DNS Request Obfuscation via Decoy Traffic Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DNS resolution methods expose user browsing habits, content requests, and location information to external DNS servers, compromising user privacy and security.
Innovation Solution
A computer-implemented method generates decoy DNS requests to obfuscate legitimate DNS requests handled by a private DNS server, sending these decoy requests to external DNS servers for resolution, thereby anonymizing and securing the legitimate requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DNS requests are sent to external DNS servers for resolution, then DNS resolution functionality is achieved, but user privacy and browsing habit information are exposed to third parties
Solution Approach 1:
The patent creates decoy DNS requests that copy the structure and appearance of legitimate DNS requests. These decoy requests are sent to external DNS servers alongside real requests, creating indistinguishable traffic patterns. The decoys replicate the necessary DNS protocol characteristics while containing fake lookup data, thereby preserving the functionality of DNS resolution while masking the actual user browsing habits from external servers.
Solution Approach 2:
The patent introduces an intermediary layer between client devices and external DNS servers. A private DNS server acts as this intermediary, receiving real DNS requests from clients, generating corresponding decoy requests, and sending both to external DNS servers. This intermediary processes and obfuscates the traffic before it reaches external servers, preventing direct exposure of user privacy information while maintaining resolution functionality.
2Object-affected harmful factors
If decoy DNS requests are generated and sent to external DNS servers, then legitimate DNS requests are obfuscated and anonymized, but additional network traffic and processing complexity are introduced
Solution Approach 1:
The patent segments the DNS request handling process into distinct functional components: receiving real DNS requests from clients, generating decoy requests, combining and sending both to external servers, and processing responses. This segmentation allows each component to be optimized independently and makes the overall system more manageable despite the added complexity of obfuscation.
Solution Approach 2:
The patent modifies parameters of DNS requests to create decoys. By changing certain parameters such as domain names, query types, or timing characteristics while maintaining others that ensure valid DNS protocol compliance, the system creates requests that appear legitimate but serve obfuscation purposes. This parameter transformation approach balances obfuscation effectiveness with traffic management.
Data Source
AI summary
DNS request obfuscation includes generating decoy domain name system (DNS) requests for obfuscating DNS request activity being handled by a private DNS server for an organization, and sending the decoy DNS requests to external DNS server(s) for resolution, receiving a DNS request seeking a DNS lookup for a client device, obfuscating the DNS request by sending, to an external DNS server of the external DNS server(s), the DNS request interspersed with at least some of the generated decoy DNS requests sent to the external DNS server, receiving, from the external DNS server, a DNS response to the sent DNS request, and providing the DNS response to a source of the DNS request.


