DNS Infection Scoring for Client Remediation Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In enterprise networks, limited IT resources make it challenging to prioritize which clients need remediation for malware infections effectively, as existing methods lack a systematic approach to differentiate between legitimate and malicious DNS traffic.

Innovation Solution

A DNS-based infection scoring system that analyzes DNS request and response packets to categorize domains and IP addresses, generating infection scores for clients based on query profiles, using observation logic, infection score generation logic, and prioritization logic to identify and prioritize clients for remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IT resources are increased to remediate all infected clients, then the ability to address malware infections improves, but the resource constraints and cost increase

Engineering Contradiction:
Improvemalware remediation capabilityVSAvoidIT resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system changes the parameter of client prioritization by introducing infection scores that quantify the likelihood of malware infection. This allows IT resources to be allocated based on prioritized lists of clients ranked by infection probability, rather than attempting to remediate all clients equally. The infection score parameter transforms the remediation approach from comprehensive but resource-intensive to targeted and efficient.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies local quality by differentiating between clients based on their specific DNS query patterns and infection risks. Instead of uniform remediation across all clients, the system identifies and prioritizes specific clients with higher infection likelihoods based on their local DNS behavior characteristics, allowing resources to be concentrated where they are most needed.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If DNS traffic analysis is performed on all clients, then infection detection accuracy improves, but the system complexity and processing overhead increase

Engineering Contradiction:
Improveinfection detection accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system changes parameters by establishing baseline DNS query patterns for each client and measuring deviations from these baselines. Infection detection is achieved by monitoring changes in query frequency, domain types, and response patterns rather than analyzing absolute values. This parameter-based approach simplifies the analysis while maintaining detection accuracy.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system segments DNS traffic analysis into distinct categories such as domain types (whitelisted, blacklisted, grey), query patterns, and response characteristics. By segmenting the analysis into manageable components and evaluating each separately, the system reduces overall complexity while improving detection precision through multi-dimensional assessment.

Inventive Principle:
Principle #1Segmentation

3Reliability

If comprehensive DNS query monitoring is implemented, then the ability to identify infected clients improves, but the time required for analysis and remediation prioritization increases

Engineering Contradiction:
Improveinfected client identificationVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by establishing baseline DNS query patterns for each client before infection occurs. These baselines are stored and used for rapid comparison when analyzing new DNS traffic. By having pre-computed reference patterns, the system can quickly identify deviations indicating infection without requiring time-consuming analysis from scratch, thus reducing detection time while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring DNS query patterns and comparing them against baselines, then using the results to update infection scores and prioritization lists. This closed-loop feedback mechanism allows the system to adapt to changing conditions and refine its identification accuracy over time, improving reliability without proportionally increasing analysis time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10474820B2DNS based infection scores
Publication Date: 2019.11.12 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10474820B2 patent drawing
  • US10474820B2 patent drawing
  • US10474820B2 patent drawing

AI summary

Systems and methods associated with domain name system (DNS) based infection scores. One example method includes maintaining query profiles for members of a set of clients in a network. The query profiles may be maintained based on DNS queries sent from the members of the set of clients, and on DNS responses received by the members of the set of clients. The method also includes generating infection scores for the members of the set of clients based on their respective query profiles. The method also includes prioritizing a vulnerable member of the set of clients for remedial action. The vulnerable member may be prioritized based on infection scores of members of the set of clients.