DNS Traffic Profiling for Proactive Low and Slow DDoS Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network management tools are primarily reactive and focus on data at a myopic level, making them ineffective in detecting and preventing attacks like low and slow DDoS, which involve legitimate-looking traffic patterns, and resulting in delayed remediation strategies.

Innovation Solution

A method for profiling DNS traffic by analyzing DNS transaction data to generate profiling results that can guide proactive remediation strategies, identifying traffic patterns that elude conventional techniques, and enabling comprehensive monitoring of network activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network management tools analyze Internet activities at later layers (application layer), then data collection is simplified, but detection time is delayed and remediation becomes ineffective

Engineering Contradiction:
Improvedata collection simplicityVSAvoiddetection time delay
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent applies preliminary action by analyzing DNS queries at the DNS layer (layer 3 in the transaction chain) rather than waiting for application layer activities to manifest. DNS queries occur before actual data transfer, allowing proactive detection and prevention of malicious activities before they execute, thus eliminating the time delay between attack initiation and detection.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If network management tools focus on individual data streams, then analysis precision is improved, but ability to detect patterns like low and slow DDoS is reduced

Engineering Contradiction:
Improveindividual activity analysis precisionVSAvoidattack pattern detection difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent merges the analysis of multiple individual DNS queries into a unified profile by examining temporal patterns, domain name relationships, and query frequency across different time windows. This aggregation approach enables detection of low and slow DDoS attacks that manifest as numerous legitimate-looking individual queries, where the collective pattern reveals the attack despite each individual query appearing normal.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If network management tools react to observed activities, then response actions are triggered, but proactive prevention of attacks is lost

Engineering Contradiction:
Improveremediation action executionVSAvoidattack prevention effectiveness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary action by generating profiles from DNS query patterns before actual data transfer or malicious activities occur. The system creates predictive models that can identify attack indicators in the DNS layer, enabling proactive blocking or alerting before the attack executes at the application layer, thus transforming reactive remediation into proactive prevention.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12184688B2Profiling domain name system (DNS) traffic
Publication Date: 2024.12.31 VERISIGN INC
  • US12184688B2 patent drawing
  • US12184688B2 patent drawing
  • US12184688B2 patent drawing

AI summary

In one embodiment, a profiling engine analyzes DNS transaction data that is logged by a recursive resolver to generate profiling results that are used to manage network activity. In operation, the profiling engine computes scores based on the DNS transaction data and scoring criteria. The profiling engine may compute any number of scores at any level of granularity. For example, the profiling engine may compute a score for each source IP address that is associated with the DNS transaction data. Subsequently, the profiling engine generates profiling results based on the scores and profiling criteria. Notably, DNS queries are typically the first step of longer transaction chains that result in the transfer of data to and from the network. Consequently, the profiling engine may provide more timely and comprehensive insight into network activities than conventional network management tools that analyze data at layers that are further down transaction chains.