DNS Query Classification for Obscured Device Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device classification methods, particularly in enterprise networks, face challenges when devices intentionally obscure their information or lack DHCP server interactions, necessitating a more robust and DHCP-independent mechanism for automated device identification.
Innovation Solution
A system utilizing DNS query patterns through SLD-based, name-based, statistical, and ensemble classifiers to categorize devices into IoT and non-IoT categories, and further classify specific types like laptops and printers, leveraging machine learning techniques for enhanced accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DHCP server interactions are used for device identification, then device classification can be performed, but devices that intentionally obscure their information or lack DHCP interactions cannot be identified
Solution Approach 1:
The patent introduces DNS servers as an intermediary mechanism for device identification. Instead of relying solely on DHCP servers, the system uses DNS query patterns as a mediating indicator to classify devices. The DNS server captures query characteristics (domains queried, query frequency, timing) that serve as indirect but reliable identifiers for device types, enabling identification of devices that obscure their information or lack DHCP interactions.
Solution Approach 2:
The patent replaces the mechanical DHCP-based identification system with a DNS-based observational system. Rather than requiring direct mechanical interaction through DHCP handshakes, the system substitutes DNS query pattern analysis - observing and analyzing the natural DNS traffic behavior of devices to infer their types. This substitution enables identification of devices that would otherwise remain hidden from traditional DHCP-based methods.
2Measurement precision
If multiple classifier types are integrated, then device classification accuracy is improved, but system complexity increases
Solution Approach 1:
The patent merges multiple classifier types (statistical classifiers analyzing query frequency and timing patterns, and machine learning classifiers using trained models on DNS characteristics) into a unified device identification system. These classifiers work together to analyze DNS query data from multiple dimensions, combining their strengths to achieve high classification accuracy. The merged system cross-validates results across different classifier approaches, improving reliability while maintaining manageable complexity through integrated architecture.
Solution Approach 2:
The patent creates a universal DNS-based classification framework that can identify multiple device types (IoT devices, laptops, printers, smartphones) using a single multi-functional system. The classifier system is designed to handle diverse device categories through common DNS query pattern analysis, making it universally applicable across different device types without requiring separate specialized systems for each device category. This multi-functionality achieves high accuracy across varied device types while avoiding the complexity of multiple separate identification systems.
Data Source
AI summary
Techniques for providing device anomaly detection based on DNS queries are disclosed. In some embodiments, a system, a process, and/or a computer program product for device anomaly detection based on DNS queries includes receiving Domain Name System (DNS) network activity, wherein the DNS network activity includes a plurality of DNS queries; processing the DNS network activity to generate a plurality of metrics; and automatically detecting anomalies associated with one or more devices for a monitored network.


