Firewall Domain Name Resolution from IP Addresses
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firewalls face difficulties in applying domain-name based security rules when network requests contain IP addresses that do not readily resolve to useful domain names, as existing reverse DNS lookups may not provide unambiguous results and can lead to ambiguity in disambiguating multiple domains hosted at a single IP address.
Innovation Solution
A firewall employs multiple techniques such as reverse DNS lookups, HTTP GET requests to extract domain information, and secure connections to analyze certificates for domain name information, collectively analyzing the obtained domain names to select a suitable domain name for enforcing security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If reverse DNS lookup is used to resolve IP address to domain name, then domain name can be obtained, but the result may be ambiguous when multiple domains are hosted at a single IP address
Solution Approach 1:
The patent segments the domain name resolution process into multiple independent techniques: reverse DNS lookup, HTTP GET request analysis, and SSL certificate analysis. Each technique targets a different information source, and their results are combined to achieve unambiguous domain name identification. This segmentation allows the system to overcome the limitation of any single technique when multiple domains share an IP address.
Solution Approach 2:
The patent introduces intermediary techniques between the IP address and the final domain name determination. Instead of directly relying on reverse DNS lookup alone, it uses HTTP GET requests and SSL certificate analysis as intermediary steps to gather additional domain name information. These intermediaries provide alternative paths to resolve the ambiguity when multiple domains are hosted at a single IP address.
2Measurement precision
If multiple techniques are used to resolve domain name from IP address, then domain name determination accuracy improves, but the complexity of the system increases
Solution Approach 1:
The patent implements a dynamic, adaptive resolution process where the firewall selectively applies different techniques based on the situation. The system can adjust which techniques to use and in what order, depending on the network request characteristics and available information. This dynamic approach allows accurate domain name determination while managing system complexity by not always executing all possible techniques.
Solution Approach 2:
The patent employs feedback mechanisms where the results from each resolution technique inform the selection and execution of subsequent techniques. If reverse DNS lookup succeeds, the system may not need to execute HTTP GET requests or SSL certificate analysis. The feedback from each step guides the overall resolution process, improving accuracy while controlling complexity through intelligent technique selection.
Data Source
AI summary
A firewall uses a variety of techniques to obtain a useful domain name from a network request, that is, a domain name that facilitates the accurate enforcement of domain-based security rules for network traffic at the firewall. If the network request includes an Internet Protocol (IP) address instead of the domain name, the firewall may begin with a reverse domain name lookup. If this technique fails to adequately resolve the domain name, then the firewall may attempt a hypertext transfer protocol (HTTP) GET request to the IP address and investigate the header for useful domain name information. The firewall may also or instead initiate a secure connection to the IP address and analyze a certificate returned from the destination for the presence of domain name information. These measures can produce one or more domain names that can be collectively analyzed to select a suitable domain name for the application of a domain-based security rule or policy by the firewall.


