Encrypted DNS Relay Unit for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware countermeasures that rely on monitoring DNS communication packets are ineffective when encrypted communication methods like DoT or DoH are used, as these encrypt DNS packets, rendering traditional monitoring techniques useless.
Innovation Solution
An image processing apparatus is designed to perform DNS name resolution using encrypted communication, featuring a relay unit for decrypting encrypted communication, a detection unit for monitoring name resolution failures, and a control unit for implementing security measures based on detected failures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted communication (DoT/DoH) is used for DNS name resolution, then security of communication is improved, but malware detection capability deteriorates because DNS packets become encrypted and cannot be monitored
Solution Approach 1:
The image processing apparatus acts as an intermediary by establishing separate encrypted communication channels: one between the external device and the apparatus, and another between the apparatus and the DNS server. This mediator role allows the apparatus to relay encrypted DNS queries while maintaining the ability to detect malware through monitoring of the external device's communication patterns and error rates, without requiring direct decryption of the DNS packets.
Solution Approach 2:
The patent replaces the traditional mechanical approach of directly monitoring and decrypting DNS packets with a statistical detection method. Instead of attempting to decrypt and analyze DNS packet contents, the system substitutes monitoring of communication patterns, error rates, and behavioral metrics to detect malware, thereby eliminating the need for packet decryption while maintaining detection capability.
2Difficulty of detecting and measuring
If traditional packet monitoring is used for malware detection, then malware detection is effective, but it becomes ineffective when encrypted communication is used
Solution Approach 1:
The patent changes the detection parameters from analyzing DNS packet contents to monitoring communication statistics such as error rates, query frequencies, and response patterns. This parameter transformation allows the system to detect malware effectively while being compatible with encrypted communication protocols, as the statistical parameters can be observed without decrypting the actual DNS packets.
3Reliability
If DNS packets are encrypted using DoT or DoH, then communication security is enhanced, but the ability to monitor DNS communication for security purposes is lost
Solution Approach 1:
The image processing apparatus serves as a mediator that establishes encrypted communication channels on both sides, allowing it to relay DNS queries while maintaining visibility into communication patterns. The apparatus can detect malware through monitoring of behavioral metrics without requiring visibility into the encrypted DNS packet contents, thus preserving communication security while maintaining detection capability.
Solution Approach 2:
The system implements feedback mechanisms by monitoring error rates and communication patterns, using this information to detect malware behavior. The feedback loop allows the system to adapt to encrypted communication by analyzing the consequences and patterns of DNS operations rather than the contents themselves, maintaining security while enabling detection.
Data Source
AI summary
A packet monitoring unit of a multi-function peripheral relays encrypted communication, decrypts encrypted communication data at time of relaying into plain text, detects a failure in name resolution by monitoring, based on contents of the decrypted communication data, communication associated with the communication data, and performs control associated with security measures based on detection of the failure in the name resolution.


