Role-Based DNS Policy Enforcement for User Notifications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security administrators face challenges in notifying end-users when their traffic is prohibited by network security policies, leading to user dissatisfaction and increased operational costs due to unresolved issues perceived by users as network problems.
Innovation Solution
Implementing a Domain Name System (DNS) device that stores user device and policy data to apply role-based policies, notifying users through a notification server when access is denied, thereby improving user experience and reducing unnecessary support requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network security controls silently discard packets that violate policies, then network security enforcement is maintained, but end-users are not notified of the prohibition leading to user dissatisfaction and increased operational costs
Solution Approach 1:
The patent implements a feedback mechanism where the DNS device notifies end-users when their traffic is prohibited by network security policies. The DNS device receives DNS requests, determines whether they violate security policies, and provides notifications to users about the prohibition reasons, creating a closed-loop feedback system that resolves the contradiction between silent enforcement and user notification
Solution Approach 2:
The DNS device acts as an intermediary between the network security controls and end-users. It receives DNS requests from users, checks them against security policies, and communicates the results to users through notifications. This intermediary role enables policy enforcement while providing user-friendly feedback without requiring changes to the core security infrastructure
2Reliability
If network security controls silently discard packets, then security policy enforcement is maintained, but end-users mistakenly believe network issues exist leading to increased support requests and operational costs
Solution Approach 1:
The DNS device implements feedback by notifying end-users when their DNS requests are blocked due to security policy violations. The notification includes information about the prohibition, preventing users from mistakenly believing there are network issues and reducing unnecessary support requests while maintaining security enforcement
Solution Approach 2:
The DNS device serves as an intermediary that captures the information about access denials and communicates it to end-users. By intercepting DNS requests and providing notifications about policy violations, it prevents information loss and eliminates the confusion that leads to increased operational costs
Data Source
AI summary
A Domain Name System (DNS) device stores data indicative of a user device and data indicative of a policy setting a level of access of the user device to a responding device. The DNS device receives, from the user device, a request for an Internet Protocol address of the responding device. The DNS device determines, based upon the request and the data indicative of the user device, that the policy applies to the request. The DNS device applies the policy in response to the determining.


