Encrypted Traffic Domain Identification via DNS and Flow Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies face challenges in accurately identifying internet domain destinations of encrypted communications within communication networks, as encrypted transactions obscure domain names and IP addresses, making it difficult for network operators to understand traffic patterns and relate them to specific websites, especially when interactions involve different servers and autonomous systems.
Innovation Solution
A system that combines sampled DNS requests, internet transactions, border gateway protocol routing tables, and IP flow data to build an IP classifier dictionary, which maps domain names to IP addresses, and uses heuristics to classify encrypted transactions, ensuring the dictionary remains current and providing accurate identification of domain names associated with encrypted internet transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted transactions are used to protect communication security, then security and privacy are improved, but the ability to identify domain destinations and analyze traffic patterns deteriorates
Solution Approach 1:
The patent introduces an intermediary classification system that acts as a mediator between encrypted traffic and domain identification. Instead of directly decrypting traffic, the system uses machine learning classifiers trained on DNS request patterns, packet timing, and flow characteristics to indirectly identify domain destinations while preserving encryption. This intermediary approach maintains security while recovering essential identification information.
Solution Approach 2:
The system performs preliminary actions by pre-training classification models using unencrypted DNS request data before deployment. During operation, these pre-trained models immediately classify encrypted traffic without requiring real-time decryption. The preliminary training phase captures domain-specific communication patterns that enable later identification of encrypted traffic destinations.
2Measurement precision
If DNS requests are monitored to identify traffic patterns, then traffic analysis capability is improved, but the ability to accurately relate encrypted transactions to specific websites deteriorates
Solution Approach 1:
The patent merges multiple data sources including DNS request patterns, packet timing information, flow characteristics, and autonomous system data into a unified classification model. By combining these diverse features, the system achieves accurate website identification for encrypted traffic without relying on any single imperfect source, thereby resolving the contradiction between traffic pattern analysis and website identification.
Solution Approach 2:
The system changes parameters by transforming raw network traffic data into classified domain identifiers through machine learning models. Instead of directly observing domain names in encrypted traffic, the system transforms packet timing, size, and flow parameters into probabilistic domain predictions, enabling accurate website identification despite encryption.
3Adaptability or versatility
If multiple servers and autonomous systems are involved in internet transactions, then network complexity and routing flexibility are improved, but the difficulty of tracking and identifying domain destinations increases
Solution Approach 1:
The patent adds another dimension to domain identification by incorporating autonomous system-level analysis alongside traditional packet inspection. Instead of relying solely on single-hop routing information, the system analyzes traffic patterns across multiple autonomous systems and uses hierarchical classification to track domains through complex multi-server transactions, thereby resolving the tracking difficulty while preserving routing flexibility.
Data Source
AI summary
Methods, apparatus, systems and articles of manufacture disclosed herein can be used to identify an internet domain to which an encrypted network communication is targeted. A disclosed method includes collecting a plurality of unencrypted communications with a domain name server, and identifying, by executing an instruction with a processor, network traffic patterns associated with the unencrypted communication based on a combination of routing information, internet protocol flow data, and internet transactions associated with the plurality of unencrypted communications with the domain name server. An example disclosed method further includes determining, by executing an instruction with a processor, and based on the network traffic patterns associated with the unencrypted communications, the internet domain to which the encrypted communication is to be delivered.


