DNS Query Classification via Probability Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively distinguish human-driven DNS queries from Machine-to-Machine (M2M) queries, which is crucial for internet traffic analysis, content delivery, advertisement, and security purposes.
Innovation Solution
A computer-implemented method and system that generates a probability score for DNS queries based on predetermined rules, including comparisons with a DNS query dictionary, analysis of domain name prefixes, and historical data patterns, to categorize queries as human-driven or M2M queries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If DNS queries are analyzed without distinction between human-driven and M2M queries, then comprehensive internet traffic data is available, but the ability to perform targeted analysis for content delivery, advertisement, and security purposes is compromised
Solution Approach 1:
The patent segments DNS queries into distinct categories (human-driven vs. M2M) by analyzing specific characteristics such as domain name patterns, query frequency, and temporal distributions. This segmentation enables targeted analysis for different purposes while maintaining overall system manageability through rule-based classification.
Solution Approach 2:
The system changes analysis parameters by examining multiple dimensions of query behavior including domain name structure, query interval, and historical patterns. By transforming raw query data into classified categories based on these parameter changes, the system achieves precise measurement without requiring overly complex analysis infrastructure.
2Productivity
If all DNS queries are processed uniformly, then complete traffic data is maintained, but the efficiency of content delivery and security measures is reduced due to inability to prioritize human-driven activities
Solution Approach 1:
The patent extracts and isolates human-driven DNS queries from the general traffic stream by identifying distinctive patterns such as browser-based query characteristics and user behavior signatures. This extraction enables efficient processing of only relevant queries for content delivery and security while preserving complete data through the extracted classifications.
Solution Approach 2:
The system incorporates feedback mechanisms that continuously refine query classification by analyzing historical data and adjusting identification criteria. This feedback loop improves processing efficiency over time while maintaining accurate human behavior analysis capabilities through iterative learning from traffic patterns.
3Reliability
If M2M DNS queries are analyzed without filtering, then automated process detection is possible, but the ability to detect malicious activities is compromised by inclusion of benign automated queries
Solution Approach 1:
The patent applies preliminary classification actions by pre-establishing criteria to identify and separate M2M queries before security analysis. This preliminary sorting based on query patterns and source characteristics enables reliable malicious activity detection while reducing the complexity of subsequent security processing through data pre-filtering.
Data Source
AI summary
The present disclosure is related to a computer-implemented method and system for distinguishing human-driven Domain Name System (DNS) queries from Machine-to-Machine (M2M) DNS queries. The method includes receiving a DNS query, which includes a domain name, generating a probability score for the domain name based on one or more predetermined rules, and categorizing the DNS query as a human-driven DNS query or a M2M DNS query based on the probability score.


