DNS Request Obfuscation via Decoy Traffic Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DNS resolution methods expose user browsing habits, content requests, and location information to external DNS servers, compromising user privacy and security.

Innovation Solution

A computer-implemented method generates decoy DNS requests to obfuscate legitimate DNS requests handled by a private DNS server, sending these decoy requests to external DNS servers for resolution, thereby anonymizing and securing the legitimate requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DNS requests are sent to external DNS servers for resolution, then DNS resolution functionality is achieved, but user privacy and browsing habit information are exposed to third parties

Engineering Contradiction:
ImproveDNS resolution functionalityVSAvoiduser privacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates decoy DNS requests that copy the structure and appearance of legitimate DNS requests. These decoy requests are sent to external DNS servers alongside real requests, creating indistinguishable traffic patterns. The decoys replicate the necessary DNS protocol characteristics while containing fake lookup data, thereby preserving the functionality of DNS resolution while masking the actual user browsing habits from external servers.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary layer between client devices and external DNS servers. A private DNS server acts as this intermediary, receiving real DNS requests from clients, generating corresponding decoy requests, and sending both to external DNS servers. This intermediary processes and obfuscates the traffic before it reaches external servers, preventing direct exposure of user privacy information while maintaining resolution functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If decoy DNS requests are generated and sent to external DNS servers, then legitimate DNS requests are obfuscated and anonymized, but additional network traffic and processing complexity are introduced

Engineering Contradiction:
ImproveDNS request obfuscation effectivenessVSAvoidDNS request handling complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the DNS request handling process into distinct functional components: receiving real DNS requests from clients, generating decoy requests, combining and sending both to external servers, and processing responses. This segmentation allows each component to be optimized independently and makes the overall system more manageable despite the added complexity of obfuscation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent modifies parameters of DNS requests to create decoys. By changing certain parameters such as domain names, query types, or timing characteristics while maintaining others that ensure valid DNS protocol compliance, the system creates requests that appear legitimate but serve obfuscation purposes. This parameter transformation approach balances obfuscation effectiveness with traffic management.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12278803B2DNS request obfuscation
Publication Date: 2025.04.15 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12278803B2 patent drawing
  • US12278803B2 patent drawing
  • US12278803B2 patent drawing

AI summary

DNS request obfuscation includes generating decoy domain name system (DNS) requests for obfuscating DNS request activity being handled by a private DNS server for an organization, and sending the decoy DNS requests to external DNS server(s) for resolution, receiving a DNS request seeking a DNS lookup for a client device, obfuscating the DNS request by sending, to an external DNS server of the external DNS server(s), the DNS request interspersed with at least some of the generated decoy DNS requests sent to the external DNS server, receiving, from the external DNS server, a DNS response to the sent DNS request, and providing the DNS response to a source of the DNS request.