DNS Query Cycle for Tracking Malicious IP Changes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for collecting information on malignant communication partners during cyberattacks, such as those using honey pots or sandboxes, fail to exhaustively and accurately specify temporarily used or preparatory malicious partners, as their IP addresses and communication relationships change over time.

Innovation Solution

A communication partner correspondence relationship collecting device that specifies subject communication partners, controls a DNS client to transmit DNS queries in a given cycle, and creates log information incorporating changes over time in correspondence relationships between communication partners and IP addresses, including dates and times of responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If information on communication partners is collected using honey pots or sandboxes, then communication content relevant to cyberattacks can be collected, but temporarily used or preparatory malicious partners cannot be exhaustively and accurately specified

Engineering Contradiction:
Improveinformation on malicious communication partnersVSAvoidaccuracy of malicious partner identification
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The system performs preliminary DNS queries at multiple time points before attacks occur to establish a baseline of legitimate communication partners. This preliminary action creates a reference dataset that enables later identification of deviations, allowing the system to detect preparatory malicious activities that traditional real-time monitoring would miss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system conducts DNS queries periodically at predetermined time intervals to collect communication partner information dynamically over time. This periodic sampling captures temporary malicious partners that appear and disappear within query intervals, enabling comprehensive identification of malicious activities including temporary and preparatory phases.

Inventive Principle:
Principle #19Periodic action

2Loss of information

If DNS queries are transmitted continuously to collect IP addresses, then comprehensive communication partner information can be obtained, but system resources and network bandwidth are consumed

Engineering Contradiction:
Improvecompleteness of IP address collectionVSAvoidsystem resource consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

DNS queries are transmitted at predetermined time intervals rather than continuously, reducing system resource consumption and network bandwidth usage while still capturing temporary malicious partners that appear between query periods. The periodic timing is optimized to balance information completeness with resource efficiency.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The query interval is dynamically adjusted based on detected changes in communication patterns. When anomalies are detected, the system increases query frequency to capture evolving malicious activities, while during normal periods it reduces frequency to conserve resources, optimizing the balance between information collection and resource usage.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10917380B2Device and associated methodology for collecting communication partner IP addresses
Publication Date: 2021.02.09 NIPPON TELEGRAPH & TELEPHONE CORP
  • US10917380B2 patent drawing
  • US10917380B2 patent drawing
  • US10917380B2 patent drawing

AI summary

A communication partner correspondence relationship collecting device includes a communication partner specifying unit that specifies a subject communication partner whose correspondence relationships are to be collected; a DNS query transmission controller that controls a DNS client such that the DNS client transmits a DNS query to the subject communication partner in a given cycle shorter than a cycle in which the IP address corresponding to the subject communication partner is changed and that collects IP addresses corresponding to the subject communication partner from responses to the DNS queries; and a correspondence relationship log information creator that creates log information from the IP addresses corresponding to the subject communication partner, which are the IP addresses collected by the DNS query transmission controller, and at least one of a set of dates and a set of times at which responses are made to the DNS queries.