Emulated DNS Server for Network Security Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security testing methods face challenges in accurately evaluating the performance of security devices like intrusion prevention systems (IPS) due to incorrect signatures leading to false blocking of benign traffic, which can impact end users.

Innovation Solution

The implementation of a method and system using an emulated server for network security testing, where an emulated DNS server provides an IP address to a client device, allowing it to communicate with an emulated server that simulates attack vectors, enabling the test controller to determine performance metrics on how the system under test handles malicious traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security testing methods are used with real network services, then the testing can evaluate actual security device performance, but incorrect signatures may cause false blocking of benign traffic impacting end users

Engineering Contradiction:
Improvesecurity device performance evaluationVSAvoidfalse blocking of benign traffic
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a virtualized test environment that copies and emulates network services (DNS server, web server, email server) instead of using real external services. This allows security devices to be tested with controlled test traffic that includes both malicious and benign patterns, enabling accurate evaluation without the risk of false blocking real user traffic. The emulated servers provide predictable responses that facilitate reliable testing.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a virtualized testbed as an intermediary layer between the security device under test and the external network. This intermediary environment includes virtual network elements (routers, switches, firewalls, and emulated applications) that mediate the testing process, allowing secure and controlled evaluation of security device performance without affecting actual network operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive security testing is performed to detect all attack vectors, then detection accuracy improves, but testing complexity and time requirements increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidtesting system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal virtualized testbed platform that can emulate multiple different network services and attack scenarios within a single integrated system. The virtualization infrastructure allows one testing system to perform diverse security evaluations (DNS attacks, web attacks, email attacks) without requiring separate specialized test environments for each service type, thereby reducing overall system complexity while maintaining comprehensive testing capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs dynamic virtual network elements that can be rapidly deployed, configured, and torn down as needed for different test scenarios. The virtualized architecture allows flexible adaptation of test configurations without physical reconfiguration, enabling comprehensive attack vector testing while maintaining operational simplicity through software-based dynamic reconfiguration.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If real network services are used for testing, then the testing reflects actual production conditions, but the testing cannot be isolated from production network operations

Engineering Contradiction:
Improvereal-world scenario representationVSAvoidtesting isolation from production
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates virtual copies of real network services (emulated DNS server, web server, email server) that replicate production-like behavior and attack patterns without actually connecting to production networks. These virtual emulations maintain the necessary complexity to represent real-world scenarios while ensuring complete isolation from production operations, eliminating any risk of interference with actual network services.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11943248B1Methods, systems, and computer readable media for network security testing using at least one emulated server
Publication Date: 2024.03.26 KEYSIGHT TECHNOLOGIES INC
  • US11943248B1 patent drawing
  • US11943248B1 patent drawing
  • US11943248B1 patent drawing

AI summary

Methods, systems, and computer readable media for network security testing using at least one emulated server are disclosed. According to one example method, the method comprises: receiving, from a client device and at an emulated domain name service (DNS) server, a DNS request requesting an Internet protocol (IP) address associated with a domain name; sending, to the client device and from the emulated DNS server, a DNS response including an IP address associated with an emulated server; receiving, from the client device and at the emulated server, a service request using the IP address; sending, to the client device and from the emulated server, a service response including at least one attack vector data portion; and determining, by a test controller and using data obtained by at least one test related entity, a performance metric associated with a system under test (SUT).