DNS Query Cycle for Tracking Malicious IP Changes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for collecting information on malignant communication partners during cyberattacks, such as those using honey pots or sandboxes, fail to exhaustively and accurately specify temporarily used or preparatory malicious partners, as their IP addresses and communication relationships change over time.
Innovation Solution
A communication partner correspondence relationship collecting device that specifies subject communication partners, controls a DNS client to transmit DNS queries in a given cycle, and creates log information incorporating changes over time in correspondence relationships between communication partners and IP addresses, including dates and times of responses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If information on communication partners is collected using honey pots or sandboxes, then communication content relevant to cyberattacks can be collected, but temporarily used or preparatory malicious partners cannot be exhaustively and accurately specified
Solution Approach 1:
The system performs preliminary DNS queries at multiple time points before attacks occur to establish a baseline of legitimate communication partners. This preliminary action creates a reference dataset that enables later identification of deviations, allowing the system to detect preparatory malicious activities that traditional real-time monitoring would miss.
Solution Approach 2:
The system conducts DNS queries periodically at predetermined time intervals to collect communication partner information dynamically over time. This periodic sampling captures temporary malicious partners that appear and disappear within query intervals, enabling comprehensive identification of malicious activities including temporary and preparatory phases.
2Loss of information
If DNS queries are transmitted continuously to collect IP addresses, then comprehensive communication partner information can be obtained, but system resources and network bandwidth are consumed
Solution Approach 1:
DNS queries are transmitted at predetermined time intervals rather than continuously, reducing system resource consumption and network bandwidth usage while still capturing temporary malicious partners that appear between query periods. The periodic timing is optimized to balance information completeness with resource efficiency.
Solution Approach 2:
The query interval is dynamically adjusted based on detected changes in communication patterns. When anomalies are detected, the system increases query frequency to capture evolving malicious activities, while during normal periods it reduces frequency to conserve resources, optimizing the balance between information collection and resource usage.
Data Source
AI summary
A communication partner correspondence relationship collecting device includes a communication partner specifying unit that specifies a subject communication partner whose correspondence relationships are to be collected; a DNS query transmission controller that controls a DNS client such that the DNS client transmits a DNS query to the subject communication partner in a given cycle shorter than a cycle in which the IP address corresponding to the subject communication partner is changed and that collects IP addresses corresponding to the subject communication partner from responses to the DNS queries; and a correspondence relationship log information creator that creates log information from the IP addresses corresponding to the subject communication partner, which are the IP addresses collected by the DNS query transmission controller, and at least one of a set of dates and a set of times at which responses are made to the DNS queries.


