DNS Tunneling Detection via Subdomain Entropy Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures fail to effectively detect and prevent Domain Name System (DNS) tunneling attacks, which embed sensitive data in DNS requests, exploiting the lack of monitoring and blocking of DNS traffic by firewalls.

Innovation Solution

A method that extracts and analyzes DNS requests from data traffic to identify excessive sub-domain requests and data sizes, initiating preventive actions when predefined criteria are met to inhibit DNS tunneling, using a processor and network interface card to monitor and intervene in suspicious DNS traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If DNS traffic is allowed without monitoring to maintain network functionality, then network usability is improved, but security against DNS tunneling attacks deteriorates

Engineering Contradiction:
Improvenetwork usabilityVSAvoidDNS tunneling attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a DNS filter as an intermediary component between the DNS client and DNS server. This filter intercepts DNS requests, analyzes them against configured policies and machine learning models, and selectively blocks malicious requests while allowing legitimate traffic to pass through. The intermediary approach maintains network functionality for legitimate DNS queries while preventing DNS tunneling attacks, resolving the contradiction between network usability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional security measures are used to protect against malware, then basic security is improved, but detection of DNS tunneling attacks deteriorates

Engineering Contradiction:
Improvebasic securityVSAvoidDNS tunneling detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extracts DNS traffic analysis from traditional security measures and creates a dedicated DNS filtering system. By separating DNS monitoring functions from general-purpose antivirus and intrusion detection systems, the patent enables specialized detection capabilities including domain reputation checking, machine learning-based anomaly detection, and policy-based blocking. This extraction allows the system to detect DNS tunneling attacks that would be invisible to traditional security measures while maintaining basic security protections.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If all DNS requests are blocked to prevent tunneling, then security is improved, but legitimate network access deteriorates

Engineering Contradiction:
ImproveDNS tunneling preventionVSAvoidlegitimate network access
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies local quality by implementing differential filtering rules for different DNS requests. Instead of uniformly blocking all DNS traffic, the system analyzes each request's characteristics (domain reputation, request patterns, entropy levels, policy compliance) and applies selective blocking. Legitimate DNS requests that pass all security checks are allowed through, while only requests matching tunneling attack patterns are blocked. This localized, granular approach maintains legitimate network access while preventing attacks.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11606385B2Behavioral DNS tunneling identification
Publication Date: 2023.03.14 PALO ALTO NETWORKS INC
  • US11606385B2 patent drawing
  • US11606385B2 patent drawing
  • US11606385B2 patent drawing

AI summary

Methods, apparatus and computer software products for protecting a computing system implement embodiments of the present invention that include extracting, from data traffic transmitted over a data network connecting a plurality of computing devices to multiple Internet hosting services, respective sets of transmissions from the computing devices to the Internet hosting services, and identifying, in a given set of the transmissions from a given computing device, multiple domain name system (DNS) requests for an identical second-level domain (2LD) and for different respective sub-domains within the 2LD. A number of the different sub-domains within the 2LD and a data size of the multiple DNS requests are computed, and when the number of the different sub-domains and the data size of the multiple DNS requests exceed a predefined criterion, a preventive action is initiated to inhibit DNS tunneling from at least the given computing device.