DNS Tunneling Detection via Subdomain Entropy Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures fail to effectively detect and prevent Domain Name System (DNS) tunneling attacks, which embed sensitive data in DNS requests, exploiting the lack of monitoring and blocking of DNS traffic by firewalls.
Innovation Solution
A method that extracts and analyzes DNS requests from data traffic to identify excessive sub-domain requests and data sizes, initiating preventive actions when predefined criteria are met to inhibit DNS tunneling, using a processor and network interface card to monitor and intervene in suspicious DNS traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If DNS traffic is allowed without monitoring to maintain network functionality, then network usability is improved, but security against DNS tunneling attacks deteriorates
Solution Approach 1:
The patent introduces a DNS filter as an intermediary component between the DNS client and DNS server. This filter intercepts DNS requests, analyzes them against configured policies and machine learning models, and selectively blocks malicious requests while allowing legitimate traffic to pass through. The intermediary approach maintains network functionality for legitimate DNS queries while preventing DNS tunneling attacks, resolving the contradiction between network usability and security.
2Reliability
If traditional security measures are used to protect against malware, then basic security is improved, but detection of DNS tunneling attacks deteriorates
Solution Approach 1:
The patent extracts DNS traffic analysis from traditional security measures and creates a dedicated DNS filtering system. By separating DNS monitoring functions from general-purpose antivirus and intrusion detection systems, the patent enables specialized detection capabilities including domain reputation checking, machine learning-based anomaly detection, and policy-based blocking. This extraction allows the system to detect DNS tunneling attacks that would be invisible to traditional security measures while maintaining basic security protections.
3Object-affected harmful factors
If all DNS requests are blocked to prevent tunneling, then security is improved, but legitimate network access deteriorates
Solution Approach 1:
The patent applies local quality by implementing differential filtering rules for different DNS requests. Instead of uniformly blocking all DNS traffic, the system analyzes each request's characteristics (domain reputation, request patterns, entropy levels, policy compliance) and applies selective blocking. Legitimate DNS requests that pass all security checks are allowed through, while only requests matching tunneling attack patterns are blocked. This localized, granular approach maintains legitimate network access while preventing attacks.
Data Source
AI summary
Methods, apparatus and computer software products for protecting a computing system implement embodiments of the present invention that include extracting, from data traffic transmitted over a data network connecting a plurality of computing devices to multiple Internet hosting services, respective sets of transmissions from the computing devices to the Internet hosting services, and identifying, in a given set of the transmissions from a given computing device, multiple domain name system (DNS) requests for an identical second-level domain (2LD) and for different respective sub-domains within the 2LD. A number of the different sub-domains within the 2LD and a data size of the multiple DNS requests are computed, and when the number of the different sub-domains and the data size of the multiple DNS requests exceed a predefined criterion, a preventive action is initiated to inhibit DNS tunneling from at least the given computing device.


