DNS Traffic Anomaly Detection via Variance Ranking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current DNS traffic analysis methods fail to effectively detect anomalies in DNS lookup data, which can indicate malicious activities or unusual behaviors, such as scams and botnets, due to limitations in characterizing network traffic patterns and mitigating double counting of queries from the same network segment.
Innovation Solution
A system and method for analyzing DNS lookup data by calculating traffic scores and variances to determine the rank of network addresses, which involves calculating traffic scores based on query records, geolocation percentages, and variances to identify potential anomalies, using a processor and memory to process and rank DNS data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current DNS traffic analysis methods are used, then basic DNS data can be processed, but anomalies in DNS lookup data cannot be effectively detected
Solution Approach 1:
The patent segments DNS traffic analysis into multiple dimensions: temporal patterns (hourly, daily, weekly lookbacks), spatial patterns (geolocation percentages by country/region), and statistical metrics (traffic scores, variances, ranks). This segmentation allows complex anomaly detection to be broken down into manageable analytical components that can be processed systematically.
Solution Approach 2:
The patent introduces multiple analytical dimensions beyond simple query counting: temporal dimension (time-based patterns), spatial dimension (geolocation distribution), and statistical dimension (variance and rank calculations). By analyzing traffic across these multiple dimensions, the system achieves more effective anomaly detection that cannot be accomplished through single-dimensional analysis alone.
2Quantity of substance
If DNS lookup data is analyzed without proper correction, then query data is available, but double counting of queries from the same network segment occurs
Solution Approach 1:
The patent extracts and removes duplicate query counts by identifying queries from the same network segment (e.g., same /24 subnet) and correcting for double counting. This extraction of redundant data ensures that traffic measurements accurately reflect unique query sources rather than inflating numbers through repeated counting of the same network's queries.
Solution Approach 2:
The patent changes the measurement parameter from simple query count to normalized traffic score that accounts for network segment duplication. By adjusting the calculation to subtract corrected duplicate counts, the system transforms raw query data into accurate traffic metrics that properly represent unique network traffic patterns.
3Productivity
If traffic scores are calculated without variance analysis, then basic traffic data is obtained, but inability to distinguish between normal and anomalous behavior exists
Solution Approach 1:
The patent introduces dynamic variance analysis that compares current traffic patterns against historical baselines. By calculating variance (deviation from mean) and rank (relative position among domains), the system dynamically adapts to normal traffic variations while flagging anomalies. This dynamic approach allows the system to maintain high processing speed while achieving precise anomaly detection through statistical context.
Data Source
AI summary
Systems and methods for analyzing domain name system (“DNS”) lookup data perform operations that may include: calculating traffic scores for a network address based on a set of DNS lookup data associated with the network address, where the set of DNS lookup data includes a plurality of query records having one or more queried network addresses; calculating a first variance and a second variance for the network address based on the traffic scores for the network address; and determining a rank of the network address based on the first and second variances.


