Network Address Rule Enforcement via DNS Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security devices face challenges in enforcing rules on network traffic, especially when it is encrypted, as deep packet inspection becomes difficult or impossible, and the presence of multiple security devices reduces reliability and increases processor usage.
Innovation Solution
A system that allows network security devices to enforce rules based on network address requests associated with network traffic, providing information to an I/O device to determine if the traffic satisfies the rules, thereby reducing the need for deep packet inspection and improving accuracy and resource conservation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If deep packet inspection is used to enforce rules on network traffic, then rule enforcement capability is improved, but processor usage increases and encrypted traffic cannot be inspected
Solution Approach 1:
The patent extracts the rule enforcement function from the deep packet inspection process and implements it at the network address resolution stage. By checking rules against application information and network addresses before traffic enters the network, the system enforces rules without requiring deep packet inspection of the actual traffic content, thereby reducing processor usage while maintaining rule enforcement capability.
Solution Approach 2:
The patent performs rule enforcement actions in advance, during the network address resolution phase before traffic is fully established. By determining whether traffic should be blocked, redirected, or allowed based on application information and network addresses prior to deep packet inspection, the system eliminates the need for resource-intensive inspection of encrypted or non-encrypted traffic content.
2Reliability
If multiple security devices are deployed to enforce rules, then rule enforcement coverage is improved, but reliability decreases and device complexity increases
Solution Approach 1:
The patent implements a universal rule enforcement mechanism that can handle multiple rule types (block, redirect, log, increment counter, pass) within a single device. The system evaluates application information and network addresses against stored rules to determine the appropriate action, consolidating what would traditionally require multiple specialized security devices into one multi-functional enforcement point.
3Measurement precision
If deep packet inspection is performed on encrypted traffic, then inspection accuracy is improved, but the ability to inspect encrypted traffic is lost
Solution Approach 1:
The patent performs rule evaluation at the network address resolution stage, before traffic encryption occurs. By checking whether application information and network addresses match stored rules during the DNS resolution phase, the system can enforce rules on both encrypted and non-encrypted traffic without requiring deep packet inspection of the encrypted content, maintaining both accuracy and encrypted traffic capability.
Data Source
AI summary
A first device may include one or more processors. The first device may receive a network address request to obtain a network address that is associated with an application. The network address request may include application information that identifies the application. The first device may determine that the application is associated with a rule. The first device may store the application information and information identifying the network address request. The first device may obtain the network address based on the network address request. The first device may determine that the network address is associated with the rule. The first device may provide the network address, the rule, and/or the application information to a second device, to permit the second device to enforce the rule, based on determining that the application is associated with the rule and determining that the network address is associated with the rule.


