DNS Nameserver Pairing for Network Device Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Dynamic IP addresses assigned to gateway devices in remote networks make it challenging to characterize and secure network traffic, as these addresses can change frequently, and devices within local networks are often hidden behind Network Address Translation (NAT), complicating anomaly detection and protection.
Innovation Solution
A cloud-based system configures gateway devices with unique pairs of static DNS nameservers, allowing a central platform to identify and classify devices within the network based on DNS traffic patterns, even if the IP address changes, using machine learning algorithms for anomaly detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If dynamic IP addresses are assigned to gateway devices, then network flexibility and resource utilization are improved, but device identification and traffic characterization become difficult
Solution Approach 1:
The patent introduces DNS nameservers as an intermediary identifier between the dynamic IP address system and the security platform. Instead of directly tracking dynamic IP addresses, the system uses DNS nameserver assignments as a stable mediator to identify and characterize devices behind NAT, enabling traffic analysis without being hindered by IP address changes
Solution Approach 2:
The patent segments the identification problem into two parts: using DNS nameserver pairs as stable identifiers for gateway devices, and using these identifiers to subsequently identify individual devices behind NAT. This segmentation allows the system to handle dynamic IP addressing by breaking down the identification task into manageable segments that can be tracked independently
2Reliability
If devices are hidden behind NAT for security, then network security is improved, but anomaly detection capability deteriorates
Solution Approach 1:
The DNS nameserver acts as an intermediary that bridges the security provided by NAT with the need for anomaly detection. By establishing identification through DNS interactions before traffic analysis, the system maintains NAT's security benefits while enabling detection capabilities through the stable DNS-based identifier
Solution Approach 2:
The system performs preliminary identification and classification of devices through DNS nameserver assignment before monitoring traffic for anomalies. This preliminary action establishes a baseline identity for each device, enabling subsequent anomaly detection without requiring direct visibility into the NAT-protected internal network
Data Source
AI summary
A central platform remote from a local network can detect anomalies on the local network. The central platform can assign a unique pair of DNS server IP addresses to the local network. The central platform can receive configuration data from the local network and use the configuration data and the assigned pair of DNS server IP addresses to uniquely identify devices on the local network. In the case that current network flow statistics do not match expected network flow statistics for the local network, a device causing the anomalous behavior can be identified using the assigned pair of DNS server IP addresses and configuration data.


