Dynamic Hostname Generation for Network Asset Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional access methods for network assets are vulnerable to malicious activities due to static architectures, which do not effectively prevent exposure to denial of service attacks and unauthorized access.
Innovation Solution
A system utilizing a fully qualified domain name with a unique and temporary hostname, generated by both client and server modules, creates temporary virtual machines that act as servers or firewalls, dynamically updating DNS records to enhance security by changing access points periodically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional static access methods are used for network assets, then ease of operation is improved, but security is worsened due to exposure to malicious activities
Solution Approach 1:
The patent implements dynamic access points by periodically generating new Fully Qualified Domain Names (FQDNs) that resolve to different IP addresses. Instead of using static hostnames or IP addresses, the system creates time-limited FQDNs that automatically expire and are replaced, making the access infrastructure dynamic and resistant to static exploitation by attackers
Solution Approach 2:
The system employs periodic regeneration of access points through automated FQDN creation and expiration cycles. The access infrastructure is continuously renewed with new FQDNs that have limited validity periods, creating a rhythmic pattern of access point rotation that prevents long-term exploitation while maintaining operational continuity
2Device complexity
If static architecture is used for network access, then device complexity is reduced, but security is worsened due to vulnerability to denial of service attacks
Solution Approach 1:
The patent transforms the static access architecture into a dynamic system where FQDNs are periodically regenerated and resolved to different IP addresses. This dynamic behavior prevents attackers from maintaining persistent denial of service attacks, as the target addresses change over time while the underlying network assets remain accessible to authorized users
3Ease of operation
If permanent access points are used for network assets, then ease of operation is improved, but security is worsened due to easy targeting by malicious bots
Solution Approach 1:
The system implements periodic FQDN regeneration that causes access points to change at regular intervals. This periodic transformation makes it difficult for scanning bots to identify and target network assets, as the FQDNs they discover become invalid by the time they attempt exploitation, while legitimate users experience no disruption due to automated FQDN distribution
Data Source
AI summary
A system for securing access to a network asset and including a launcher and a master each configure to generate a new unique and temporary hostname and virtual machines each having an IP address associated to a corresponding generated unique, secret and temporary hostname. Each virtual machine operates either as a server hosting the network asset or a reverse proxy or a firewall between a client device having the launcher stored in the memory thereof and the corresponding network asset. A new virtual machine is created each time a new hostname is generated and is destructed after the corresponding hostname expires. The system also includes a DNS server storing a database of host records each including a public IP address of one of the virtual machines and the corresponding hostname, the database of host records being updated each time a new virtual machine is created in a DNS domain.


