NXNS DDoS Domain Identification via Packet Amplification Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies are inadequate in detecting and preventing malicious activities using NoneXistent NameServer (NXNS) domains, which can be exploited for distributed denial-of-service (DDoS) attacks, as they do not effectively identify and block such domains, leading to potential harm to computer systems.

Innovation Solution

A data appliance and security platform that utilize DNS record query information to identify and block attack domains by analyzing passive DNS data, determining candidate attack domains, and validating them through a packet amplification factor analysis, thereby preventing malicious DNS queries and mitigating DDoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current technologies are used to detect malicious activities, then general malware detection is possible, but NXNS-based DDoS attack domains cannot be effectively identified and blocked

Engineering Contradiction:
Improvedetection capabilityVSAvoidcoverage of attack types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the detection process into multiple specialized components: passive DNS data collection module, packet amplification factor analysis module, candidate attack domain identification module, and validation module. Each component handles a specific aspect of NXNS attack detection, enabling reliable identification of this specific attack type while maintaining the ability to adapt to other attack variants through modular design

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces packet amplification factor as a new detection parameter specifically for NXNS attacks. By calculating and analyzing the packet amplification factor from passive DNS data, the system can reliably distinguish NXNS-based DDoS attack domains from legitimate domains, thereby improving both detection reliability and coverage of this specific attack type

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If passive DNS data analysis is performed to identify candidate attack domains, then detection accuracy is improved, but computational resources and time are increased

Engineering Contradiction:
Improveattack domain identification accuracyVSAvoidvalidation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary filtering by calculating the packet amplification factor early in the analysis process using passive DNS data. This preliminary action identifies candidate attack domains before more intensive validation steps, reducing the overall validation time by eliminating obviously malicious domains early while maintaining high detection accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial validation actions by focusing computational resources on analyzing the packet amplification factor for candidate domains rather than performing exhaustive validation on all domains. This partial action approach achieves sufficient detection accuracy for NXNS attacks while significantly reducing the time and computational resources required compared to complete validation of all possible domains

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20230370492A1Identify and block domains used for NXNS-based DDOS attack
Publication Date: 2023.11.16 PALO ALTO NETWORKS INC
  • US20230370492A1 patent drawing
  • US20230370492A1 patent drawing
  • US20230370492A1 patent drawing

AI summary

Techniques for identifying and blocking domains used for NXNS-based distributed denial of service (DDos) attacks are disclosed. An analysis of DNS data is performed to identify a candidate attack domain associated with an NXNS attack. The candidate attack domain is confirmed as a confirmed attack domain based at least in part on a validation.