Malicious Device Detection in LAN Name Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DNS server discovery mechanisms in LAN networks lack security, making them vulnerable to malicious device interference, which can lead to data interception and fraudulent site redirection, as existing solutions like authentication certificates and protocols like DoH/DoT are insufficient to detect fraudulent devices.

Innovation Solution

A method involving a communication device that uses multiple identifiers to emulate a terminal within the network, allowing it to detect malicious devices by analyzing anomalies in name resolution requests and responses, and taking actions such as blocking or notifying incidents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional DNS server discovery mechanisms are used in LAN networks, then ease of operation is improved, but network security deteriorates due to vulnerability to malicious device interference

Engineering Contradiction:
ImproveDNS server discoveryVSAvoidmalicious device interference
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary detection actions by having the communication device proactively send test DNS requests through discovered DNS servers before normal network operations. This preliminary action allows the system to verify server legitimacy in advance, preventing malicious servers from interfering with subsequent operations while maintaining ease of DNS discovery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism where the communication device acts as a mediator between terminals and DNS servers. By implementing a verification process that checks DNS server responses and behavior, the system creates a protective intermediary layer that blocks malicious interference while allowing legitimate DNS operations to proceed smoothly.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If authentication certificates and DoH/DoT protocols are implemented, then network security is improved, but the ability to detect fraudulent devices deteriorates

Engineering Contradiction:
Improvedata interception protectionVSAvoidfraudulent device detection
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements dynamic detection by continuously monitoring DNS server behavior and responses in real-time. Rather than relying on static authentication certificates, the system dynamically evaluates DNS server legitimacy through ongoing test requests and response analysis, enabling detection of fraudulent devices that may have valid certificates but exhibit malicious behavior patterns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent establishes a feedback mechanism where test DNS requests are sent to discovered servers and responses are analyzed to verify server legitimacy. This feedback loop provides continuous information about server behavior, allowing the system to detect fraudulent devices by identifying anomalous response patterns, timing deviations, or inconsistent information returned by malicious servers.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple identifiers are used for emulation and detection, then detection reliability is improved, but device complexity increases

Engineering Contradiction:
Improvemalicious device detectionVSAvoididentifier management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies multi-functionality by using the communication device's existing network interfaces and identifiers for dual purposes: normal network communication and security detection operations. The device uses its own identifiers to send test requests while also acting as a detector, eliminating the need for separate dedicated detection hardware or complex identifier management systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service by having the communication device perform its own security detection using its existing resources and identifiers. The device leverages its own network capabilities to conduct test DNS requests and analyze responses, rather than requiring external detection systems or additional identifiers, thereby maintaining reliability while minimizing complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240007484A1Method for detecting a malicious device in a communication network, corresponding communication device and computer program
Publication Date: 2024.01.04 ORANGE SA
  • US20240007484A1 patent drawing
  • US20240007484A1 patent drawing
  • US20240007484A1 patent drawing

AI summary

A method for detecting a malicious device in a communication network, corresponding communication device and computer program. The method is implemented in a communication device configured with at least one name resolution server which is referred to as a legitimate name resolution server and associated with at least one network interface through which the communication device is able to communicate using at least one first identifier. The method includes: obtaining at least one second identifier, separate from the first identifier, for the communication device and the at least one network interface; obtaining configuration information from a name resolution service for the communication device using the at least one second identifier; and detecting presence of a malicious device in the event of an anomaly in the processing of a name resolution request sent by the communication device using the at least one second identifier and the obtained configuration information.