DNS Query Classification for Obscured Device Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device classification methods, particularly in enterprise networks, face challenges when devices intentionally obscure their information or lack DHCP server interactions, necessitating a more robust and DHCP-independent mechanism for automated device identification.

Innovation Solution

A system utilizing DNS query patterns through SLD-based, name-based, statistical, and ensemble classifiers to categorize devices into IoT and non-IoT categories, and further classify specific types like laptops and printers, leveraging machine learning techniques for enhanced accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DHCP server interactions are used for device identification, then device classification can be performed, but devices that intentionally obscure their information or lack DHCP interactions cannot be identified

Engineering Contradiction:
Improvedevice identification reliabilityVSAvoidcapability to identify obscured devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces DNS servers as an intermediary mechanism for device identification. Instead of relying solely on DHCP servers, the system uses DNS query patterns as a mediating indicator to classify devices. The DNS server captures query characteristics (domains queried, query frequency, timing) that serve as indirect but reliable identifiers for device types, enabling identification of devices that obscure their information or lack DHCP interactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical DHCP-based identification system with a DNS-based observational system. Rather than requiring direct mechanical interaction through DHCP handshakes, the system substitutes DNS query pattern analysis - observing and analyzing the natural DNS traffic behavior of devices to infer their types. This substitution enables identification of devices that would otherwise remain hidden from traditional DHCP-based methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If multiple classifier types are integrated, then device classification accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedevice classification accuracyVSAvoidclassifier system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple classifier types (statistical classifiers analyzing query frequency and timing patterns, and machine learning classifiers using trained models on DNS characteristics) into a unified device identification system. These classifiers work together to analyze DNS query data from multiple dimensions, combining their strengths to achieve high classification accuracy. The merged system cross-validates results across different classifier approaches, improving reliability while maintaining manageable complexity through integrated architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal DNS-based classification framework that can identify multiple device types (IoT devices, laptops, printers, smartphones) using a single multi-functional system. The classifier system is designed to handle diverse device categories through common DNS query pattern analysis, making it universally applicable across different device types without requiring separate specialized systems for each device category. This multi-functionality achieves high accuracy across varied device types while avoiding the complexity of multiple separate identification systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260067297A1Device anomaly detection based on DNS queries
Publication Date: 2026.03.05 INFOBLOX INC
  • US20260067297A1 patent drawing
  • US20260067297A1 patent drawing
  • US20260067297A1 patent drawing

AI summary

Techniques for providing device anomaly detection based on DNS queries are disclosed. In some embodiments, a system, a process, and/or a computer program product for device anomaly detection based on DNS queries includes receiving Domain Name System (DNS) network activity, wherein the DNS network activity includes a plurality of DNS queries; processing the DNS network activity to generate a plurality of metrics; and automatically detecting anomalies associated with one or more devices for a monitored network.