Consolidated DNS Resolution Tree for Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network vulnerability detection systems fail to efficiently and effectively represent complex DNS resolution paths, leading to difficulties in identifying and addressing misconfigurations and vulnerabilities, particularly in large and dynamic networks with numerous virtual machines.

Innovation Solution

A method and system for generating and displaying a consolidated resolution tree of network nodes by creating tentative equivalence classes, processing edges and vertices, and retrieving nameservers from domain registration records to visualize DNS resolution paths in an interactive and comprehensible manner.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If DNS resolution paths are mapped to show all nodes in detail, then completeness of vulnerability detection is improved, but complexity of the representation increases making it difficult to comprehend

Engineering Contradiction:
Improvecompleteness of vulnerability detectionVSAvoidcomplexity of tree representation
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple name servers that provide equivalent DNS resolution paths into single representative nodes. Equivalence classes are created where name servers returning the same set of downstream name servers are consolidated, reducing the total number of nodes displayed while preserving complete vulnerability detection capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the DNS resolution tree into hierarchical levels and equivalence classes. By organizing name servers into discrete equivalence classes at each resolution level, the system maintains detailed vulnerability information while presenting a structured, manageable representation that avoids overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If all name servers in the DNS resolution path are displayed individually, then accuracy of vulnerability identification is improved, but ease of operation deteriorates due to difficulty in comprehension

Engineering Contradiction:
Improveaccuracy of vulnerability identificationVSAvoidease of comprehension
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

Name servers with identical resolution behavior are merged into single representative nodes within equivalence classes. This merging preserves accurate vulnerability identification because each equivalence class represents a complete set of servers with the same security characteristics, while dramatically improving ease of comprehension by reducing visual complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent employs visual indicators such as color coding to distinguish different equivalence classes and highlight vulnerable nodes. This visual encoding maintains accurate vulnerability information while making the tree structure much easier to comprehend at a glance.

Inventive Principle:
Principle #32Color changes

3Reliability

If the DNS resolution tree includes every possible node and connection, then reliability of security monitoring is improved, but device complexity increases making it difficult to manage

Engineering Contradiction:
Improvereliability of security monitoringVSAvoidcomplexity of tree management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges name servers into equivalence classes based on their resolution behavior, maintaining reliable security monitoring by ensuring each class represents complete security characteristics. This reduces the number of individual nodes that must be managed while preserving all necessary vulnerability detection capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Each equivalence class node serves multiple functions: representing multiple physical name servers, capturing complete vulnerability information, and providing a manageable unit for security analysis. This multi-functionality maintains reliability while reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11539662B2System and method for generation of simplified domain name server resolution trees
Publication Date: 2022.12.27 IONIX IO LTD
  • US11539662B2 patent drawing
  • US11539662B2 patent drawing
  • US11539662B2 patent drawing

AI summary

A system and method for generating and representing a consolidated resolution tree of a network are provided. The method includes receiving a target fully qualified domain name (FQDN); creating at least one tentative equivalence class (TEC) containing all the internet root domain name servers (DNS); processing the at least one TEC to determine respective consolidated edges and vertices; retrieving nameservers from domain registration records; determining whether additional TECs are to be generated for the retrieved nameserver(s); processing all new TECs to determine respective consolidated edges and vertices, when it is determined that new TECs are to be generated; and generating a resolution tree for display based on the consolidated edges and vertices.