Gateway DNS Query Interception for IoT Device Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting IoT devices in networks require preliminary knowledge and fingerprint databases, limiting their effectiveness in securing networks with unknown or unregistered devices.

Innovation Solution

A method involving a gateway computer that intercepts DNS queries, transmits them to a content rating system, and determines device types based on categorization categories, enabling security decisions without prior knowledge of specific devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If fingerprinting technique with reference metric database is used to detect IoT devices, then device identification accuracy is improved, but system complexity and preparation work increase due to requiring preliminary knowledge and database building

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the device identification task from the complex fingerprinting system. Instead of using comprehensive fingerprint databases, the solution isolates DNS query pattern analysis as a separate, simpler mechanism that can identify device types without requiring pre-built reference metrics or fingerprints.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces DNS query patterns as an intermediary between network traffic and device identification. Rather than directly analyzing complex device fingerprints, the system uses DNS queries as a mediator to infer device types, simplifying the detection process while maintaining accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If fingerprint database approach is used for IoT device detection, then known device identification is improved, but adaptability to unknown or unregistered devices deteriorates

Engineering Contradiction:
Improveknown device identificationVSAvoidadaptability to unknown devices
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent inverts the traditional fingerprinting approach. Instead of matching device traffic patterns against a database of known fingerprints, the system queries DNS patterns to infer device types. This inversion enables identification of unknown devices by their behavioral patterns rather than requiring them to match pre-stored fingerprints.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent changes the detection parameter from static device fingerprints to dynamic DNS query patterns. This parameter change allows the system to adapt to unknown devices by analyzing their operational behavior in real-time rather than relying on pre-defined device profiles.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If DNS query interception and content rating system are used to determine device types, then adaptability to unknown devices is improved, but network traffic processing complexity increases

Engineering Contradiction:
Improveadaptability to unknown devicesVSAvoidnetwork processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the network processing task into distinct functional components: DNS query interception, content rating system analysis, and device type determination. This segmentation allows each component to handle specific aspects of device identification independently, managing overall system complexity while improving adaptability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11503082B2Network security
Publication Date: 2022.11.15 F SECURE CORP
  • US11503082B2 patent drawing
  • US11503082B2 patent drawing
  • US11503082B2 patent drawing

AI summary

There is provided a network security method in a computer network. The method comprises detecting, by a gateway computer, a target device being connected to the computer network, detecting the target device transmitting a DNS query for resolving a hostname into an IP address, transmitting a query to a content rating system, wherein the query comprises the resolved hostname related to the DNS query of the target device, receiving, from the content rating system, a list of categorization categories assigned to the resolved hostname, determining a type of the target device on the basis of the received list of categorization categories assigned to the hostname, and generating a security related decision on the basis of the determined type of the target device.