Detecting Compromised Hosts via DNS NX Message Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods are inadequate for quickly and efficiently detecting compromised computing hosts, as malicious software has become adept at camouflaging or obfuscating these hosts and their command servers, making it difficult for network operators to identify and mitigate malicious activities.
Innovation Solution
The system employs DNS non-existent domain (NX) messages to determine if a computing host is compromised by using a host score associated with unique DNS zones or domain names, and upon detection, performs mitigation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional detection methods are used to identify compromised hosts, then detection capability is limited, but detection speed and efficiency deteriorate due to sophisticated camouflage techniques of malicious software
Solution Approach 1:
Instead of trying to detect compromised hosts directly through their malicious activities or camouflaged identities, the patent inverts the approach by monitoring DNS NX messages (non-existent domain responses) generated by hosts. Compromised hosts typically generate abnormal patterns of NX messages when attempting to communicate with command servers, while legitimate hosts do not. This inversion transforms the detection problem from identifying malicious behavior to identifying abnormal DNS query patterns.
Solution Approach 2:
The patent introduces DNS NX messages as an intermediary indicator for detecting compromised hosts. Rather than directly analyzing malicious software behavior or host characteristics, the system uses DNS query responses as a mediator that reveals compromised host activity. The NX messages serve as indirect evidence that compromised hosts are attempting to establish communication, allowing detection without directly observing the camouflaged malicious activities.
2Reliability
If network operators attempt to identify and mitigate compromised hosts using current methods, then malicious activities may be thwarted, but the complexity and resource requirements increase due to obfuscation techniques
Solution Approach 1:
The patent extracts and isolates a specific, manageable indicator (DNS NX message patterns) from the complex ecosystem of compromised host detection. By focusing exclusively on analyzing NX message characteristics rather than attempting to detect all forms of malicious behavior or decode obfuscation techniques, the system achieves reliable mitigation with reduced complexity. This extraction principle allows the system to ignore irrelevant complexity while maintaining detection effectiveness.
3Measurement precision
If comprehensive monitoring of all DNS traffic is performed to detect compromised hosts, then detection accuracy improves, but processing time and computational resources increase
Solution Approach 1:
The patent extracts only the relevant subset of DNS traffic data - specifically NX messages - for analysis, ignoring the vast majority of normal DNS query responses. This selective extraction maintains high detection accuracy by focusing on the specific message type generated by compromised hosts, while dramatically reducing processing time and computational resources compared to analyzing all DNS traffic comprehensively.
Data Source
AI summary
Methods, systems, and computer readable media for detecting a compromised computing host are disclosed. According to one method, the method includes receiving one or more domain name system (DNS) non-existent domain (NX) messages associated with a computing host. The method also includes determining, using a host score associated with one or more unique DNS zones or domain names included in the one or more DNS NX messages, whether the computing host is compromised. The method further includes performing, in response to determining that the computing host is compromised, a mitigation action.


