DNS-Based Network Endpoint Interaction Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional approaches to network planning focus on bandwidth and infrastructure, failing to provide insights into network complexity and tools for monitoring connections between network endpoints, especially in enterprise environments with BYOD and complex IT infrastructures.
Innovation Solution
A system and process for monitoring and analysis of interactions between network endpoints, involving the collection of DNS response data, analysis, and generation of graphs to visualize interactions, using software-defined networking (SDN) devices and a telemetry platform to provide insights into network complexity and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If traditional network monitoring tools are used to monitor bandwidth and infrastructure, then network management functions are provided, but insights into network complexity and endpoint interactions are not obtained
Solution Approach 1:
The patent introduces DNS response data as an intermediary that indirectly reveals endpoint interactions and network complexity. Instead of directly monitoring all network traffic between endpoints, the system uses DNS query responses as a mediator to infer connection patterns, thereby obtaining network complexity insights without deploying complex monitoring infrastructure throughout the network
Solution Approach 2:
The patent replaces traditional mechanical network monitoring approaches (direct traffic inspection, endpoint agents, network taps) with an information-based approach using DNS response analysis. By substituting direct observation mechanisms with indirect inference from DNS data, the system reduces the mechanical complexity of monitoring while still capturing essential interaction patterns
2Measurement precision
If comprehensive network monitoring is implemented to track all endpoint interactions, then detailed network complexity insights are obtained, but system complexity and resource requirements increase
Solution Approach 1:
The patent extracts only the necessary information (endpoint interaction patterns) from DNS response data, rather than monitoring and analyzing all network traffic. By taking out only the relevant DNS query and response pairs that indicate endpoint connections, the system achieves precise interaction analysis without the complexity of comprehensive network monitoring infrastructure
Solution Approach 2:
The patent makes the DNS system multi-functional by having it serve both its traditional purpose of domain name resolution and an additional function of providing network complexity measurement data. This universal approach allows the same DNS infrastructure to fulfill multiple roles, reducing the need for separate dedicated monitoring systems
3Reliability
If network monitoring focuses on bandwidth and infrastructure metrics, then traditional network management is maintained, but security issues and anomalies are not detected
Solution Approach 1:
The patent implements feedback by analyzing DNS response patterns to detect anomalies and security issues. The system continuously monitors endpoint interaction data and provides feedback about unusual connection patterns, potential security threats, and network complexity changes, enabling proactive security management while maintaining ease of network planning through automated analysis
Data Source
AI summary
Techniques for monitoring and analysis of interactions between network endpoints are disclosed. In some embodiments, a process for monitoring and analysis of interactions between network endpoints includes collecting Domain Name System (DNS) response data from a network device; determining network endpoint interactions based on an analysis of the DNS response data (e.g., using a processor); and generating a graph corresponding to the network endpoint interactions. For example, the network device can include a DNS device and/or a software-defined networking (SDN) device (e.g., an SDN switch, such as an OpenFlow switch).


