DNS Threat Intelligence Automation for Accurate Domain Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DNS security systems face challenges in providing accurate and timely threat intelligence, leading to potential network outages due to false positives or failure to detect malicious domains, while traditional methods struggle to scale effectively.
Innovation Solution
The DNS Automated Intelligence System (DAISy) employs a self-sustaining architecture that aggregates and classifies DNS data, utilizes human-in-the-loop acceleration, and generates DNS-specific signatures to identify and block suspicious domains, providing real-time threat intelligence to DNS Detection and Response (DDR) systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If DNS security systems manually analyze and classify DNS resources, then detection accuracy is improved, but processing speed and scalability deteriorate
Solution Approach 1:
The system employs machine learning models that automatically learn and classify DNS resources without human intervention. The models are trained on historical DNS data and continuously improve their classification accuracy by self-adjusting parameters based on detected patterns, enabling both high accuracy and scalability simultaneously
Solution Approach 2:
Manual analysis processes are replaced with automated machine learning systems. The patent substitutes human expert analysis with algorithms that can process vast amounts of DNS data rapidly, maintaining detection accuracy through sophisticated pattern recognition while achieving scalable processing speeds
2Reliability
If DNS security systems aggregate data from multiple networks, then threat detection capability is improved, but system complexity and data processing burden increase
Solution Approach 1:
The system divides the complex task of multi-network DNS data analysis into modular components: data collection modules from individual networks, data normalization modules, feature extraction modules, and classification modules. This segmentation allows each component to handle specific aspects independently, reducing overall system complexity while maintaining comprehensive threat detection
Solution Approach 2:
The patent introduces intermediary processing layers including data normalization modules and feature extraction modules that act as mediators between raw multi-network DNS data and the final classification system. These intermediaries standardize diverse data formats and extract relevant features, simplifying the integration of data from multiple networks
3Loss of time
If DNS security systems generate real-time threat intelligence, then response time is improved, but computational resource consumption increases
Solution Approach 1:
The system performs preliminary actions by pre-training machine learning models on historical DNS data and maintaining updated threat intelligence databases in advance. When new DNS queries arrive, the pre-trained models can rapidly classify them using previously learned patterns, achieving real-time response without intensive computational resources
Solution Approach 2:
The patent applies partial action by focusing computational resources on analyzing only the most critical and suspicious DNS queries rather than processing every query with full computational intensity. The system uses lightweight initial filtering followed by more intensive analysis only when necessary, reducing overall resource consumption while maintaining rapid response times
Data Source
AI summary
Various techniques for providing a DNS automated intelligence solution are disclosed. In some embodiments, a DNS Automated Intelligence System (DAISy) is disclosed that includes a system designed to create threat intelligence for use in protective DNS, or DNS Detection and Response systems which control access to internet resources at a DNS resolver. The disclosed DAISy solution includes the ingestion of raw source data, the curation and refinement of this source data into specialized data sets used for identifying threats, active processes to increase visibility into internet domain names, and can also include human-in-the-loop acceleration that allows for rapid automation, and a modular incorporation of DNS-specific signatures for identification of suspicious domain names. The disclosed DAISy solution is self-sustaining, automated, and incorporates human guidance. Moreover, it is effective for scaling the detection of malicious and suspicious domains, which is not possible with existing traditional approaches to DNS security.


