack clear-text content for analysis, making it difficult to differentiate between benign and malicious traffic.
Innovation Solution
A network device captures DNS response data and session data for encrypted sessions, using machine learning or rule-based classifiers to determine malicious activity, allowing for mediation actions to be taken based on the analysis of DNS contextual flows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network security systems analyze clear-text content for malicious traffic detection, then detection accuracy is improved, but encrypted traffic cannot be analyzed
Solution Approach 1:
The patent introduces DNS response data as an intermediary element that bridges the gap between encrypted traffic analysis and malicious content detection. By capturing and analyzing DNS responses associated with encrypted sessions, the system can identify malicious patterns without decrypting the actual traffic, thus maintaining both detection accuracy and encrypted traffic compatibility
Solution Approach 2:
The patent shifts the analysis from the traditional content dimension to a contextual dimension by incorporating DNS response data. This dimensional change allows the system to analyze encrypted traffic through associated DNS information, enabling malicious traffic detection without compromising encryption
2Device complexity
If traditional flow monitoring systems are used, then system complexity is maintained, but detection capability for encrypted malicious traffic is insufficient
Solution Approach 1:
The patent implements preliminary action by capturing DNS response data before analyzing encrypted sessions. This pre-capture of contextual information enables the system to establish baseline patterns and associations in advance, improving detection reliability without significantly increasing system complexity during the actual monitoring phase
Data Source
AI summary
In one embodiment, a device in a network captures domain name system (DNS) response data from a DNS response sent by a DNS service to a client in the network. The device captures session data for an encrypted session of the client. The device makes a determination that the encrypted session is malicious by using the captured DNS response data and the captured session data as input to a machine learning-based or rule-based classifier. The device performs a mediation action in response to the determination that the encrypted session is malicious.


