DNS-Based Network Endpoint Interaction Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional approaches to network planning focus on bandwidth and infrastructure, failing to provide insights into network complexity and tools for monitoring connections between network endpoints, especially in enterprise environments with BYOD and complex IT infrastructures.

Innovation Solution

A system and process for monitoring and analysis of interactions between network endpoints, involving the collection of DNS response data, analysis, and generation of graphs to visualize interactions, using software-defined networking (SDN) devices and a telemetry platform to provide insights into network complexity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional network monitoring tools are used to monitor bandwidth and infrastructure, then network management functions are provided, but insights into network complexity and endpoint interactions are not obtained

Engineering Contradiction:
Improvenetwork complexity insightsVSAvoidmonitoring system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces DNS response data as an intermediary that indirectly reveals endpoint interactions and network complexity. Instead of directly monitoring all network traffic between endpoints, the system uses DNS query responses as a mediator to infer connection patterns, thereby obtaining network complexity insights without deploying complex monitoring infrastructure throughout the network

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical network monitoring approaches (direct traffic inspection, endpoint agents, network taps) with an information-based approach using DNS response analysis. By substituting direct observation mechanisms with indirect inference from DNS data, the system reduces the mechanical complexity of monitoring while still capturing essential interaction patterns

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If comprehensive network monitoring is implemented to track all endpoint interactions, then detailed network complexity insights are obtained, but system complexity and resource requirements increase

Engineering Contradiction:
Improveendpoint interaction analysisVSAvoidmonitoring infrastructure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the necessary information (endpoint interaction patterns) from DNS response data, rather than monitoring and analyzing all network traffic. By taking out only the relevant DNS query and response pairs that indicate endpoint connections, the system achieves precise interaction analysis without the complexity of comprehensive network monitoring infrastructure

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent makes the DNS system multi-functional by having it serve both its traditional purpose of domain name resolution and an additional function of providing network complexity measurement data. This universal approach allows the same DNS infrastructure to fulfill multiple roles, reducing the need for separate dedicated monitoring systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If network monitoring focuses on bandwidth and infrastructure metrics, then traditional network management is maintained, but security issues and anomalies are not detected

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork planning
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements feedback by analyzing DNS response patterns to detect anomalies and security issues. The system continuously monitors endpoint interaction data and provides feedback about unusual connection patterns, potential security threats, and network complexity changes, enabling proactive security management while maintaining ease of network planning through automated analysis

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11121947B2Monitoring and analysis of interactions between network endpoints
Publication Date: 2021.09.14 INFOBLOX INC
  • US11121947B2 patent drawing
  • US11121947B2 patent drawing
  • US11121947B2 patent drawing

AI summary

Techniques for monitoring and analysis of interactions between network endpoints are disclosed. In some embodiments, a process for monitoring and analysis of interactions between network endpoints includes collecting Domain Name System (DNS) response data from a network device; determining network endpoint interactions based on an analysis of the DNS response data (e.g., using a processor); and generating a graph corresponding to the network endpoint interactions. For example, the network device can include a DNS device and/or a software-defined networking (SDN) device (e.g., an SDN switch, such as an OpenFlow switch).