DNS Server DGA Domain Detection Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in efficiently identifying and mitigating Domain Generation Algorithm (DGA) domain names used by malware, as they require dedicated analysis systems that are costly and complex to implement, and often overwhelm network infrastructure, leading to increased bandwidth consumption and management complexity.

Innovation Solution

Integrating DGA domain identification and remediation capabilities directly into the DNS server, allowing it to determine whether a domain name is benign or potentially malicious, and respond accordingly, thereby preventing communication with Command and Control servers without the need for additional hardware or infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If dedicated analysis systems are used to identify DGA domain names, then detection capability is improved, but system complexity and cost increase

Engineering Contradiction:
ImproveDGA domain name detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines DGA domain name detection functionality with the existing DNS server infrastructure. The DNS server performs DGA analysis directly when resolving domain names, merging the detection function into the name resolution process itself rather than using a separate dedicated analysis system. This integration eliminates the need for additional hardware or complex standalone detection systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The DNS server is enhanced to perform multiple functions: traditional domain name resolution plus DGA domain name detection and mitigation. By making the DNS server multi-functional, the system avoids requiring separate dedicated analysis systems, thereby reducing overall system complexity while maintaining detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If dedicated analysis systems are deployed, then detection capability improves, but infrastructure cost increases

Engineering Contradiction:
ImproveDGA domain name detection capabilityVSAvoidimplementation cost
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The detection functionality is merged into the existing DNS server, eliminating the need to purchase, deploy, and maintain separate dedicated analysis systems. This integration significantly reduces infrastructure cost while preserving the ability to detect and mitigate DGA domain names effectively.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If network infrastructure is enhanced for DGA detection, then detection capability improves, but bandwidth consumption increases

Engineering Contradiction:
ImproveDGA domain name detection capabilityVSAvoidbandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The DNS server performs DGA analysis in advance during the domain name resolution process, before any actual data transmission occurs. By identifying potentially malicious domain names at the DNS query stage, the system can block communications proactively without requiring continuous monitoring or analysis of data traffic, thereby minimizing bandwidth consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system rapidly resolves and analyzes domain names during the DNS lookup process, making quick determinations about potential malware communications. This fast-track approach allows the system to identify and block malicious domains immediately without performing lengthy analysis that would consume additional bandwidth or time.

Inventive Principle:
Principle #21Skipping (Rushing through)

4Measurement precision

If dedicated analysis systems are implemented, then detection capability improves, but management complexity increases

Engineering Contradiction:
ImproveDGA domain name detection capabilityVSAvoidmanagement complexity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

By integrating DGA detection into the DNS server, the system eliminates the need to manage separate analysis infrastructure. The existing DNS server administration processes continue to apply, simplifying operational management while maintaining enhanced detection capability for malware-generated domain names.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10880319B2Determining potentially malware generated domain names
Publication Date: 2020.12.29 MICRO FOCUS LLC
  • US10880319B2 patent drawing
  • US10880319B2 patent drawing
  • US10880319B2 patent drawing

AI summary

In some examples, a Domain Name System (DNS) server is to receive, over a network, a DNS query containing a domain name, the DNS query sent by a device. The DNS server is to determine whether the domain name is potentially generated by malware. In response to determining that the domain name is potentially generated by malware, the DNS server is to generate a DNS response containing information indicating that the domain name is potentially generated by malware, and send the DNS response to the network.