Proxy Appliance DNS Snooping for Spyware Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security measures are inadequate in effectively preventing spyware and web-based malware from infiltrating and spreading within enterprise networks, with over 80% of corporate PCs infected and less than 10% of corporations deploying perimeter spyware defenses.

Innovation Solution

A proxy appliance is deployed to monitor and filter network traffic, utilizing multiple spyware scanning engines, web reputation filters, and dynamic vectoring techniques to detect and block malicious content, while also employing DNS snooping and caching to enhance performance and accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple spyware scanning engines are deployed to scan HTTP responses, then the detection capability and security reliability are improved, but the processing time and system complexity increase

Engineering Contradiction:
Improvespyware detection capabilityVSAvoidresponse scanning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by selectively scanning only certain HTTP responses based on content type and source reputation. The system identifies and scans only responses that contain potential spyware indicators, rather than scanning all responses uniformly. This selective approach reduces the overall scanning time while maintaining effective detection of malicious content.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent segments the spyware detection process into multiple specialized scanning engines, each targeting specific types of malicious content. By dividing the scanning task into specialized components that operate in parallel on different response segments, the system achieves comprehensive coverage without linearly increasing total processing time.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple spyware scanning engines are deployed to scan HTTP responses, then the detection capability and security reliability are improved, but the device complexity increases

Engineering Contradiction:
Improvespyware detection capabilityVSAvoidscanning system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functionality by designing a unified scanning architecture where a single HTTP response can be evaluated by multiple scanning engines simultaneously. The system manages diverse scanning engines through a common interface that handles content analysis, reputation checking, and threat detection, reducing operational complexity despite having multiple engines.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple scanning engines into a coordinated system where results from different engines are aggregated and evaluated together. The combination of multiple detection mechanisms is managed through a unified decision-making process that determines whether content should be blocked or allowed, simplifying the overall system management.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If DNS snooping and caching are employed to enhance performance, then the measurement precision and filtering accuracy are improved, but the device complexity increases

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidDNS monitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action through DNS snooping that occurs before HTTP response scanning. The system pre-evaluates the reputation of requested domains and caches these reputation scores. When subsequent requests target the same domain, the cached reputation information is used to quickly determine whether scanning is necessary, improving detection accuracy without adding proportional complexity to each request handling.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8087082B2Apparatus for filtering server responses
Publication Date: 2011.12.27 IRONPORT SYST
  • US8087082B2 patent drawing
  • US8087082B2 patent drawing
  • US8087082B2 patent drawing

AI summary

A data processing apparatus, comprising at least one processor and a traffic monitor comprising logic which, when executed by the processor, causes the processor to perform: creating, using forward Domain Name System (DNS) lookups, a mapping of domain names to Internet Protocol (IP) addresses; determining whether a particular domain in the mapping requires handling data traffic to or from the particular domain by performing a particular action; based on the mapping, determining one or more IP addresses that are associated with the particular domain; generating policy for a firewall that instructs the firewall to perform the particular action upon receiving a particular request; wherein the particular request specifies a particular IP address that is within the particular domain.