Detecting Compromised Hosts via DNS NX Message Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods are inadequate for quickly and efficiently detecting compromised computing hosts, as malicious software has become adept at camouflaging or obfuscating these hosts and their command servers, making it difficult for network operators to identify and mitigate malicious activities.

Innovation Solution

The system employs DNS non-existent domain (NX) messages to determine if a computing host is compromised by using a host score associated with unique DNS zones or domain names, and upon detection, performs mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional detection methods are used to identify compromised hosts, then detection capability is limited, but detection speed and efficiency deteriorate due to sophisticated camouflage techniques of malicious software

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

Instead of trying to detect compromised hosts directly through their malicious activities or camouflaged identities, the patent inverts the approach by monitoring DNS NX messages (non-existent domain responses) generated by hosts. Compromised hosts typically generate abnormal patterns of NX messages when attempting to communicate with command servers, while legitimate hosts do not. This inversion transforms the detection problem from identifying malicious behavior to identifying abnormal DNS query patterns.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces DNS NX messages as an intermediary indicator for detecting compromised hosts. Rather than directly analyzing malicious software behavior or host characteristics, the system uses DNS query responses as a mediator that reveals compromised host activity. The NX messages serve as indirect evidence that compromised hosts are attempting to establish communication, allowing detection without directly observing the camouflaged malicious activities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network operators attempt to identify and mitigate compromised hosts using current methods, then malicious activities may be thwarted, but the complexity and resource requirements increase due to obfuscation techniques

Engineering Contradiction:
Improvemitigation effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and isolates a specific, manageable indicator (DNS NX message patterns) from the complex ecosystem of compromised host detection. By focusing exclusively on analyzing NX message characteristics rather than attempting to detect all forms of malicious behavior or decode obfuscation techniques, the system achieves reliable mitigation with reduced complexity. This extraction principle allows the system to ignore irrelevant complexity while maintaining detection effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If comprehensive monitoring of all DNS traffic is performed to detect compromised hosts, then detection accuracy improves, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts only the relevant subset of DNS traffic data - specifically NX messages - for analysis, ignoring the vast majority of normal DNS query responses. This selective extraction maintains high detection accuracy by focusing on the specific message type generated by compromised hosts, while dramatically reducing processing time and computational resources compared to analyzing all DNS traffic comprehensively.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9934379B2Methods, systems, and computer readable media for detecting a compromised computing host
Publication Date: 2018.04.03 THE UNIV OF NORTH CAROLINA AT CHAPEL HILL
  • US9934379B2 patent drawing
  • US9934379B2 patent drawing
  • US9934379B2 patent drawing

AI summary

Methods, systems, and computer readable media for detecting a compromised computing host are disclosed. According to one method, the method includes receiving one or more domain name system (DNS) non-existent domain (NX) messages associated with a computing host. The method also includes determining, using a host score associated with one or more unique DNS zones or domain names included in the one or more DNS NX messages, whether the computing host is compromised. The method further includes performing, in response to determining that the computing host is compromised, a mitigation action.