DNS Resolution Metrics for Adversary Infrastructure Role Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malicious software campaigns utilize dynamic infrastructure, such as domains and IP addresses, to evade detection and disrupt investigations, making it challenging to track and identify adversary networks effectively.

Innovation Solution

A system that collects and analyzes DNS resolution data to determine resolution metrics, including geographic locations and IP address usage patterns, to classify the role of adversary infrastructure and initiate remedy responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dynamic infrastructure is used by adversaries, then the survivability and mobility of malware are improved, but the ability to track and identify adversary networks deteriorates

Engineering Contradiction:
Improvesurvivability of malwareVSAvoiddifficulty of tracking adversary networks
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary analysis of DNS resolution data to establish baseline metrics and patterns before malicious activity fully develops. By pre-processing and pre-characterizing infrastructure data, the system creates a foundation for rapid detection and tracking of adversary networks using their own dynamic infrastructure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous monitoring and feedback loops that track DNS resolution patterns over time. By analyzing recurring patterns, frequency of resolutions, and geographic distributions, the system adapts to adversary behavior changes and maintains tracking capability despite infrastructure dynamics.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If dynamic domain infrastructure is used, then the mobility of malware is improved, but the traceability of adversary operations deteriorates

Engineering Contradiction:
Improvemobility of malwareVSAvoidloss of traceability information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system introduces DNS resolution metrics as an intermediary layer between the adversary's dynamic infrastructure and the tracking system. By measuring and characterizing DNS resolution patterns, the system creates a stable observational layer that preserves traceability information even as the underlying infrastructure changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system characterizes different infrastructure roles by identifying distinctive patterns in DNS resolution data, effectively 'coloring' different infrastructure types with unique behavioral signatures. This allows differentiation between command and control infrastructure, parking domains, and other roles despite dynamic IP addresses and domain names.

Inventive Principle:
Principle #32Color changes

3Device complexity

If infrastructure roles are not classified, then the complexity of response actions increases, but the precision of targeted responses decreases

Engineering Contradiction:
Improvecomplexity of response actionsVSAvoidprecision of infrastructure characterization
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The system segments adversary infrastructure into distinct roles (command and control, parking, data exfiltration, etc.) based on DNS resolution pattern analysis. By dividing the infrastructure into categorized segments, the system reduces the complexity of response actions while maintaining high precision in characterizing each infrastructure's specific function.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10044736B1Methods and apparatus for identifying and characterizing computer network infrastructure involved in malicious activity
Publication Date: 2018.08.07 THREATCONNECT INC

AI summary

In some embodiments, an apparatus includes a memory and a processor operatively coupled to the memory. The processor is configured to receive a set of domain name resolutions associated with a domain. Each domain name resolution from the set of domain name resolutions includes a mapping between a domain name and an Internet Protocol (IP) address. The processor is then configured to determine, based on the set of domain name resolutions, a set of resolution metrics associated with a first geolocation and a set of resolution metrics associated with a second geolocation. The processor is also configured to compare and identify a role of an adversary infrastructure at the first geolocation and a role of an adversary infrastructure at the second geolocation, and subsequently send a signal such that a remedy response associated with at least one of the set of IP addresses or the domain name is initiated.