DNS Request Tracking for Machine Traffic Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DNS systems face challenges in identifying and mitigating machine-generated traffic, particularly from unregistered and non-existent domain names, which can lead to malicious activities and network congestion.

Innovation Solution

A method and system for tracking and classifying requests to resolve unregistered domain names, using heuristics and statistical approaches to map requestors to frequency counts, and applying thresholds to identify machine-generated traffic patterns, thereby distinguishing between legitimate and malicious sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If DNS systems log and analyze all requests to resolve unresolvable textual identifiers, then the ability to identify machine-generated traffic improves, but the complexity of the system increases

Engineering Contradiction:
Improveidentification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the analysis process into distinct components: logging requests, classifying textual identifiers into taxonomical sets, mapping requestors to frequency counts, and applying heuristics. This segmentation allows each component to be optimized independently while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary data structures including taxonomical sets for classifying textual identifiers, frequency count mappings, and heuristic rules. These intermediaries bridge the raw request data and the final identification results, enabling complex analysis through structured intermediate representations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If heuristics and statistical approaches are applied to identify machine-generated traffic, then the ability to distinguish malicious sources improves, but the computational resources required increase

Engineering Contradiction:
Improvetraffic identification reliabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary classification of textual identifiers into taxonomical sets and pre-computes frequency counts for requestors. This preliminary processing organizes data in advance, making the subsequent heuristic analysis more efficient and reducing computational resources needed during actual traffic identification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses the traffic data itself to generate identification criteria through heuristics and statistical analysis. The frequency counts and taxonomical classifications are derived automatically from the logged requests without requiring external manual configuration, enabling the system to self-optimize its identification accuracy.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If frequency counts and taxonomical sets are maintained for mapping requestors, then the precision of machine-generated traffic identification improves, but the data storage requirements increase

Engineering Contradiction:
Improvetraffic pattern recognition precisionVSAvoiddata storage volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies local quality by organizing data with specific properties at different levels: taxonomical sets group textual identifiers by local characteristics, frequency counts track requestors within specific taxonomical contexts, and heuristics apply localized analysis rules. This structured organization enables precise identification while storing only relevant data characteristics.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9053320B2Method of and apparatus for identifying requestors of machine-generated requests to resolve a textual identifier
Publication Date: 2015.06.09 VERISIGN INC
  • US9053320B2 patent drawing
  • US9053320B2 patent drawing
  • US9053320B2 patent drawing

AI summary

Methods and systems provide tracking or logging requests to resolve non-existent textual identifiers and classifying the textual identifier into a predefined set of taxonomical categories to support the detection of requestors of machine generated requests to resolve textual identifiers. Detection includes calculating a measure of probability based on the analysis and classification of prior textual identifier requests from a requestor.