Endpoint DNS Agent for Client Identification Behind NAT
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based DNS security systems struggle to distinguish between client devices due to Network Address Translation (NAT), making it difficult to configure different permissions and accurately log threats, and they cannot effectively manage domain name requests to block malicious or undesirable domains.
Innovation Solution
An endpoint Domain Name Server (DNS) agent is installed on client devices to intercept and process DNS requests based on a security policy, distinguishing between local and external domains, and redirecting requests through a local or cloud-based DNS server, with the option to override DNS redirections using credentials and route them through a tunnel server for filtering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a cloud-based DNS server is used to block malicious domains, then security protection is provided, but the system cannot distinguish between different client devices due to NAT, making it impossible to configure different permissions or accurately log threats
Solution Approach 1:
The patent introduces an endpoint DNS agent as an intermediary component installed on each client device. This agent acts as a local mediator between the client device and the cloud-based DNS server, enabling the system to identify and distinguish between different client devices despite NAT masking. The agent captures device-specific information and forwards it to the cloud server, allowing for precise client identification and personalized security policies.
Solution Approach 2:
The patent segments the DNS security system into two distinct components: a lightweight endpoint agent running on each client device and a cloud-based DNS server. This segmentation allows the identification function to be performed locally at each endpoint while the security policy enforcement and threat blocking occur in the cloud, resolving the contradiction between providing security protection and enabling precise client device identification.
2Adaptability or versatility
If a cloud-based DNS server is used, then centralized security management is achieved, but granular control over individual device permissions and accurate threat logging cannot be implemented
Solution Approach 1:
The endpoint DNS agent implements a feedback mechanism that collects device-specific information, DNS request details, and threat encounter data, then forwards this information to the cloud-based DNS server. This feedback loop enables the centralized server to maintain accurate records of each device's security posture, permissions, and encountered threats, allowing for granular control and precise logging while maintaining centralized management.
Solution Approach 2:
The endpoint agent serves as a feedback intermediary that bridges the gap between the client device and the cloud server. It captures and reports device identifiers, DNS query information, and security events back to the centralized system, enabling granular control and accurate logging without compromising the simplicity of centralized security management.
3Object-affected harmful factors
If DNS requests are blocked or redirected by a security device, then malicious domains are prevented from being accessed, but the ability to provide customized security policies for different users or devices is lost
Solution Approach 1:
The patent applies local quality by enabling each endpoint device to have its own security policy configuration stored and enforced by the local DNS agent. Different users or devices can have customized security policies tailored to their specific needs and risk profiles, while still benefiting from the centralized threat intelligence and blocking capabilities of the cloud-based DNS server. This allows customized security policies to coexist with effective malicious domain blocking.
Solution Approach 2:
The system segments security policy enforcement to the endpoint level while maintaining centralized threat intelligence. Each device can have customized permissions and policies applied locally by its DNS agent, yet the cloud server continues to provide centralized security management and coordinated blocking of malicious domains, achieving both customized policies and effective threat prevention.
Data Source
AI summary
A network is secured by managing domain name requests such that client devices are restricted from visiting malicious or undesirable domains. An endpoint Domain Name Server (DNS) agent is installed on client devices on a local network, and the endpoint DNS agents intercept DNS requests from the client devices and process the received DNS request in the endpoint DNS agent based on a security policy set for the client device via the endpoint DNS agent. In a further example processing the received DNS request comprises identifying the client device, end user, and the DNS request to a cloud-based DNS server, and processing a response received from the cloud-based DNS server received in response to the DNS request. The endpoint DNS agent is further operable to distinguish between DNS requests for local domains and remote domains, and to redirect DNS requests for local domains to a local network DNS server.


