DNS QoS Management for DoS Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Domain Name Service (DNS) is vulnerable to performance degradation due to Denial of Service (DoS) attacks, which disrupt Internet traffic and cause inconvenience, lost productivity, and economic losses, as existing solutions fail to effectively mitigate the impact of such attacks on networks.

Innovation Solution

Implementing quality-of-service management for DNS that identifies and differentiates between legitimate and illegitimate traffic by forcing top-talking recursive resolvers to use Transmission Control Protocol (TCP) instead of User Datagram Protocol (UDP), establishing persistent TCP sessions, and discarding packets with forged source IP addresses, while reallocating network resources based on projected normal traffic volumes to minimize the impact of DoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If quality-of-service management is implemented to protect DNS traffic against DoS attacks, then DNS service reliability is improved, but device complexity increases

Engineering Contradiction:
ImproveDNS service reliabilityVSAvoidQoS management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments DNS traffic into different priority levels based on source identification. Recursive resolvers are identified and allocated dedicated network resources, while other traffic receives standard service. This segmentation allows the system to protect against DoS attacks by ensuring critical DNS queries receive guaranteed bandwidth and processing, without requiring complex analysis of every individual packet.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary identification and classification of recursive resolvers before the DoS attack occurs. By pre-establishing resource allocations and priority levels for known legitimate DNS clients, the system is prepared to immediately filter and protect against malicious traffic when an attack occurs, rather than reacting in real-time to each attack vector.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If network resources are reallocated based on projected normal traffic volume, then productivity is improved, but measurement precision requirements increase

Engineering Contradiction:
ImproveDNS service productivityVSAvoidTraffic volume measurement precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary measurement and establishment of baseline traffic volumes during normal operating conditions, before DoS attacks occur. These baseline measurements capture the typical traffic patterns and resource requirements of legitimate recursive resolvers. This pre-established baseline enables the system to quickly compare actual traffic during attacks and identify anomalies without requiring continuous high-precision measurement during the attack itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The QoS management system automatically adjusts resource allocation based on the pre-established baselines and current traffic conditions, without requiring manual intervention or continuous complex analysis. The system self-regulates by comparing actual traffic against the baseline and automatically applying appropriate resource allocation policies, reducing the need for ongoing high-precision measurement and manual adjustment.

Inventive Principle:
Principle #25Self-service

3Reliability

If top-talking recursive resolvers are forced to use TCP instead of UDP, then reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
ImproveDNS query reliabilityVSAvoidProtocol compatibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different protocol requirements to different client types based on their characteristics and risk profiles. Top-talking recursive resolvers, which are identified as high-value targets and legitimate high-volume clients, are required to use TCP for enhanced reliability and attack resistance. Other clients continue to use UDP without restriction. This localized application of protocol requirements minimizes the impact on overall system operation while providing enhanced protection where most needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the protocol parameter (UDP vs TCP) specifically for identified top-talking recursive resolvers rather than applying a blanket policy to all DNS clients. This selective parameter change provides the reliability benefits of TCP where most needed while maintaining the simplicity and speed of UDP for other clients, thus balancing reliability improvement with operational ease.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10440147B2Quality-of-service management for domain name service
Publication Date: 2019.10.08 WOODCOCK IV WILLIAM EDWARD
  • US10440147B2 patent drawing
  • US10440147B2 patent drawing

AI summary

Quality-of-service management for Domain Name Service comprising identifying top-talking recursive resolvers of Domain Name Service packets, determining a baseline volume of Internet traffic, extrapolating future projected normal traffic volume, and allocating electronic communication network resources proportionally in accordance with the projected volume. Top-talking recursive resolvers not using a desired protocol can be induced to use that protocol, and a persistent session can be established with the top-talking recursive resolvers, such as by use of a TC flag set. The stateful nature of a TCP conversation allows rate-limiting and traffic volume management. A source IP address can be identified as apparently comprising a forged source IP address based on whether the desired transmission protocol is employed, and packets with the forged source IP address can be discarded.