DNS Security Network with Centralized Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current antivirus software and firewall technologies are inadequate in combating the increasing sophistication of malicious activities on the Internet, such as hacking, viruses, worms, and spyware, as they fail to provide a dynamic and global response to network security threats.

Innovation Solution

A DNS security network comprising DNS appliances and a security operations center (SOC) server that generates and enforces security policies to detect and respond to prohibited activities, such as malicious queries, by replacing or discarding answers to client queries from unauthorized or malicious sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus software and firewall technologies are employed as protective measures, then network security is improved, but the sophistication of hackers continues to increase making these measures inadequate

Engineering Contradiction:
Improvenetwork securityVSAvoidresponse to sophisticated threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically generates and updates security policies based on real-time telemetry data from DNS appliances. The SOC server continuously monitors network activity, identifies patterns indicating malicious behavior, and automatically updates security policies to block new threats, making the security system adaptive to evolving hacker sophistication

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements a feedback loop where DNS appliances send telemetry data about client queries to the SOC server, which analyzes this data to identify malicious patterns and generates updated security policies that are fed back to the DNS appliances for enforcement, creating a continuous improvement cycle

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If DNS security network with SOC server is implemented, then dynamic and global response to threats is achieved, but system complexity increases

Engineering Contradiction:
Improvedynamic response capabilityVSAvoidnetwork architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system is divided into separate functional components: DNS appliances handle local query processing and telemetry collection, while the SOC server handles centralized policy generation and distribution. This segmentation allows each component to focus on specific functions, making the overall complex system more manageable and scalable

Inventive Principle:
Principle #1Segmentation

3Reliability

If security policies are generated and enforced by DNS appliances, then malicious activities are detected and mitigated, but processing time for DNS queries increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidDNS query response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The SOC server generates and distributes security policies in advance based on analyzed telemetry data and threat patterns. These pre-computed policies are stored in the DNS appliances before actual queries occur, allowing fast lookup and enforcement without real-time analysis delays

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8375120B2Domain name system security network
Publication Date: 2013.02.12 TREND MICRO INC
  • US8375120B2 patent drawing
  • US8375120B2 patent drawing
  • US8375120B2 patent drawing

AI summary

In one embodiment, a DNS security network includes several DNS appliances and a security operations center (SOC) server computer. The SOC server computer may receive telemetry data from the DNS appliances, the telemetry data comprising information about DNS client queries received in the respective DNS appliances. From the telemetry data, the SOC server computer may generate security policies for distribution to the DNS appliances. The security policies may be used by the DNS appliances to determine whether a DNS client query is originated by a client computer performing a prohibited activity (e.g., sending spam, communicating with a zombie control computer, navigating to a prohibited website, etc.). An answer to a client query may be replaced or discarded altogether in cases where the originator is performing a prohibited activity.