Domain Name Attack Countermeasure Determination via Multi-Stage Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing countermeasures for malicious domain names lack the ability to objectively determine appropriate countermeasures for each domain name, leading to potential unauthorized filtering of legitimate services and ineffective long-term solutions due to the dynamic nature of attackers using new domain names.
Innovation Solution
An attack countermeasure determination apparatus that receives a domain name, acquires setting, registration, and external information, and uses this feature information to specify a category for the domain name, determining countermeasures in a stepwise manner, including the means, granularity, and expiration date, to implement targeted and timely countermeasures without blocking authorized services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a countermeasure is implemented to filter communication addressed to malicious domain names by specifying them, then cyber attacks are prevented, but legitimate services may be erroneously filtered
Solution Approach 1:
The invention segments the countermeasure approach by implementing a multi-stage determination process. First, the system determines whether a domain name is malicious using multiple detection methods (blacklist matching, DNS query analysis, web access verification). Only after confirming maliciousness through these segmented stages does the system apply filtering, thereby reducing erroneous blocking of legitimate services while maintaining effective attack prevention
Solution Approach 2:
The invention introduces an intermediary determination apparatus that acts as a mediator between domain name registration and filtering execution. This intermediary system performs comprehensive verification including checking multiple DNS servers, analyzing DNS query patterns, and verifying web access before confirming malicious status. This intermediary layer prevents hasty filtering decisions that could erroneously block legitimate services
2Ease of operation
If a countermeasure is implemented to filter malicious domain names uniformly, then attack responses are simplified, but the countermeasure becomes ineffective against dynamically changing attacker domain names
Solution Approach 1:
The invention implements a dynamic countermeasure system that continuously adapts to changing attacker behaviors. The determination apparatus periodically re-evaluates domain names, updates blacklist information, and adjusts filtering criteria based on observed DNS query patterns and web access characteristics. This dynamic approach maintains operational simplicity while effectively countering attackers who frequently change domain names
Solution Approach 2:
The system incorporates feedback mechanisms where DNS query analysis results, web access verification outcomes, and blacklist matching data continuously feed back into the determination process. This feedback loop enables the system to learn from observed patterns, refine its malicious domain identification accuracy, and adapt filtering strategies to counter evolving attack methods while maintaining simple operational procedures
3Speed
If filtering is applied at the DNS communication path, then attack response speed is improved, but authorized advertisement delivery and other legitimate services are blocked
Solution Approach 1:
The invention applies local quality by implementing targeted filtering only for confirmed malicious domain names rather than uniform filtering across all DNS traffic. The determination apparatus identifies specific malicious domains through multi-stage verification and applies filtering selectively to those cases, while allowing authorized advertisement delivery and other legitimate services to proceed unimpeded through the DNS communication path
Solution Approach 2:
The system performs preliminary verification actions before applying filtering, including blacklist matching, DNS query pattern analysis, and web access verification. This preliminary action ensures that only genuinely malicious domain names are filtered, preventing premature blocking of authorized services like advertisement delivery while maintaining fast response to confirmed threats
Data Source
AI summary
An attack countermeasure determination includes a domain name input unit that receives any domain name as input, and acquires setting information corresponding to the domain name, registration information corresponding to the domain name, and external information corresponding to an internet protocol (IP) address corresponding to the domain name, as feature information on the domain name, an attack countermeasure determination unit that specifies a pre-designated category for the domain name on the basis of the feature information and determines, in a stepwise manner, an attack countermeasure against the domain name in accordance with the specified category, and an attack countermeasure information output unit that outputs attack countermeasure information corresponding to the attack countermeasure.


