Cognitive DNS Tunneling Detection via Machine Learning Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems (IDS) and intrusion prevention systems (IPS) are ineffective in detecting malicious DNS traffic due to the open nature of the DNS protocol and the difficulty in distinguishing it from benign communications, making it challenging to identify and prevent data exfiltration and other malicious activities.

Innovation Solution

A cognitive and contextual detection method employing advanced machine-learning techniques is developed to analyze DNS traffic by constructing input features from packet metadata, classifying transmissions as malicious, and generating notifications to cease malicious DNS tunneling, utilizing trained classification models and heuristics to identify suspicious DNS protocol attributes and traffic parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional intrusion detection systems are used to monitor DNS traffic, then network security is maintained, but malicious DNS tunneling cannot be detected due to the open nature of the DNS protocol

Engineering Contradiction:
Improvedetection accuracyVSAvoidmalicious traffic identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent transforms DNS traffic analysis from traditional signature-based detection to machine learning-based classification by changing the parameters from simple pattern matching to complex feature analysis including packet size, frequency, entropy, and contextual metadata, enabling reliable detection of malicious tunneling while maintaining protocol openness

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional mechanical intrusion detection mechanisms with cognitive classification models that use advanced machine learning techniques to automatically distinguish malicious DNS tunneling from benign traffic, overcoming the limitations of rule-based systems

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If DNS protocol openness is maintained for legitimate communications, then network functionality is preserved, but malicious activities can masquerade as benign traffic

Engineering Contradiction:
Improveprotocol flexibilityVSAvoidmalicious data exchange
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cognitive classification model as an intermediary layer between DNS clients and servers, which analyzes traffic characteristics and metadata to identify malicious tunneling attempts while allowing legitimate DNS communications to proceed uninterrupted, thus maintaining protocol flexibility while blocking harmful activities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments DNS traffic analysis into multiple independent feature dimensions including packet metadata, traffic patterns, entropy measurements, and contextual information, allowing the system to evaluate each aspect separately and make more accurate classification decisions

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If advanced machine-learning techniques are deployed for DNS traffic analysis, then detection precision is improved, but system complexity increases

Engineering Contradiction:
Improvemalicious classification accuracyVSAvoiddetection system architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-training cognitive classification models with extensive DNS traffic data and pre-computing metadata features before deployment, so that during actual operation the system can quickly classify malicious traffic without real-time complex processing, reducing operational system complexity while maintaining high detection precision

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10397253B2Cognitive and contextual detection of malicious DNS
Publication Date: 2019.08.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10397253B2 patent drawing
  • US10397253B2 patent drawing
  • US10397253B2 patent drawing

AI summary

From a record of a packet in a Domain Name System (DNS) communication between a DNS client and a DNS server, an input feature is constructed. Using the packet, a metadata item supporting the input feature is computed. Using a processor and a memory to execute a trained cognitive classification model, and by supplying the input feature and the supporting metadata item as inputs to the cognitive classification model, a transmission of the packet is classified as malicious use of DNS tunneling between the DNS client and the DNS server. From the cognitive classification model, a classification of the packet as malicious, and a confidence value in the malicious classification are output. By generating a notification, the DNS client is caused to cease the malicious use of the DNS tunneling.