Domain Name Attack Countermeasure Determination via Multi-Stage Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing countermeasures for malicious domain names lack the ability to objectively determine appropriate countermeasures for each domain name, leading to potential unauthorized filtering of legitimate services and ineffective long-term solutions due to the dynamic nature of attackers using new domain names.

Innovation Solution

An attack countermeasure determination apparatus that receives a domain name, acquires setting, registration, and external information, and uses this feature information to specify a category for the domain name, determining countermeasures in a stepwise manner, including the means, granularity, and expiration date, to implement targeted and timely countermeasures without blocking authorized services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a countermeasure is implemented to filter communication addressed to malicious domain names by specifying them, then cyber attacks are prevented, but legitimate services may be erroneously filtered

Engineering Contradiction:
Improveattack prevention effectivenessVSAvoiderroneous filtering of legitimate services
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The invention segments the countermeasure approach by implementing a multi-stage determination process. First, the system determines whether a domain name is malicious using multiple detection methods (blacklist matching, DNS query analysis, web access verification). Only after confirming maliciousness through these segmented stages does the system apply filtering, thereby reducing erroneous blocking of legitimate services while maintaining effective attack prevention

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces an intermediary determination apparatus that acts as a mediator between domain name registration and filtering execution. This intermediary system performs comprehensive verification including checking multiple DNS servers, analyzing DNS query patterns, and verifying web access before confirming malicious status. This intermediary layer prevents hasty filtering decisions that could erroneously block legitimate services

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a countermeasure is implemented to filter malicious domain names uniformly, then attack responses are simplified, but the countermeasure becomes ineffective against dynamically changing attacker domain names

Engineering Contradiction:
Improvecountermeasure implementation simplicityVSAvoidresponse effectiveness against dynamic attacker behavior
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The invention implements a dynamic countermeasure system that continuously adapts to changing attacker behaviors. The determination apparatus periodically re-evaluates domain names, updates blacklist information, and adjusts filtering criteria based on observed DNS query patterns and web access characteristics. This dynamic approach maintains operational simplicity while effectively countering attackers who frequently change domain names

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where DNS query analysis results, web access verification outcomes, and blacklist matching data continuously feed back into the determination process. This feedback loop enables the system to learn from observed patterns, refine its malicious domain identification accuracy, and adapt filtering strategies to counter evolving attack methods while maintaining simple operational procedures

Inventive Principle:
Principle #23Feedback

3Speed

If filtering is applied at the DNS communication path, then attack response speed is improved, but authorized advertisement delivery and other legitimate services are blocked

Engineering Contradiction:
Improveattack response speedVSAvoidauthorized service delivery
Core Design Contradiction:
SpeedVSProductivity

Solution Approach 1:

The invention applies local quality by implementing targeted filtering only for confirmed malicious domain names rather than uniform filtering across all DNS traffic. The determination apparatus identifies specific malicious domains through multi-stage verification and applies filtering selectively to those cases, while allowing authorized advertisement delivery and other legitimate services to proceed unimpeded through the DNS communication path

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary verification actions before applying filtering, including blacklist matching, DNS query pattern analysis, and web access verification. This preliminary action ensures that only genuinely malicious domain names are filtered, preventing premature blocking of authorized services like advertisement delivery while maintaining fast response to confirmed threats

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11652845B2Attack countermeasure determination apparatus, attack countermeasure determination method, and attack countermeasure determination program
Publication Date: 2023.05.16 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11652845B2 patent drawing
  • US11652845B2 patent drawing
  • US11652845B2 patent drawing

AI summary

An attack countermeasure determination includes a domain name input unit that receives any domain name as input, and acquires setting information corresponding to the domain name, registration information corresponding to the domain name, and external information corresponding to an internet protocol (IP) address corresponding to the domain name, as feature information on the domain name, an attack countermeasure determination unit that specifies a pre-designated category for the domain name on the basis of the feature information and determines, in a stepwise manner, an attack countermeasure against the domain name in accordance with the specified category, and an attack countermeasure information output unit that outputs attack countermeasure information corresponding to the attack countermeasure.