DNS Request Classification for Machine-Generated Traffic Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Domain Name System (DNS) is affected by malicious machine-generated requests from internet bots, which skew systems designed to search for available domain names and can lead to network resource exhaustion and security threats, making it difficult to distinguish between legitimate and illegitimate traffic.

Innovation Solution

A method and apparatus for tracking and classifying requests to resolve non-existent domain names (NXDomains) by maintaining a log of requests, identifying unique sets of unresolvable textual identifiers, and categorizing them into taxonomical sets to distinguish machine-generated requests, including filtering suspicious requests using statistical heuristics and suggesting available domain names for registration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If DNS systems track all requests to search for available domain names, then domain name availability search capability is improved, but network resource exhaustion and security threats increase due to malicious machine-generated requests

Engineering Contradiction:
Improvedomain name availability search capabilityVSAvoidnetwork resource exhaustion and security threats
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary classification system that sits between the DNS request tracking and the domain name availability search. This intermediary analyzes request characteristics (such as request patterns, source identification, and temporal distribution) to distinguish machine-generated requests from legitimate user requests, allowing the system to filter out malicious traffic while maintaining the ability to track and search for available domain names

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different quality standards and analysis methods to different types of requests. By identifying specific characteristics of machine-generated requests (such as automated patterns, lack of human interaction markers, or systematic enumeration behaviors), the system applies targeted filtering rules to these specific request types while maintaining normal processing for legitimate requests, thus addressing the harmful factor locally without affecting overall system productivity

Inventive Principle:
Principle #3Local quality

2Reliability

If the system filters out machine-generated requests to reduce resource exhaustion, then network security is improved, but the ability to track and analyze all DNS requests for domain name availability decreases

Engineering Contradiction:
Improvenetwork securityVSAvoidrequest tracking and analysis capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent performs preliminary classification and identification of request types before filtering. By analyzing request characteristics in advance and categorizing them as machine-generated or legitimate, the system can make informed decisions about which requests to filter and which to maintain in the tracking system. This preliminary action ensures that security filtering does not result in loss of important information about legitimate domain name availability search requests

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9058381B2Method of and apparatus for identifying machine-generated textual identifiers
Publication Date: 2015.06.16 VERISIGN INC
  • US9058381B2 patent drawing
  • US9058381B2 patent drawing
  • US9058381B2 patent drawing

AI summary

Methods and systems provide tracking or logging requests to resolve non-existent textual identifiers and classifying the textual identifier into a predefined set of taxonomical categories to support the detection of machine generated textual identifiers. Detection includes calculating a measure of probability based on the analysis and classification of prior textual identifier requests from a set of requests for a specific textual identifier.