DNS Traffic Profiling for Proactive Low and Slow DDoS Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network management tools are primarily reactive and focus on data at a myopic level, making them ineffective in detecting and preventing attacks like low and slow DDoS, which involve legitimate-looking traffic patterns, and resulting in delayed remediation strategies.
Innovation Solution
A method for profiling DNS traffic by analyzing DNS transaction data to generate profiling results that can guide proactive remediation strategies, identifying traffic patterns that elude conventional techniques, and enabling comprehensive monitoring of network activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If network management tools analyze Internet activities at later layers (application layer), then data collection is simplified, but detection time is delayed and remediation becomes ineffective
Solution Approach 1:
The patent applies preliminary action by analyzing DNS queries at the DNS layer (layer 3 in the transaction chain) rather than waiting for application layer activities to manifest. DNS queries occur before actual data transfer, allowing proactive detection and prevention of malicious activities before they execute, thus eliminating the time delay between attack initiation and detection.
2Measurement precision
If network management tools focus on individual data streams, then analysis precision is improved, but ability to detect patterns like low and slow DDoS is reduced
Solution Approach 1:
The patent merges the analysis of multiple individual DNS queries into a unified profile by examining temporal patterns, domain name relationships, and query frequency across different time windows. This aggregation approach enables detection of low and slow DDoS attacks that manifest as numerous legitimate-looking individual queries, where the collective pattern reveals the attack despite each individual query appearing normal.
3Productivity
If network management tools react to observed activities, then response actions are triggered, but proactive prevention of attacks is lost
Solution Approach 1:
The patent implements preliminary action by generating profiles from DNS query patterns before actual data transfer or malicious activities occur. The system creates predictive models that can identify attack indicators in the DNS layer, enabling proactive blocking or alerting before the attack executes at the application layer, thus transforming reactive remediation into proactive prevention.
Data Source
AI summary
In one embodiment, a profiling engine analyzes DNS transaction data that is logged by a recursive resolver to generate profiling results that are used to manage network activity. In operation, the profiling engine computes scores based on the DNS transaction data and scoring criteria. The profiling engine may compute any number of scores at any level of granularity. For example, the profiling engine may compute a score for each source IP address that is associated with the DNS transaction data. Subsequently, the profiling engine generates profiling results based on the scores and profiling criteria. Notably, DNS queries are typically the first step of longer transaction chains that result in the transfer of data to and from the network. Consequently, the profiling engine may provide more timely and comprehensive insight into network activities than conventional network management tools that analyze data at layers that are further down transaction chains.


