Emulated DNS Server for Network Security Testing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security testing methods face challenges in accurately evaluating the performance of security devices like intrusion prevention systems (IPS) due to incorrect signatures leading to false blocking of benign traffic, which can impact end users.
Innovation Solution
The implementation of a method and system using an emulated server for network security testing, where an emulated DNS server provides an IP address to a client device, allowing it to communicate with an emulated server that simulates attack vectors, enabling the test controller to determine performance metrics on how the system under test handles malicious traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network security testing methods are used with real network services, then the testing can evaluate actual security device performance, but incorrect signatures may cause false blocking of benign traffic impacting end users
Solution Approach 1:
The patent creates a virtualized test environment that copies and emulates network services (DNS server, web server, email server) instead of using real external services. This allows security devices to be tested with controlled test traffic that includes both malicious and benign patterns, enabling accurate evaluation without the risk of false blocking real user traffic. The emulated servers provide predictable responses that facilitate reliable testing.
Solution Approach 2:
The patent introduces a virtualized testbed as an intermediary layer between the security device under test and the external network. This intermediary environment includes virtual network elements (routers, switches, firewalls, and emulated applications) that mediate the testing process, allowing secure and controlled evaluation of security device performance without affecting actual network operations.
2Measurement precision
If comprehensive security testing is performed to detect all attack vectors, then detection accuracy improves, but testing complexity and time requirements increase
Solution Approach 1:
The patent implements a universal virtualized testbed platform that can emulate multiple different network services and attack scenarios within a single integrated system. The virtualization infrastructure allows one testing system to perform diverse security evaluations (DNS attacks, web attacks, email attacks) without requiring separate specialized test environments for each service type, thereby reducing overall system complexity while maintaining comprehensive testing capability.
Solution Approach 2:
The patent employs dynamic virtual network elements that can be rapidly deployed, configured, and torn down as needed for different test scenarios. The virtualized architecture allows flexible adaptation of test configurations without physical reconfiguration, enabling comprehensive attack vector testing while maintaining operational simplicity through software-based dynamic reconfiguration.
3Adaptability or versatility
If real network services are used for testing, then the testing reflects actual production conditions, but the testing cannot be isolated from production network operations
Solution Approach 1:
The patent creates virtual copies of real network services (emulated DNS server, web server, email server) that replicate production-like behavior and attack patterns without actually connecting to production networks. These virtual emulations maintain the necessary complexity to represent real-world scenarios while ensuring complete isolation from production operations, eliminating any risk of interference with actual network services.
Data Source
AI summary
Methods, systems, and computer readable media for network security testing using at least one emulated server are disclosed. According to one example method, the method comprises: receiving, from a client device and at an emulated domain name service (DNS) server, a DNS request requesting an Internet protocol (IP) address associated with a domain name; sending, to the client device and from the emulated DNS server, a DNS response including an IP address associated with an emulated server; receiving, from the client device and at the emulated server, a service request using the IP address; sending, to the client device and from the emulated server, a service response including at least one attack vector data portion; and determining, by a test controller and using data obtained by at least one test related entity, a performance metric associated with a system under test (SUT).


