Malicious Device Detection in LAN Name Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current DNS server discovery mechanisms in LAN networks lack security, making them vulnerable to malicious device interference, which can lead to data interception and fraudulent site redirection, as existing solutions like authentication certificates and protocols like DoH/DoT are insufficient to detect fraudulent devices.
Innovation Solution
A method involving a communication device that uses multiple identifiers to emulate a terminal within the network, allowing it to detect malicious devices by analyzing anomalies in name resolution requests and responses, and taking actions such as blocking or notifying incidents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional DNS server discovery mechanisms are used in LAN networks, then ease of operation is improved, but network security deteriorates due to vulnerability to malicious device interference
Solution Approach 1:
The patent implements preliminary detection actions by having the communication device proactively send test DNS requests through discovered DNS servers before normal network operations. This preliminary action allows the system to verify server legitimacy in advance, preventing malicious servers from interfering with subsequent operations while maintaining ease of DNS discovery.
Solution Approach 2:
The patent introduces an intermediary verification mechanism where the communication device acts as a mediator between terminals and DNS servers. By implementing a verification process that checks DNS server responses and behavior, the system creates a protective intermediary layer that blocks malicious interference while allowing legitimate DNS operations to proceed smoothly.
2Object-affected harmful factors
If authentication certificates and DoH/DoT protocols are implemented, then network security is improved, but the ability to detect fraudulent devices deteriorates
Solution Approach 1:
The patent implements dynamic detection by continuously monitoring DNS server behavior and responses in real-time. Rather than relying on static authentication certificates, the system dynamically evaluates DNS server legitimacy through ongoing test requests and response analysis, enabling detection of fraudulent devices that may have valid certificates but exhibit malicious behavior patterns.
Solution Approach 2:
The patent establishes a feedback mechanism where test DNS requests are sent to discovered servers and responses are analyzed to verify server legitimacy. This feedback loop provides continuous information about server behavior, allowing the system to detect fraudulent devices by identifying anomalous response patterns, timing deviations, or inconsistent information returned by malicious servers.
3Reliability
If multiple identifiers are used for emulation and detection, then detection reliability is improved, but device complexity increases
Solution Approach 1:
The patent applies multi-functionality by using the communication device's existing network interfaces and identifiers for dual purposes: normal network communication and security detection operations. The device uses its own identifiers to send test requests while also acting as a detector, eliminating the need for separate dedicated detection hardware or complex identifier management systems.
Solution Approach 2:
The patent implements self-service by having the communication device perform its own security detection using its existing resources and identifiers. The device leverages its own network capabilities to conduct test DNS requests and analyze responses, rather than requiring external detection systems or additional identifiers, thereby maintaining reliability while minimizing complexity.
Data Source
AI summary
A method for detecting a malicious device in a communication network, corresponding communication device and computer program. The method is implemented in a communication device configured with at least one name resolution server which is referred to as a legitimate name resolution server and associated with at least one network interface through which the communication device is able to communicate using at least one first identifier. The method includes: obtaining at least one second identifier, separate from the first identifier, for the communication device and the at least one network interface; obtaining configuration information from a name resolution service for the communication device using the at least one second identifier; and detecting presence of a malicious device in the event of an anomaly in the processing of a name resolution request sent by the communication device using the at least one second identifier and the obtained configuration information.


