Recursive DNS Cache Seeding Using Threat Intelligence Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Populating a DNS cache for a recursive DNS server after restart or initialization is a time-consuming and resource-intensive process, leading to significant performance degradation.
Innovation Solution
A method and system that utilizes a threat intelligence system to provide query-answer pairs to populate the DNS cache of a recursive DNS server, applying filters based on geographic location, time-to-live, and popularity, thereby reducing the need for the server to query other DNS servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a recursive DNS server uses traditional caching population methods after restart or initialization, then the DNS cache can be populated, but the process is time-consuming and resource-consuming, leading to performance degradation
Solution Approach 1:
The patent applies preliminary action by pre-collecting and storing DNS query-answer pairs in a threat intelligence system before the recursive DNS server needs to operate. When the server restarts or initializes, these pre-collected data are immediately available for cache population, eliminating the need for time-consuming real-time queries during the critical initialization phase.
Solution Approach 2:
The threat intelligence system serves as an intermediary between the recursive DNS server and the broader DNS infrastructure. It collects DNS data from various sources and provides it to the recursive DNS server, acting as a mediator that reduces the server's direct communication overhead with other DNS servers during cache population.
2Measurement precision
If a recursive DNS server queries other DNS servers to resolve queries, then accurate IP address resolution is achieved, but query processing capacity is limited during cache population
Solution Approach 1:
The system performs preliminary DNS data collection and storage in the threat intelligence system before the recursive DNS server needs to process queries. This pre-computed data is then immediately available for cache population, allowing the server to handle queries at full capacity without needing to perform time-consuming external queries during initialization.
Solution Approach 2:
The patent employs copying by creating a replica of DNS query-answer pairs in the threat intelligence system that can be efficiently copied to the recursive DNS server's cache. This copying approach allows rapid cache population without requiring the server to perform original DNS resolution queries for each entry, thereby increasing query processing capacity while maintaining resolution accuracy.
3Speed
If the DNS cache is populated by collecting DNS data from network communications, then cache population speed increases, but the system complexity increases due to threat intelligence system integration
Solution Approach 1:
The threat intelligence system is designed with multi-functionality, serving both security purposes (threat detection and intelligence gathering) and DNS cache population purposes. This universal approach allows the same system to fulfill multiple roles, increasing cache population speed while limiting the increase in overall system complexity through shared infrastructure.
Solution Approach 2:
The threat intelligence system acts as an intermediary layer that simplifies the interaction between the recursive DNS server and the broader network infrastructure. By centralizing data collection and processing in this intermediary system, the patent reduces the complexity of direct integration requirements between multiple components, enabling faster cache population through a single coordinated interface.
Data Source
AI summary
The present application describes systems and methods for populating a DNS cache of a recursive DNS server using information gathered by a threat intelligence system. The threat intelligence system may collect some or all DNS responses from one or more recursive DNS servers as the one or more DNS servers process various received requests. Since the threat intelligence engine has access to this DNS data, the DNS data may be used to seed a DNS cache of a recursive DNS server.


