Pharming Alert Filtering Reducing False Positives

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security services for detecting pharming attacks generate a high rate of false positive alerts due to frequent IP address changes of websites and the introduction of new subdomains, overwhelming site operators and reducing the effectiveness of alerting systems.

Innovation Solution

A method that generates pharming alerts based on mismatches between expected and obtained IP addresses from multiple DNS servers, and filters these alerts using circumstances such as the number of mismatching DNS servers, time, geographic location, and hosting companies, to reduce false positives by blocking less suspect alerts and allowing more suspect ones to reach operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security services generate alerts for all IP address mismatches detected from DNS servers, then the detection of pharming attacks is improved, but the rate of false positive alerts increases significantly

Engineering Contradiction:
Improvepharming attack detectionVSAvoidnumber of alerts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by differentiating the treatment of alerts based on their specific characteristics. Instead of treating all IP mismatches uniformly, the system analyzes individual alert attributes (such as number of mismatching DNS servers, time patterns, geographic location, and hosting company relationships) to determine the local quality or suspiciousness level of each alert, thereby filtering out false positives while maintaining detection reliability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes parameters by introducing multiple filtering criteria and thresholds for alert evaluation. The system modifies the alert generation process by incorporating parameters such as the number of DNS servers returning mismatched IPs, time-based patterns, geographic distribution, and hosting company affiliations. These parameter changes enable the system to distinguish between legitimate IP changes and actual pharming attacks, reducing false positives while maintaining detection accuracy.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If security services monitor all DNS server IP address associations, then the coverage of pharming detection is improved, but the complexity of the monitoring system increases

Engineering Contradiction:
Improvedetection coverageVSAvoidmonitoring system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the complex monitoring task into manageable components. The system segments the alert filtering process into distinct evaluation stages, analyzing different aspects of alerts independently (such as DNS server count, temporal patterns, geographic data, and hosting company relationships). This segmentation reduces the complexity of processing each individual alert while maintaining comprehensive detection coverage across multiple dimensions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary filtering mechanism that sits between the DNS query process and the alert generation process. This intermediary layer processes and evaluates alert characteristics before final alert delivery to operators. The intermediary filters out low-suspicion alerts based on analyzed circumstances, reducing the complexity of handling all alerts uniformly while maintaining broad detection coverage through systematic evaluation of multiple parameters.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If site operators receive all pharming alerts without filtering, then the completeness of security information is improved, but the operational burden on operators increases

Engineering Contradiction:
Improvesecurity information completenessVSAvoidoperator workload
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent extracts and removes less suspicious alerts from the operator workload through systematic filtering. By analyzing alert characteristics (such as the number of mismatching DNS servers, time patterns, geographic location, and hosting company relationships), the system extracts and blocks low-suspicion false positive alerts from reaching operators. This extraction preserves the completeness of genuine security information while significantly reducing the operational burden on site operators by filtering out unnecessary alerts.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements feedback mechanisms that allow operators to provide input on alert accuracy, which feeds back into the filtering system. The system learns from operator interactions and feedback to refine its filtering algorithms, improving the distinction between genuine threats and false positives over time. This feedback loop maintains information completeness for actual threats while progressively reducing operator workload by improving filter accuracy based on real-world operational data.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9621582B1Generating pharming alerts with reduced false positives
Publication Date: 2017.04.11 EMC IP HLDG CO LLC
  • US9621582B1 patent drawing
  • US9621582B1 patent drawing
  • US9621582B1 patent drawing

AI summary

A technique for informing an Internet site operator of potential pharming attacks includes generating pharming alerts based on mismatches between a set of expected IP addresses and IP addresses obtained from DNS servers on the Internet and filtering the generated alerts based on circumstances surrounding the generated pharming alerts. Filtering the alerts blocks less suspect pharming alerts while allowing more suspect ones to pass to the site operator, reducing the rate of false positives and better enabling the operator to focus on alerts that may present actual threats.