DNS Contextual Flows for Encrypted Session Malicious Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face challenges in detecting malicious traffic, particularly in encrypted sessions, as they lack clear-text content for analysis, making it difficult to differentiate between benign and malicious traffic.

Innovation Solution

A network device captures DNS response data and session data for encrypted sessions, using machine learning or rule-based classifiers to determine malicious activity, allowing for mediation actions to be taken based on the analysis of DNS contextual flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network security systems analyze clear-text content for malicious traffic detection, then detection accuracy is improved, but encrypted traffic cannot be analyzed

Engineering Contradiction:
Improvemalicious traffic detection accuracyVSAvoidencrypted traffic analysis capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent introduces DNS response data as an intermediary element that bridges the gap between encrypted traffic analysis and malicious content detection. By capturing and analyzing DNS responses associated with encrypted sessions, the system can identify malicious patterns without decrypting the actual traffic, thus maintaining both detection accuracy and encrypted traffic compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent shifts the analysis from the traditional content dimension to a contextual dimension by incorporating DNS response data. This dimensional change allows the system to analyze encrypted traffic through associated DNS information, enabling malicious traffic detection without compromising encryption

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If traditional flow monitoring systems are used, then system complexity is maintained, but detection capability for encrypted malicious traffic is insufficient

Engineering Contradiction:
Improvesystem complexityVSAvoidencrypted malicious traffic detection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements preliminary action by capturing DNS response data before analyzing encrypted sessions. This pre-capture of contextual information enables the system to establish baseline patterns and associations in advance, improving detection reliability without significantly increasing system complexity during the actual monitoring phase

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11785041B2Identifying and using DNS contextual flows
Publication Date: 2023.10.10 CISCO TECHNOLOGY INC
  • US11785041B2 patent drawing
  • US11785041B2 patent drawing
  • US11785041B2 patent drawing

AI summary

In one embodiment, a device in a network captures domain name system (DNS) response data from a DNS response sent by a DNS service to a client in the network. The device captures session data for an encrypted session of the client. The device makes a determination that the encrypted session is malicious by using the captured DNS response data and the captured session data as input to a machine learning-based or rule-based classifier. The device performs a mediation action in response to the determination that the encrypted session is malicious.