Proxy Appliance DNS Snooping for Spyware Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security measures are inadequate in effectively preventing spyware and web-based malware from infiltrating and spreading within enterprise networks, with over 80% of corporate PCs infected and less than 10% of corporations deploying perimeter spyware defenses.
Innovation Solution
A proxy appliance is deployed to monitor and filter network traffic, utilizing multiple spyware scanning engines, web reputation filters, and dynamic vectoring techniques to detect and block malicious content, while also employing DNS snooping and caching to enhance performance and accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple spyware scanning engines are deployed to scan HTTP responses, then the detection capability and security reliability are improved, but the processing time and system complexity increase
Solution Approach 1:
The patent applies partial action by selectively scanning only certain HTTP responses based on content type and source reputation. The system identifies and scans only responses that contain potential spyware indicators, rather than scanning all responses uniformly. This selective approach reduces the overall scanning time while maintaining effective detection of malicious content.
Solution Approach 2:
The patent segments the spyware detection process into multiple specialized scanning engines, each targeting specific types of malicious content. By dividing the scanning task into specialized components that operate in parallel on different response segments, the system achieves comprehensive coverage without linearly increasing total processing time.
2Reliability
If multiple spyware scanning engines are deployed to scan HTTP responses, then the detection capability and security reliability are improved, but the device complexity increases
Solution Approach 1:
The patent implements multi-functionality by designing a unified scanning architecture where a single HTTP response can be evaluated by multiple scanning engines simultaneously. The system manages diverse scanning engines through a common interface that handles content analysis, reputation checking, and threat detection, reducing operational complexity despite having multiple engines.
Solution Approach 2:
The patent merges multiple scanning engines into a coordinated system where results from different engines are aggregated and evaluated together. The combination of multiple detection mechanisms is managed through a unified decision-making process that determines whether content should be blocked or allowed, simplifying the overall system management.
3Measurement precision
If DNS snooping and caching are employed to enhance performance, then the measurement precision and filtering accuracy are improved, but the device complexity increases
Solution Approach 1:
The patent applies preliminary action through DNS snooping that occurs before HTTP response scanning. The system pre-evaluates the reputation of requested domains and caches these reputation scores. When subsequent requests target the same domain, the cached reputation information is used to quickly determine whether scanning is necessary, improving detection accuracy without adding proportional complexity to each request handling.
Data Source
AI summary
A data processing apparatus, comprising at least one processor and a traffic monitor comprising logic which, when executed by the processor, causes the processor to perform: creating, using forward Domain Name System (DNS) lookups, a mapping of domain names to Internet Protocol (IP) addresses; determining whether a particular domain in the mapping requires handling data traffic to or from the particular domain by performing a particular action; based on the mapping, determining one or more IP addresses that are associated with the particular domain; generating policy for a firewall that instructs the firewall to perform the particular action upon receiving a particular request; wherein the particular request specifies a particular IP address that is within the particular domain.


