Network Address Rule Enforcement via DNS Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security devices face challenges in enforcing rules on network traffic, especially when it is encrypted, as deep packet inspection becomes difficult or impossible, and the presence of multiple security devices reduces reliability and increases processor usage.

Innovation Solution

A system that allows network security devices to enforce rules based on network address requests associated with network traffic, providing information to an I/O device to determine if the traffic satisfies the rules, thereby reducing the need for deep packet inspection and improving accuracy and resource conservation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deep packet inspection is used to enforce rules on network traffic, then rule enforcement capability is improved, but processor usage increases and encrypted traffic cannot be inspected

Engineering Contradiction:
Improverule enforcement capabilityVSAvoidprocessor usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the rule enforcement function from the deep packet inspection process and implements it at the network address resolution stage. By checking rules against application information and network addresses before traffic enters the network, the system enforces rules without requiring deep packet inspection of the actual traffic content, thereby reducing processor usage while maintaining rule enforcement capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs rule enforcement actions in advance, during the network address resolution phase before traffic is fully established. By determining whether traffic should be blocked, redirected, or allowed based on application information and network addresses prior to deep packet inspection, the system eliminates the need for resource-intensive inspection of encrypted or non-encrypted traffic content.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple security devices are deployed to enforce rules, then rule enforcement coverage is improved, but reliability decreases and device complexity increases

Engineering Contradiction:
Improverule enforcement coverageVSAvoidnumber of security devices
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal rule enforcement mechanism that can handle multiple rule types (block, redirect, log, increment counter, pass) within a single device. The system evaluates application information and network addresses against stored rules to determine the appropriate action, consolidating what would traditionally require multiple specialized security devices into one multi-functional enforcement point.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If deep packet inspection is performed on encrypted traffic, then inspection accuracy is improved, but the ability to inspect encrypted traffic is lost

Engineering Contradiction:
Improveinspection accuracyVSAvoidencrypted traffic inspection capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent performs rule evaluation at the network address resolution stage, before traffic encryption occurs. By checking whether application information and network addresses match stored rules during the DNS resolution phase, the system can enforce rules on both encrypted and non-encrypted traffic without requiring deep packet inspection of the encrypted content, maintaining both accuracy and encrypted traffic capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10560480B1Rule enforcement based on network address requests
Publication Date: 2020.02.11 JUNIPER NETWORKS INC
  • US10560480B1 patent drawing
  • US10560480B1 patent drawing
  • US10560480B1 patent drawing

AI summary

A first device may include one or more processors. The first device may receive a network address request to obtain a network address that is associated with an application. The network address request may include application information that identifies the application. The first device may determine that the application is associated with a rule. The first device may store the application information and information identifying the network address request. The first device may obtain the network address based on the network address request. The first device may determine that the network address is associated with the rule. The first device may provide the network address, the rule, and/or the application information to a second device, to permit the second device to enforce the rule, based on determining that the application is associated with the rule and determining that the network address is associated with the rule.