DNS Query Classification via Probability Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively distinguish human-driven DNS queries from Machine-to-Machine (M2M) queries, which is crucial for internet traffic analysis, content delivery, advertisement, and security purposes.

Innovation Solution

A computer-implemented method and system that generates a probability score for DNS queries based on predetermined rules, including comparisons with a DNS query dictionary, analysis of domain name prefixes, and historical data patterns, to categorize queries as human-driven or M2M queries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If DNS queries are analyzed without distinction between human-driven and M2M queries, then comprehensive internet traffic data is available, but the ability to perform targeted analysis for content delivery, advertisement, and security purposes is compromised

Engineering Contradiction:
Improvequery classification accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments DNS queries into distinct categories (human-driven vs. M2M) by analyzing specific characteristics such as domain name patterns, query frequency, and temporal distributions. This segmentation enables targeted analysis for different purposes while maintaining overall system manageability through rule-based classification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes analysis parameters by examining multiple dimensions of query behavior including domain name structure, query interval, and historical patterns. By transforming raw query data into classified categories based on these parameter changes, the system achieves precise measurement without requiring overly complex analysis infrastructure.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If all DNS queries are processed uniformly, then complete traffic data is maintained, but the efficiency of content delivery and security measures is reduced due to inability to prioritize human-driven activities

Engineering Contradiction:
Improveanalysis processing efficiencyVSAvoidhuman behavior analysis capability
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent extracts and isolates human-driven DNS queries from the general traffic stream by identifying distinctive patterns such as browser-based query characteristics and user behavior signatures. This extraction enables efficient processing of only relevant queries for content delivery and security while preserving complete data through the extracted classifications.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system incorporates feedback mechanisms that continuously refine query classification by analyzing historical data and adjusting identification criteria. This feedback loop improves processing efficiency over time while maintaining accurate human behavior analysis capabilities through iterative learning from traffic patterns.

Inventive Principle:
Principle #23Feedback

3Reliability

If M2M DNS queries are analyzed without filtering, then automated process detection is possible, but the ability to detect malicious activities is compromised by inclusion of benign automated queries

Engineering Contradiction:
Improvemalicious activity detection accuracyVSAvoidquery filtering system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary classification actions by pre-establishing criteria to identify and separate M2M queries before security analysis. This preliminary sorting based on query patterns and source characteristics enables reliable malicious activity detection while reducing the complexity of subsequent security processing through data pre-filtering.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10164989B2Distinguishing human-driven DNS queries from machine-to-machine DNS queries
Publication Date: 2018.12.25 AKAMAI TECHNOLOGIES INC
  • US10164989B2 patent drawing
  • US10164989B2 patent drawing
  • US10164989B2 patent drawing

AI summary

The present disclosure is related to a computer-implemented method and system for distinguishing human-driven Domain Name System (DNS) queries from Machine-to-Machine (M2M) DNS queries. The method includes receiving a DNS query, which includes a domain name, generating a probability score for the domain name based on one or more predetermined rules, and categorizing the DNS query as a human-driven DNS query or a M2M DNS query based on the probability score.