Encrypted Traffic Domain Identification via DNS and Flow Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies face challenges in accurately identifying internet domain destinations of encrypted communications within communication networks, as encrypted transactions obscure domain names and IP addresses, making it difficult for network operators to understand traffic patterns and relate them to specific websites, especially when interactions involve different servers and autonomous systems.

Innovation Solution

A system that combines sampled DNS requests, internet transactions, border gateway protocol routing tables, and IP flow data to build an IP classifier dictionary, which maps domain names to IP addresses, and uses heuristics to classify encrypted transactions, ensuring the dictionary remains current and providing accurate identification of domain names associated with encrypted internet transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted transactions are used to protect communication security, then security and privacy are improved, but the ability to identify domain destinations and analyze traffic patterns deteriorates

Engineering Contradiction:
Improvecommunication securityVSAvoiddomain name identification
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary classification system that acts as a mediator between encrypted traffic and domain identification. Instead of directly decrypting traffic, the system uses machine learning classifiers trained on DNS request patterns, packet timing, and flow characteristics to indirectly identify domain destinations while preserving encryption. This intermediary approach maintains security while recovering essential identification information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-training classification models using unencrypted DNS request data before deployment. During operation, these pre-trained models immediately classify encrypted traffic without requiring real-time decryption. The preliminary training phase captures domain-specific communication patterns that enable later identification of encrypted traffic destinations.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If DNS requests are monitored to identify traffic patterns, then traffic analysis capability is improved, but the ability to accurately relate encrypted transactions to specific websites deteriorates

Engineering Contradiction:
Improvetraffic pattern analysisVSAvoidwebsite identification
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent merges multiple data sources including DNS request patterns, packet timing information, flow characteristics, and autonomous system data into a unified classification model. By combining these diverse features, the system achieves accurate website identification for encrypted traffic without relying on any single imperfect source, thereby resolving the contradiction between traffic pattern analysis and website identification.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system changes parameters by transforming raw network traffic data into classified domain identifiers through machine learning models. Instead of directly observing domain names in encrypted traffic, the system transforms packet timing, size, and flow parameters into probabilistic domain predictions, enabling accurate website identification despite encryption.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If multiple servers and autonomous systems are involved in internet transactions, then network complexity and routing flexibility are improved, but the difficulty of tracking and identifying domain destinations increases

Engineering Contradiction:
Improverouting flexibilityVSAvoiddomain destination tracking
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent adds another dimension to domain identification by incorporating autonomous system-level analysis alongside traditional packet inspection. Instead of relying solely on single-hop routing information, the system analyzes traffic patterns across multiple autonomous systems and uses hierarchical classification to track domains through complex multi-server transactions, thereby resolving the tracking difficulty while preserving routing flexibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10361931B2Methods and apparatus to identify an internet domain to which an encrypted network communication is targeted
Publication Date: 2019.07.23 AT&T INTELLECTUAL PROPERTY I L P
  • US10361931B2 patent drawing
  • US10361931B2 patent drawing
  • US10361931B2 patent drawing

AI summary

Methods, apparatus, systems and articles of manufacture disclosed herein can be used to identify an internet domain to which an encrypted network communication is targeted. A disclosed method includes collecting a plurality of unencrypted communications with a domain name server, and identifying, by executing an instruction with a processor, network traffic patterns associated with the unencrypted communication based on a combination of routing information, internet protocol flow data, and internet transactions associated with the plurality of unencrypted communications with the domain name server. An example disclosed method further includes determining, by executing an instruction with a processor, and based on the network traffic patterns associated with the unencrypted communications, the internet domain to which the encrypted communication is to be delivered.