DNS Server Classification via RFC Adherence and Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DNS server implementations rely on insecure communication mechanisms, making them vulnerable to attacks like DNS spoofing, which existing security solutions struggle to detect effectively, especially in resource-constrained devices and without requiring third-party validation or public key infrastructure.

Innovation Solution

A method using machine-learning techniques to classify and recognize DNS servers by evaluating their adherence to RFC specifications through specially crafted DNS queries, building a feature vector to assess trustworthiness and detect malicious servers without relying on third-party mechanisms or hardware changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DNS server implementations are used, then basic DNS functionality is provided, but security vulnerabilities to spoofing attacks exist

Engineering Contradiction:
ImproveDNS server trustworthinessVSAvoidDNS spoofing attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary classification and recognition of DNS servers before establishing connections. By proactively evaluating DNS servers using machine learning models and RFC compliance checks beforehand, the system prevents connections to potentially malicious servers, thereby improving reliability and preventing spoofing attacks before they can affect the client.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary classification system that acts as a mediator between the client and DNS server. This intermediary layer evaluates DNS servers using multiple features (RFC compliance, behavioral patterns, machine learning classification) and provides trust assessments, allowing clients to make informed decisions about which DNS servers to connect to without directly exposing themselves to spoofing risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If machine-learning techniques are implemented for DNS server classification, then detection accuracy improves, but computational demands increase

Engineering Contradiction:
ImproveDNS server classification accuracyVSAvoidcomputational energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the DNS server evaluation process into multiple independent features (RFC compliance checks, behavioral pattern analysis, machine learning classification). Each feature is evaluated separately and contributes to the overall classification, allowing the system to achieve high accuracy while managing computational complexity through modular, incremental processing rather than requiring all features to be computed simultaneously at full intensity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts evaluation parameters based on the classification stage. Different machine learning models and feature sets are applied at different stages of the classification process, optimizing the balance between accuracy and computational cost. The system can adjust the depth of analysis based on initial assessments, reducing unnecessary computational overhead while maintaining detection accuracy.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive RFC compliance checking is performed, then DNS server validation improves, but processing time increases

Engineering Contradiction:
ImproveDNS protocol compliance validationVSAvoidDNS server evaluation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial RFC compliance checking by focusing on the most critical and commonly violated RFC requirements rather than performing exhaustive validation of all RFC specifications. This selective approach evaluates the most relevant compliance aspects that are most indicative of malicious behavior, achieving sufficient validation reliability without the time cost of comprehensive checking of every possible RFC requirement.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11258753B2Method for detection of DNS spoofing servers using machine-learning techniques
Publication Date: 2022.02.22 SAMSUNG ELECTRONICSA AMAZONIA LTDA
  • US11258753B2 patent drawing
  • US11258753B2 patent drawing
  • US11258753B2 patent drawing

AI summary

The present disclosure is related to the network communication technology field and relates to a method for the classification and recognition of the Domain Name System (DNS) server, using machine-learning techniques. The classification process assigns a given DNS server as belonging to a preset of classes. For example, it enables to label a DNS server as either benign or malicious. On the other hand, the recognition process seeks the identification of the DNS server behavioral profile, which, consequently, can be used to assess the DNS server trustworthiness before DNS responses can be reliably used, e.g. identification of well-known and trusted DNS servers. Hence, the present patent, by the means of detecting the DNS server RFC adherence improves user security through the classification and recognition of DNS characteristics. Therefore, security solutions can use the DNS server characteristics to assess its trustworthiness before DNS responses can be reliably used.