NXNS DDoS Domain Identification via Packet Amplification Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies are inadequate in detecting and preventing malicious activities using NoneXistent NameServer (NXNS) domains, which can be exploited for distributed denial-of-service (DDoS) attacks, as they do not effectively identify and block such domains, leading to potential harm to computer systems.
Innovation Solution
A data appliance and security platform that utilize DNS record query information to identify and block attack domains by analyzing passive DNS data, determining candidate attack domains, and validating them through a packet amplification factor analysis, thereby preventing malicious DNS queries and mitigating DDoS attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current technologies are used to detect malicious activities, then general malware detection is possible, but NXNS-based DDoS attack domains cannot be effectively identified and blocked
Solution Approach 1:
The patent segments the detection process into multiple specialized components: passive DNS data collection module, packet amplification factor analysis module, candidate attack domain identification module, and validation module. Each component handles a specific aspect of NXNS attack detection, enabling reliable identification of this specific attack type while maintaining the ability to adapt to other attack variants through modular design
Solution Approach 2:
The patent introduces packet amplification factor as a new detection parameter specifically for NXNS attacks. By calculating and analyzing the packet amplification factor from passive DNS data, the system can reliably distinguish NXNS-based DDoS attack domains from legitimate domains, thereby improving both detection reliability and coverage of this specific attack type
2Measurement precision
If passive DNS data analysis is performed to identify candidate attack domains, then detection accuracy is improved, but computational resources and time are increased
Solution Approach 1:
The patent performs preliminary filtering by calculating the packet amplification factor early in the analysis process using passive DNS data. This preliminary action identifies candidate attack domains before more intensive validation steps, reducing the overall validation time by eliminating obviously malicious domains early while maintaining high detection accuracy
Solution Approach 2:
The patent applies partial validation actions by focusing computational resources on analyzing the packet amplification factor for candidate domains rather than performing exhaustive validation on all domains. This partial action approach achieves sufficient detection accuracy for NXNS attacks while significantly reducing the time and computational resources required compared to complete validation of all possible domains
Data Source
AI summary
Techniques for identifying and blocking domains used for NXNS-based distributed denial of service (DDos) attacks are disclosed. An analysis of DNS data is performed to identify a candidate attack domain associated with an NXNS attack. The candidate attack domain is confirmed as a confirmed attack domain based at least in part on a validation.


