DNS Threat Intelligence Automation for Accurate Domain Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DNS security systems face challenges in providing accurate and timely threat intelligence, leading to potential network outages due to false positives or failure to detect malicious domains, while traditional methods struggle to scale effectively.

Innovation Solution

The DNS Automated Intelligence System (DAISy) employs a self-sustaining architecture that aggregates and classifies DNS data, utilizes human-in-the-loop acceleration, and generates DNS-specific signatures to identify and block suspicious domains, providing real-time threat intelligence to DNS Detection and Response (DDR) systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If DNS security systems manually analyze and classify DNS resources, then detection accuracy is improved, but processing speed and scalability deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system employs machine learning models that automatically learn and classify DNS resources without human intervention. The models are trained on historical DNS data and continuously improve their classification accuracy by self-adjusting parameters based on detected patterns, enabling both high accuracy and scalability simultaneously

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual analysis processes are replaced with automated machine learning systems. The patent substitutes human expert analysis with algorithms that can process vast amounts of DNS data rapidly, maintaining detection accuracy through sophisticated pattern recognition while achieving scalable processing speeds

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If DNS security systems aggregate data from multiple networks, then threat detection capability is improved, but system complexity and data processing burden increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the complex task of multi-network DNS data analysis into modular components: data collection modules from individual networks, data normalization modules, feature extraction modules, and classification modules. This segmentation allows each component to handle specific aspects independently, reducing overall system complexity while maintaining comprehensive threat detection

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary processing layers including data normalization modules and feature extraction modules that act as mediators between raw multi-network DNS data and the final classification system. These intermediaries standardize diverse data formats and extract relevant features, simplifying the integration of data from multiple networks

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If DNS security systems generate real-time threat intelligence, then response time is improved, but computational resource consumption increases

Engineering Contradiction:
Improveresponse timeVSAvoidcomputational resource consumption
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by pre-training machine learning models on historical DNS data and maintaining updated threat intelligence databases in advance. When new DNS queries arrive, the pre-trained models can rapidly classify them using previously learned patterns, achieving real-time response without intensive computational resources

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by focusing computational resources on analyzing only the most critical and suspicious DNS queries rather than processing every query with full computational intensity. The system uses lightweight initial filtering followed by more intensive analysis only when necessary, reducing overall resource consumption while maintaining rapid response times

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12621316B2DNS automated intelligence
Publication Date: 2026.05.05 INFOBLOX INC
  • US12621316B2 patent drawing
  • US12621316B2 patent drawing
  • US12621316B2 patent drawing

AI summary

Various techniques for providing a DNS automated intelligence solution are disclosed. In some embodiments, a DNS Automated Intelligence System (DAISy) is disclosed that includes a system designed to create threat intelligence for use in protective DNS, or DNS Detection and Response systems which control access to internet resources at a DNS resolver. The disclosed DAISy solution includes the ingestion of raw source data, the curation and refinement of this source data into specialized data sets used for identifying threats, active processes to increase visibility into internet domain names, and can also include human-in-the-loop acceleration that allows for rapid automation, and a modular incorporation of DNS-specific signatures for identification of suspicious domain names. The disclosed DAISy solution is self-sustaining, automated, and incorporates human guidance. Moreover, it is effective for scaling the detection of malicious and suspicious domains, which is not possible with existing traditional approaches to DNS security.