Encrypted DNS Relay Unit for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware countermeasures that rely on monitoring DNS communication packets are ineffective when encrypted communication methods like DoT or DoH are used, as these encrypt DNS packets, rendering traditional monitoring techniques useless.

Innovation Solution

An image processing apparatus is designed to perform DNS name resolution using encrypted communication, featuring a relay unit for decrypting encrypted communication, a detection unit for monitoring name resolution failures, and a control unit for implementing security measures based on detected failures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted communication (DoT/DoH) is used for DNS name resolution, then security of communication is improved, but malware detection capability deteriorates because DNS packets become encrypted and cannot be monitored

Engineering Contradiction:
Improvesecurity of communicationVSAvoidmalware detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The image processing apparatus acts as an intermediary by establishing separate encrypted communication channels: one between the external device and the apparatus, and another between the apparatus and the DNS server. This mediator role allows the apparatus to relay encrypted DNS queries while maintaining the ability to detect malware through monitoring of the external device's communication patterns and error rates, without requiring direct decryption of the DNS packets.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical approach of directly monitoring and decrypting DNS packets with a statistical detection method. Instead of attempting to decrypt and analyze DNS packet contents, the system substitutes monitoring of communication patterns, error rates, and behavioral metrics to detect malware, thereby eliminating the need for packet decryption while maintaining detection capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Difficulty of detecting and measuring

If traditional packet monitoring is used for malware detection, then malware detection is effective, but it becomes ineffective when encrypted communication is used

Engineering Contradiction:
Improvemalware detection effectivenessVSAvoidcompatibility with encrypted communication
Core Design Contradiction:
Difficulty of detecting and measuringVSAdaptability or versatility

Solution Approach 1:

The patent changes the detection parameters from analyzing DNS packet contents to monitoring communication statistics such as error rates, query frequencies, and response patterns. This parameter transformation allows the system to detect malware effectively while being compatible with encrypted communication protocols, as the statistical parameters can be observed without decrypting the actual DNS packets.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If DNS packets are encrypted using DoT or DoH, then communication security is enhanced, but the ability to monitor DNS communication for security purposes is lost

Engineering Contradiction:
Improvecommunication securityVSAvoidDNS communication visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The image processing apparatus serves as a mediator that establishes encrypted communication channels on both sides, allowing it to relay DNS queries while maintaining visibility into communication patterns. The apparatus can detect malware through monitoring of behavioral metrics without requiring visibility into the encrypted DNS packet contents, thus preserving communication security while maintaining detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms by monitoring error rates and communication patterns, using this information to detect malware behavior. The feedback loop allows the system to adapt to encrypted communication by analyzing the consequences and patterns of DNS operations rather than the contents themselves, maintaining security while enabling detection.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250119440A1Image processing apparatus, method for controlling image processing apparatus, and computer readable storage medium
Publication Date: 2025.04.10 CANON KK
  • US20250119440A1 patent drawing
  • US20250119440A1 patent drawing
  • US20250119440A1 patent drawing

AI summary

A packet monitoring unit of a multi-function peripheral relays encrypted communication, decrypts encrypted communication data at time of relaying into plain text, detects a failure in name resolution by monitoring, based on contents of the decrypted communication data, communication associated with the communication data, and performs control associated with security measures based on detection of the failure in the name resolution.