DNS-Based Malicious Website Interception via VPN On Demand
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for intercepting malicious websites on closed operating systems like iOS require constant VPN connection, leading to poor user experience and high server costs due to the need for all application traffic to be routed through the VPN server, which is resource-intensive.
Innovation Solution
Implementing a system where a DNS server analyzes domain names and intercepts malicious traffic without requiring constant VPN connection by using VPN On Demand conditions and modifying DNS settings to filter out malicious domains, allowing only necessary traffic to be routed through the VPN.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all application traffic is routed through the VPN server for global malicious website interception, then interception coverage is improved, but system resource consumption and server costs increase
Solution Approach 1:
The patent segments network traffic into different categories (e.g., web traffic, API traffic, file transfer traffic) and applies different interception strategies to each segment. Web traffic is subject to full malicious website interception through VPN, while other traffic types use alternative handling methods, thereby reducing overall system resource consumption while maintaining effective interception coverage for critical traffic types.
Solution Approach 2:
The patent applies local quality by providing different levels of security protection to different traffic types. Instead of uniform treatment of all traffic, the system tailors the interception mechanism to local characteristics of each traffic type, enabling resource-efficient interception where needed while allowing optimized handling where risk is lower.
2Reliability
If all application traffic is routed through the VPN server for global malicious website interception, then interception coverage is improved, but server costs increase
Solution Approach 1:
The patent segments network traffic into different categories (e.g., web traffic, API traffic, file transfer traffic) and applies different interception strategies to each segment. Web traffic is subject to full malicious website interception through VPN, while other traffic types use alternative handling methods, thereby reducing overall system resource consumption while maintaining effective interception coverage for critical traffic types.
Solution Approach 2:
The patent applies partial action by implementing malicious website interception only for traffic that requires it most (e.g., web browsing traffic), rather than treating all traffic uniformly. This selective approach reduces the volume of traffic processed by the VPN server, thereby lowering server costs while maintaining adequate protection for the most vulnerable traffic types.
3Reliability
If the terminal remains connected to the VPN for malicious website interception, then interception capability is maintained, but user experience deteriorates due to slow network speeds
Solution Approach 1:
The patent implements dynamic VPN connection management where the VPN connection is established only when needed for malicious website interception and can be disconnected when not required. The system dynamically adjusts the VPN connection state based on current network conditions and traffic types, allowing users to experience fast network speeds during normal operations while maintaining interception capability when necessary.
Solution Approach 2:
The patent applies periodic action by establishing VPN connection only at specific moments when malicious website interception is required, rather than maintaining continuous connection. The system periodically checks network conditions and traffic characteristics to determine when VPN connection should be activated, thereby improving user experience during normal operations while ensuring interception capability is available when needed.
Data Source
AI summary
Embodiments of the present application relate to a method, device, and system for intercepting traffic to malicious websites. The method includes obtaining, by one or more processors, a network request from a terminal, obtaining, by one or more processors, domain information from the network request, determining, by one or more processors, whether the domain information corresponds to an access-prohibited website domain, and communicating, by one or more processors, a web page response to terminal, wherein the web page response is based at least in part on the determining whether the domain information corresponds to an access-prohibited website domain.


