Policy-Based DNS Server for Selective Traffic Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional DNS servers are vulnerable to cache poisoning attacks and lack the ability to selectively manage responses based on the source of DNS queries, leading to unwanted traffic and potential security breaches.

Innovation Solution

A policy-based DNS server system that utilizes a processor with a policy engine to make informed decisions about DNS replies based on the source IP address and other criteria, allowing for the selection or generation of replies to be sent to the source IP address or algorithmically generated, enabling the differentiation of responses according to the sender's identity and circumstances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional DNS server responds to all queries with IP addresses, then network accessibility is maintained, but security vulnerabilities increase due to cache poisoning attacks and unwanted traffic

Engineering Contradiction:
ImproveDNS securityVSAvoidNetwork accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by making DNS responses non-uniform based on the source IP address. Different quality levels of responses are provided to different clients: legitimate clients receive valid IP addresses while malicious clients receive null routes or loopback addresses. This resolves the contradiction by maintaining accessibility for legitimate users while blocking malicious traffic, thereby improving security without compromising overall network accessibility.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent inverts the conventional DNS approach by not providing IP addresses to all clients by default, but instead selectively denying service to specific clients based on their source IP addresses. The system evaluates each query source and applies policy-based responses, inverting the traditional open-access model into a controlled-access model that prioritizes security while maintaining accessibility for authorized clients.

Inventive Principle:
Principle #13The other way round (Inversion)

2Loss of information

If a DNS server provides all resource records to all clients, then complete information availability is achieved, but traffic control and security management become difficult

Engineering Contradiction:
ImproveDNS information availabilityVSAvoidTraffic management complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring policy rules that define which clients should receive which types of DNS responses. The policy engine is pre-programmed with security policies and evaluation criteria that automatically determine the appropriate response for each client based on their source IP address. This resolves the contradiction by establishing information distribution rules in advance, making traffic management systematic and controllable rather than complex and ad-hoc.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of DNS response content based on the client's source IP address. Instead of providing uniform information to all clients, the system dynamically adjusts the response parameters (IP address, null route, loopback address) according to policy evaluations. This resolves the contradiction by enabling selective information availability through parameter variation, simplifying traffic management through policy-based control rather than complex individual handling.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If a DNS server uses random selection for load balancing, then traffic distribution is simplified, but security control and traffic management capabilities are reduced

Engineering Contradiction:
ImproveLoad balancing efficiencyVSAvoidSecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies dynamics by transitioning from static random selection to dynamic policy-based response selection. The DNS server dynamically evaluates each client's source IP address against configured policies and adjusts responses in real-time based on the evaluation results. This resolves the contradiction by maintaining load balancing efficiency through automated dynamic decision-making while simultaneously enabling security control through policy-based differentiation of responses to different clients.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8447856B2Policy-managed DNS server for to control network traffic
Publication Date: 2013.05.21 BARRACUDA NETWORKS INC
  • US8447856B2 patent drawing
  • US8447856B2 patent drawing
  • US8447856B2 patent drawing

AI summary

Disclosed is a method, a computer system, and a computer-readable media product that contains a set of computer executable software instructions for directing the computer to execute a process for policy-based operation of a DNS server apparatus to manage traffic due to undesirable mail or requests for electronic documents. The policies operate according to owners, regions, or countries controlling source IP addresses and deterministically select from a plurality of non-equivalent replies to be sent to the source IP address. Accumulating previous activity records may assist in determining which traffic may be usefully deferred or suppressed. The process includes withholding certain information from certain DNS servers seeking IP addresses to improve overall security and integrity of the Internet.