Mobile DNS Proxy Policy Control Beyond VPN Tunnels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network monitoring systems for mobile devices struggle to provide visibility and control over network communications outside VPN tunnels, especially for name queries, and require extensive human intervention for policy rule creation and machine learning training, leading to inefficiencies and performance degradation.
Innovation Solution
A system that captures all network flows on mobile devices, steers name queries inside or outside the VPN tunnel based on policy rules, processes data in real-time using machine learning algorithms to automatically create and apply network policies, and aggregates data for centralized analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VPN solutions are used to provide visibility and control of mobile network communications, then control over network flows inside the VPN tunnel is improved, but visibility and control over network flows that bypass the VPN tunnel deteriorates
Solution Approach 1:
The patent introduces a DNS proxy as an intermediary component that intercepts and redirects DNS queries. This mediator enables the system to observe and control all network flows including those that bypass the VPN tunnel, since DNS queries must pass through the proxy regardless of whether the subsequent traffic uses the VPN tunnel or not.
Solution Approach 2:
The patent segments network flow control into two independent components: DNS query handling (through the DNS proxy) and VPN tunneling. This segmentation allows the system to control DNS queries for all destinations while maintaining selective VPN tunneling for specific traffic, thereby achieving visibility and control over both tunneled and non-tunneled flows.
2Adaptability or versatility
If network monitoring systems scale up to handle more mobile devices, then coverage of mobile workers is improved, but system complexity and human intervention requirements deteriorates
Solution Approach 1:
The patent implements self-service through automated machine learning algorithms that continuously analyze network traffic patterns and automatically create policy rules. The system monitors mobile worker behavior, identifies anomalies, and generates control policies without requiring manual intervention from network administrators, thereby reducing complexity as the system scales.
Solution Approach 2:
The system incorporates feedback loops where network traffic data is continuously collected, analyzed by machine learning algorithms, and used to automatically update policy rules. This closed-loop feedback mechanism enables the system to adapt to changing network conditions and worker behavior patterns automatically, reducing the need for manual system configuration and complexity management.
3Stability of the object's composition
If centralized mechanisms are used for network control, then policy consistency is improved, but network performance and user experience deteriorates due to bottlenecks
Solution Approach 1:
The patent segments the network control function into distributed components: a centralized policy management plane that defines high-level policies and local enforcement points (such as the DNS proxy and VPN client) that execute policies autonomously. This segmentation maintains policy consistency through centralized coordination while eliminating performance bottlenecks by allowing local devices to make real-time control decisions without waiting for centralized processing.
Data Source
AI summary
Mobile management method, system and client. The method includes receiving a DNS query for a host name from an application on a client; retrieving reputation data associated with the host name from a local cache on the client; determining a policy for the host name, which is associated with the host name and the reputation data associated with the host name; based on the determined policy for the host name, blocking attempted network flows to a host corresponding to the host name; sending at least attempted network flow metadata related to the blocked attempted network flows to a collector on the client; and transmitting the attempted network flow metadata in the collector to a VPN server pool via a VPN tunnel.


