DNS Requests as Security Reporting Vehicle

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures often block reporting information intended for central security facilities, as it is misinterpreted by chokepoint firewalls, hindering the detection and response to widespread security breaches like spam or malware distribution.

Innovation Solution

Utilizing Domain Name Service (DNS) requests as a reporting vehicle, where digital fingerprints generated by algorithms like MD5 are embedded in DNS queries, allowing reporting information to bypass conventional security rules and reach central facilities effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security rules are applied at chokepoint firewalls to block spam and malware, then network security is improved, but reporting information intended for central security facilities is blocked

Engineering Contradiction:
Improvenetwork securityVSAvoidreporting information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent uses DNS requests as an intermediary carrier to transmit reporting information. Instead of sending reporting data through conventional security channels that are blocked by firewalls, the system embeds reporting information within DNS queries, which are permitted to pass through the firewall. This intermediary approach allows reporting information to reach the central security facility without being intercepted by security rules designed to block spam and malware.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If chokepoint firewalls enforce security rules to prevent spam and malware distribution, then harmful factors are reduced, but legitimate reporting traffic is misinterpreted and blocked

Engineering Contradiction:
Improvespam and malware distributionVSAvoidreporting information transmission
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies different treatment to different types of traffic at the firewall. DNS requests containing reporting information are identified and permitted to pass through, while other traffic subject to security rules continues to be blocked if it matches spam or malware patterns. This local quality approach allows the firewall to maintain its security function while creating a specific exception for authenticated DNS reporting traffic.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If centralized security facilities receive reporting information to identify security breaches, then detection capability is improved, but transmission of reporting data is blocked by independent network security devices

Engineering Contradiction:
Improvedetection of security breachesVSAvoidreporting data
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent makes the DNS request serve multiple functions: it performs the standard function of domain name resolution while simultaneously carrying reporting information about security events. This multi-functionality allows the same communication channel to be used for both legitimate DNS operations and security reporting, eliminating the need for separate reporting channels that would be blocked by firewalls.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8843612B2Distributed frequency data collection via DNS networking
Publication Date: 2014.09.23 BARRACUDA NETWORKS INC
  • US8843612B2 patent drawing
  • US8843612B2 patent drawing
  • US8843612B2 patent drawing

AI summary

Domain Name Service (DNS) requests are used as the reporting vehicle for ensuring that security-related information can be transferred from a network. As one possibility, a central facility for a security provider may maintain a data collection capability that is based upon receiving the DNS requests containing the information being reported. In an email application, if a data block is embedded within or attached to an email message, an algorithm is applied to the data block to generate an indicator that is specifically related to the contents of the data block. As one possibility, the algorithm may generate a hash that provides a “digital fingerprint” having a reasonable likelihood that the hash is unique to the data block. By embedding the hash within a DNS request, the request becomes a report that the data block has been accessed.