DNS Security Gateway Intermediary for Tunneling Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of the DNS protocol by hackers for covert channels compromises network security, as malicious actors exploit its decentralized nature and user-defined data fields to exfiltrate data and transmit commands undetected through DNS tunneling techniques.

Innovation Solution

Implementing a DNS tunneling detection operation by a processor that analyzes DNS queries and responses to identify and prevent DNS tunneling activity, using cognitive and contextual computing techniques to detect anomalies and thwart data exfiltration, and disrupting communication mechanisms outside of bona fide DNS communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If DNS protocol is used for name resolution, then network communication efficiency is improved, but network security deteriorates due to DNS tunneling exploitation

Engineering Contradiction:
Improvenetwork communication efficiencyVSAvoidDNS tunneling exploitation
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

A DNS security gateway is introduced as an intermediary component between the DNS resolver and the DNS name server. The gateway intercepts DNS queries, performs security analysis to detect tunneling activities, and decides whether to allow or block the queries. This mediator approach maintains the efficiency of legitimate DNS communications while preventing malicious DNS tunneling exploitation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If DNS queries are monitored and analyzed, then detection precision is improved, but processing time increases

Engineering Contradiction:
Improvedetection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The DNS security gateway applies partial analysis by focusing detection efforts on queries that exhibit suspicious characteristics. Rather than performing exhaustive analysis on every DNS query, the system uses heuristics to identify potentially malicious queries and applies deeper inspection only to those cases, thereby maintaining high detection precision while minimizing overall processing time delays.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10097568B2DNS tunneling prevention
Publication Date: 2018.10.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10097568B2 patent drawing
  • US10097568B2 patent drawing
  • US10097568B2 patent drawing

AI summary

Embodiments for domain name service (DNS) tunneling prevention by a processor. A DNS tunneling detection operation is requested to be performed upon receiving a DNS query. A response is generated based on the DNS tunneling detection operation such that the DNS tunneling detection operation indicates in the response that the DNS query for a domain name is associated with DNS tunneling activity.