Outlier DNS Request Scoring for Suspicious Activity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DNS systems lack the ability to identify and inspect outlier DNS requests that may be associated with suspicious or malicious activity, making it difficult to detect and address undesirable network interactions.

Innovation Solution

A DNS resolver monitors and scores DNS requests based on characteristics, groups them, identifies outliers, and inspects these requests for anomalies, allowing for further analysis to determine the source and nature of potential malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If DNS requests are monitored and scored to identify outliers, then the ability to detect suspicious activity is improved, but the device complexity increases

Engineering Contradiction:
Improvedetection of suspicious activityVSAvoidcomplexity of DNS monitoring system
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system segments DNS requests into normal and outlier categories by scoring individual request characteristics (domain name, IP address, timing patterns) and grouping them into clusters. This segmentation enables automated detection of suspicious activity without requiring complex manual analysis of every request.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary scoring and grouping mechanism that sits between DNS request processing and security analysis. This intermediary layer automatically evaluates request characteristics, assigns scores, groups similar requests, and identifies outliers, thereby simplifying the overall detection process while improving capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If DNS requests are grouped and inspected for anomalies, then the reliability of security monitoring is improved, but the loss of time increases

Engineering Contradiction:
Improvereliability of security monitoringVSAvoidtime for request analysis
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary scoring and grouping of DNS requests in real-time as they are processed. By pre-evaluating request characteristics and establishing baseline groups before potential attacks occur, the system can quickly identify outliers without requiring time-consuming post-incident analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The DNS monitoring system performs self-service by automatically scoring its own requests, grouping them into clusters, and identifying outliers without requiring external intervention. This automation maintains high reliability while minimizing time loss compared to manual security analysis.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If all DNS requests are inspected for anomalies, then the detection precision is improved, but the productivity decreases

Engineering Contradiction:
Improveprecision of anomaly detectionVSAvoidproductivity of DNS processing
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies local quality by inspecting only the characteristics of individual DNS requests that deviate from established patterns (outliers), rather than uniformly inspecting all requests. This selective inspection maintains high detection precision for anomalies while preserving overall processing productivity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by focusing inspection resources only on outlier requests that exceed predefined thresholds, rather than exhaustively analyzing every DNS request. This partial inspection approach achieves sufficient detection precision while avoiding the productivity penalty of full inspection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12432237B2Identification and inspection of outlier domain name system requests
Publication Date: 2025.09.30 THREATER INC
  • US12432237B2 patent drawing
  • US12432237B2 patent drawing
  • US12432237B2 patent drawing

AI summary

The technology disclosed herein enables identification of outlier DNS requests so the identified requests can be inspected to determine whether the identified requests may be associated with suspicious activity. In a particular example, a method provides determining characteristics of a Domain Name System (DNS) request and generating a score for the DNS request from the characteristics. The method further provides grouping a plurality of DNS requests into one or more groups based on a plurality of DNS request scores for the plurality of DNS requests. The plurality of DNS requests occurred in a specified timeframe and include the DNS request. The plurality of DNS request scores includes the score. In response to determining the DNS request is an outlier relative to the one or more groups, the method provides inspecting the DNS request for anomalies.