DNS Server Defense Engine for DDoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in effectively defending against DNS-based attacks, such as DDoS and data exfiltration, due to the high costs and resource consumption of dedicated analysis systems, and the time-consuming remediation processes, which allow malicious activities to continue for extended periods.

Innovation Solution

A DNS server with a built-in DNS-based attack defense engine that monitors DNS queries for common domain names and cache misses, triggering countermeasures such as rate limiting and re-imaging infected devices, and utilizes Bloom filters to detect and prevent malicious DNS queries, thereby addressing threats like DDoS and data exfiltration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated analysis system is used to detect DNS-based attacks, then detection capability is improved, but system cost and resource consumption increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the attack detection functionality into the existing DNS server by integrating a defense engine that monitors DNS queries, analyzes patterns, and detects malicious activities directly within the DNS server infrastructure, eliminating the need for separate dedicated analysis systems

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The DNS server is enhanced to perform multiple functions simultaneously: it continues to resolve domain names while also monitoring DNS queries, analyzing traffic patterns, detecting attacks, and executing countermeasures, making the DNS server a multi-functional security component

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a dedicated analysis system is deployed to monitor DNS queries, then attack detection is improved, but network resource consumption increases

Engineering Contradiction:
Improveattack detectionVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The DNS server performs self-monitoring and self-protection by incorporating a defense engine that autonomously analyzes its own DNS queries, detects malicious patterns, and executes countermeasures without requiring external analysis systems or additional network resources

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional remediation processes are used to address detected threats, then security response is improved, but response time increases allowing malicious activities to continue

Engineering Contradiction:
Improvesecurity responseVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The defense engine continuously monitors DNS queries and pre-identifies malicious patterns and threats before they can cause significant damage, allowing the system to execute countermeasures proactively rather than reactively, thereby reducing the time malicious activities can continue

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements real-time feedback loops where the defense engine continuously analyzes DNS query results, detects anomalies, triggers countermeasures, and monitors the effectiveness of those countermeasures, enabling rapid iterative response to threats

Inventive Principle:
Principle #23Feedback

4Measurement precision

If comprehensive DNS query analysis is performed to detect malicious activities, then detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The defense engine applies partial analysis by focusing monitoring efforts on specific indicators of malicious activity such as high-frequency queries, unusual domain patterns, and cache miss ratios, rather than analyzing every DNS query in exhaustive detail, thereby maintaining detection accuracy while reducing processing overhead

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11271963B2Defending against domain name system based attacks
Publication Date: 2022.03.08 MICRO FOCUS LLC
  • US11271963B2 patent drawing
  • US11271963B2 patent drawing
  • US11271963B2 patent drawing

AI summary

In some examples, a Domain Name System (DNS) server receives, over a network, DNS queries containing domain names, extracts a common domain name shared by the domain names, determines whether a measure of an amount of data relating to the DNS queries containing the common domain name exceeds a threshold, and in response to determining that the measure of the amount of data relating to the DNS queries containing the common domain name exceeds the threshold, trigger a countermeasure action to address a threat associated with the DNS queries.