DNS-Based Malicious Website Interception via VPN On Demand

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for intercepting malicious websites on closed operating systems like iOS require constant VPN connection, leading to poor user experience and high server costs due to the need for all application traffic to be routed through the VPN server, which is resource-intensive.

Innovation Solution

Implementing a system where a DNS server analyzes domain names and intercepts malicious traffic without requiring constant VPN connection by using VPN On Demand conditions and modifying DNS settings to filter out malicious domains, allowing only necessary traffic to be routed through the VPN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all application traffic is routed through the VPN server for global malicious website interception, then interception coverage is improved, but system resource consumption and server costs increase

Engineering Contradiction:
Improveinterception coverageVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments network traffic into different categories (e.g., web traffic, API traffic, file transfer traffic) and applies different interception strategies to each segment. Web traffic is subject to full malicious website interception through VPN, while other traffic types use alternative handling methods, thereby reducing overall system resource consumption while maintaining effective interception coverage for critical traffic types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by providing different levels of security protection to different traffic types. Instead of uniform treatment of all traffic, the system tailors the interception mechanism to local characteristics of each traffic type, enabling resource-efficient interception where needed while allowing optimized handling where risk is lower.

Inventive Principle:
Principle #3Local quality

2Reliability

If all application traffic is routed through the VPN server for global malicious website interception, then interception coverage is improved, but server costs increase

Engineering Contradiction:
Improveinterception coverageVSAvoidserver costs
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments network traffic into different categories (e.g., web traffic, API traffic, file transfer traffic) and applies different interception strategies to each segment. Web traffic is subject to full malicious website interception through VPN, while other traffic types use alternative handling methods, thereby reducing overall system resource consumption while maintaining effective interception coverage for critical traffic types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by implementing malicious website interception only for traffic that requires it most (e.g., web browsing traffic), rather than treating all traffic uniformly. This selective approach reduces the volume of traffic processed by the VPN server, thereby lowering server costs while maintaining adequate protection for the most vulnerable traffic types.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the terminal remains connected to the VPN for malicious website interception, then interception capability is maintained, but user experience deteriorates due to slow network speeds

Engineering Contradiction:
Improveinterception capabilityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic VPN connection management where the VPN connection is established only when needed for malicious website interception and can be disconnected when not required. The system dynamically adjusts the VPN connection state based on current network conditions and traffic types, allowing users to experience fast network speeds during normal operations while maintaining interception capability when necessary.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies periodic action by establishing VPN connection only at specific moments when malicious website interception is required, rather than maintaining continuous connection. The system periodically checks network conditions and traffic characteristics to determine when VPN connection should be activated, thereby improving user experience during normal operations while ensuring interception capability is available when needed.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10846398B2Method, means, system, processor, and memory for intercepting malicious websites
Publication Date: 2020.11.24 ALIBABA GROUP HOLDING LTD
  • US10846398B2 patent drawing
  • US10846398B2 patent drawing
  • US10846398B2 patent drawing

AI summary

Embodiments of the present application relate to a method, device, and system for intercepting traffic to malicious websites. The method includes obtaining, by one or more processors, a network request from a terminal, obtaining, by one or more processors, domain information from the network request, determining, by one or more processors, whether the domain information corresponds to an access-prohibited website domain, and communicating, by one or more processors, a web page response to terminal, wherein the web page response is based at least in part on the determining whether the domain information corresponds to an access-prohibited website domain.