Outlier DNS Request Scoring for Suspicious Activity Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DNS systems lack the ability to identify and inspect outlier DNS requests that may be associated with suspicious or malicious activity, making it difficult to detect and address undesirable network interactions.
Innovation Solution
A DNS resolver monitors and scores DNS requests based on characteristics, groups them, identifies outliers, and inspects these requests for anomalies, allowing for further analysis to determine the source and nature of potential malicious activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If DNS requests are monitored and scored to identify outliers, then the ability to detect suspicious activity is improved, but the device complexity increases
Solution Approach 1:
The system segments DNS requests into normal and outlier categories by scoring individual request characteristics (domain name, IP address, timing patterns) and grouping them into clusters. This segmentation enables automated detection of suspicious activity without requiring complex manual analysis of every request.
Solution Approach 2:
The patent introduces an intermediary scoring and grouping mechanism that sits between DNS request processing and security analysis. This intermediary layer automatically evaluates request characteristics, assigns scores, groups similar requests, and identifies outliers, thereby simplifying the overall detection process while improving capability.
2Reliability
If DNS requests are grouped and inspected for anomalies, then the reliability of security monitoring is improved, but the loss of time increases
Solution Approach 1:
The system performs preliminary scoring and grouping of DNS requests in real-time as they are processed. By pre-evaluating request characteristics and establishing baseline groups before potential attacks occur, the system can quickly identify outliers without requiring time-consuming post-incident analysis.
Solution Approach 2:
The DNS monitoring system performs self-service by automatically scoring its own requests, grouping them into clusters, and identifying outliers without requiring external intervention. This automation maintains high reliability while minimizing time loss compared to manual security analysis.
3Measurement precision
If all DNS requests are inspected for anomalies, then the detection precision is improved, but the productivity decreases
Solution Approach 1:
The system applies local quality by inspecting only the characteristics of individual DNS requests that deviate from established patterns (outliers), rather than uniformly inspecting all requests. This selective inspection maintains high detection precision for anomalies while preserving overall processing productivity.
Solution Approach 2:
The patent implements partial action by focusing inspection resources only on outlier requests that exceed predefined thresholds, rather than exhaustively analyzing every DNS request. This partial inspection approach achieves sufficient detection precision while avoiding the productivity penalty of full inspection.
Data Source
AI summary
The technology disclosed herein enables identification of outlier DNS requests so the identified requests can be inspected to determine whether the identified requests may be associated with suspicious activity. In a particular example, a method provides determining characteristics of a Domain Name System (DNS) request and generating a score for the DNS request from the characteristics. The method further provides grouping a plurality of DNS requests into one or more groups based on a plurality of DNS request scores for the plurality of DNS requests. The plurality of DNS requests occurred in a specified timeframe and include the DNS request. The plurality of DNS request scores includes the score. In response to determining the DNS request is an outlier relative to the one or more groups, the method provides inspecting the DNS request for anomalies.


