DNS Modification Prevention via Behavioral Source Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems are ineffective in detecting and preventing malware that changes domain name system (DNS) settings, often failing to recognize unknown malware signatures and exhibiting high turnaround times in response, with incomplete cleaning processes.

Innovation Solution

A system and method that detect attempts to modify DNS settings, verify the source and attributes of these attempts, and prevent malicious modifications by comparing them against whitelists and blacklists, notifying users and potentially undoing or blocking such changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security systems use signature-based detection for malware, then known malware can be detected, but unknown malware without signatures cannot be detected

Engineering Contradiction:
Improvedetection accuracyVSAvoidcapability to detect unknown malware
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the detection parameter from static malware signatures to dynamic behavioral parameters. The system monitors DNS setting modifications, process creation patterns, and system registry changes to detect malware behavior rather than relying on predefined signatures. This allows detection of unknown malware by analyzing its operational characteristics and deviations from normal system behavior.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary actions by establishing baseline DNS settings and creating monitoring mechanisms before malware execution. It proactively sets up hooks and filters to detect attempted modifications, rather than waiting for signature updates after malware is identified. This preventive monitoring approach enables detection of novel threats based on their behavioral patterns.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional security systems submit malware samples for analysis, then malware can be identified, but the turnaround time is significantly high

Engineering Contradiction:
Improvemalware identification accuracyVSAvoidturnaround time for security response
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service by automatically monitoring and detecting DNS modification attempts in real-time without requiring external analysis services. The local security agent continuously watches for suspicious activities and can respond immediately to threats, eliminating the time delay associated with submitting samples to remote security vendors for analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent rushes through the detection process by using real-time behavioral monitoring that provides immediate detection and response. Instead of the traditional slow process of sample collection, submission, analysis, and update deployment, the system skips these intermediate steps by detecting threats locally as they occur through continuous monitoring of DNS settings and process behaviors.

Inventive Principle:
Principle #21Skipping (Rushing through)

3Ease of manufacture

If traditional security systems perform cleaning of infected systems, then some malware can be removed, but the cleaning is often incomplete with respect to DNS settings

Engineering Contradiction:
Improvecleaning effectivenessVSAvoidcompleteness of DNS setting restoration
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system performs preliminary action by creating restorable snapshots of DNS settings before allowing modifications and by continuously monitoring for changes. When malware is detected, the system can restore to the pre-infection state using these预先 prepared snapshots, ensuring complete and accurate restoration of DNS settings without manual intervention or incomplete cleaning processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms that continuously monitor DNS settings to verify whether restoration was successful. The system compares current settings against known good configurations and continues restoration operations until complete cleanliness is achieved, providing feedback loops that ensure thorough cleaning rather than incomplete manual processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9294505B2System, method, and computer program product for preventing a modification to a domain name system setting
Publication Date: 2016.03.22 MCAFEE LLC
  • US9294505B2 patent drawing
  • US9294505B2 patent drawing
  • US9294505B2 patent drawing

AI summary

A system, method, and computer program product are provided for preventing a modification to a domain name system setting. In use, an attempt to modify a domain name system setting is detected. Additionally, a source of the attempt and an attribute of the modification are verified. Further, the modification to the domain name system setting is prevented, based on the verification.