Pharming Alert Filtering Reducing False Positives
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security services for detecting pharming attacks generate a high rate of false positive alerts due to frequent IP address changes of websites and the introduction of new subdomains, overwhelming site operators and reducing the effectiveness of alerting systems.
Innovation Solution
A method that generates pharming alerts based on mismatches between expected and obtained IP addresses from multiple DNS servers, and filters these alerts using circumstances such as the number of mismatching DNS servers, time, geographic location, and hosting companies, to reduce false positives by blocking less suspect alerts and allowing more suspect ones to reach operators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security services generate alerts for all IP address mismatches detected from DNS servers, then the detection of pharming attacks is improved, but the rate of false positive alerts increases significantly
Solution Approach 1:
The patent applies local quality by differentiating the treatment of alerts based on their specific characteristics. Instead of treating all IP mismatches uniformly, the system analyzes individual alert attributes (such as number of mismatching DNS servers, time patterns, geographic location, and hosting company relationships) to determine the local quality or suspiciousness level of each alert, thereby filtering out false positives while maintaining detection reliability.
Solution Approach 2:
The patent changes parameters by introducing multiple filtering criteria and thresholds for alert evaluation. The system modifies the alert generation process by incorporating parameters such as the number of DNS servers returning mismatched IPs, time-based patterns, geographic distribution, and hosting company affiliations. These parameter changes enable the system to distinguish between legitimate IP changes and actual pharming attacks, reducing false positives while maintaining detection accuracy.
2Adaptability or versatility
If security services monitor all DNS server IP address associations, then the coverage of pharming detection is improved, but the complexity of the monitoring system increases
Solution Approach 1:
The patent applies segmentation by dividing the complex monitoring task into manageable components. The system segments the alert filtering process into distinct evaluation stages, analyzing different aspects of alerts independently (such as DNS server count, temporal patterns, geographic data, and hosting company relationships). This segmentation reduces the complexity of processing each individual alert while maintaining comprehensive detection coverage across multiple dimensions.
Solution Approach 2:
The patent introduces an intermediary filtering mechanism that sits between the DNS query process and the alert generation process. This intermediary layer processes and evaluates alert characteristics before final alert delivery to operators. The intermediary filters out low-suspicion alerts based on analyzed circumstances, reducing the complexity of handling all alerts uniformly while maintaining broad detection coverage through systematic evaluation of multiple parameters.
3Loss of information
If site operators receive all pharming alerts without filtering, then the completeness of security information is improved, but the operational burden on operators increases
Solution Approach 1:
The patent extracts and removes less suspicious alerts from the operator workload through systematic filtering. By analyzing alert characteristics (such as the number of mismatching DNS servers, time patterns, geographic location, and hosting company relationships), the system extracts and blocks low-suspicion false positive alerts from reaching operators. This extraction preserves the completeness of genuine security information while significantly reducing the operational burden on site operators by filtering out unnecessary alerts.
Solution Approach 2:
The patent implements feedback mechanisms that allow operators to provide input on alert accuracy, which feeds back into the filtering system. The system learns from operator interactions and feedback to refine its filtering algorithms, improving the distinction between genuine threats and false positives over time. This feedback loop maintains information completeness for actual threats while progressively reducing operator workload by improving filter accuracy based on real-world operational data.
Data Source
AI summary
A technique for informing an Internet site operator of potential pharming attacks includes generating pharming alerts based on mismatches between a set of expected IP addresses and IP addresses obtained from DNS servers on the Internet and filtering the generated alerts based on circumstances surrounding the generated pharming alerts. Filtering the alerts blocks less suspect pharming alerts while allowing more suspect ones to pass to the site operator, reducing the rate of false positives and better enabling the operator to focus on alerts that may present actual threats.


