DNS Traffic Anomaly Detection via Variance Ranking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DNS traffic analysis methods fail to effectively detect anomalies in DNS lookup data, which can indicate malicious activities or unusual behaviors, such as scams and botnets, due to limitations in characterizing network traffic patterns and mitigating double counting of queries from the same network segment.

Innovation Solution

A system and method for analyzing DNS lookup data by calculating traffic scores and variances to determine the rank of network addresses, which involves calculating traffic scores based on query records, geolocation percentages, and variances to identify potential anomalies, using a processor and memory to process and rank DNS data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current DNS traffic analysis methods are used, then basic DNS data can be processed, but anomalies in DNS lookup data cannot be effectively detected

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidcharacterization of network traffic patterns
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments DNS traffic analysis into multiple dimensions: temporal patterns (hourly, daily, weekly lookbacks), spatial patterns (geolocation percentages by country/region), and statistical metrics (traffic scores, variances, ranks). This segmentation allows complex anomaly detection to be broken down into manageable analytical components that can be processed systematically.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces multiple analytical dimensions beyond simple query counting: temporal dimension (time-based patterns), spatial dimension (geolocation distribution), and statistical dimension (variance and rank calculations). By analyzing traffic across these multiple dimensions, the system achieves more effective anomaly detection that cannot be accomplished through single-dimensional analysis alone.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Quantity of substance

If DNS lookup data is analyzed without proper correction, then query data is available, but double counting of queries from the same network segment occurs

Engineering Contradiction:
Improvequery data volumeVSAvoidaccuracy of traffic measurement
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent extracts and removes duplicate query counts by identifying queries from the same network segment (e.g., same /24 subnet) and correcting for double counting. This extraction of redundant data ensures that traffic measurements accurately reflect unique query sources rather than inflating numbers through repeated counting of the same network's queries.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the measurement parameter from simple query count to normalized traffic score that accounts for network segment duplication. By adjusting the calculation to subtract corrected duplicate counts, the system transforms raw query data into accurate traffic metrics that properly represent unique network traffic patterns.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If traffic scores are calculated without variance analysis, then basic traffic data is obtained, but inability to distinguish between normal and anomalous behavior exists

Engineering Contradiction:
Improvetraffic analysis speedVSAvoiddetection of unusual traffic behaviors
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent introduces dynamic variance analysis that compares current traffic patterns against historical baselines. By calculating variance (deviation from mean) and rank (relative position among domains), the system dynamically adapts to normal traffic variations while flagging anomalies. This dynamic approach allows the system to maintain high processing speed while achieving precise anomaly detection through statistical context.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9172716B2System and method for detecting DNS traffic anomalies
Publication Date: 2015.10.27 VERISIGN INC
  • US9172716B2 patent drawing
  • US9172716B2 patent drawing
  • US9172716B2 patent drawing

AI summary

Systems and methods for analyzing domain name system (“DNS”) lookup data perform operations that may include: calculating traffic scores for a network address based on a set of DNS lookup data associated with the network address, where the set of DNS lookup data includes a plurality of query records having one or more queried network addresses; calculating a first variance and a second variance for the network address based on the traffic scores for the network address; and determining a rank of the network address based on the first and second variances.