Recursive DNS Traffic Analysis for Cloud Threat Baselines
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud service provider (CSP) environments are highly vulnerable to malicious cyber-attacks due to their distributed and complex nature, posing a significant threat to customer data and requiring improved protection mechanisms.
Innovation Solution
A cloud defense system monitors and analyzes recursive DNS (rDNS) traffic to identify potential threats by tracking regions, virtual cloud networks (VCNs), and host machines, generating baselines to differentiate malicious activity from normal behavior, and initiating protective actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional network monitoring is used in cloud environments, then basic traffic visibility is achieved, but false positives increase and threat detection accuracy decreases due to noise from legitimate traffic
Solution Approach 1:
The patent segments network traffic analysis into multiple hierarchical layers: cloud account level, virtual cloud network (VCN) level, and individual resource level. By dividing the monitoring scope into discrete segments with defined boundaries, the system can analyze traffic patterns at appropriate granularities, reducing noise from unrelated legitimate traffic while maintaining visibility into suspicious activities.
Solution Approach 2:
The patent introduces an intermediary analysis layer that sits between raw network traffic and threat detection outcomes. This intermediary layer uses baseline traffic patterns and contextual information about cloud resource relationships to filter and interpret raw traffic data, thereby reducing false positives while improving accurate threat detection.
2Reliability
If comprehensive network traffic monitoring is implemented, then all suspicious activities can be detected, but system complexity and computational overhead increase significantly
Solution Approach 1:
The monitoring system is segmented into modular components: traffic collection modules, baseline generation modules, analysis modules, and response modules. Each module handles specific aspects of traffic monitoring independently, reducing overall system complexity while maintaining comprehensive monitoring capability through coordinated operation of these segmented components.
Solution Approach 2:
The patent applies partial monitoring action by focusing computational resources on analyzing only the necessary traffic patterns and relationships relevant to threat detection. Rather than analyzing every single packet in detail, the system uses baseline patterns and contextual information to selectively deep-dive into suspicious activities, reducing computational overhead while maintaining detection effectiveness.
3Measurement precision
If detailed analysis of all DNS traffic is performed, then accurate threat identification is achieved, but processing time and system resources are excessively consumed
Solution Approach 1:
The DNS traffic analysis implements partial detailed examination by using baseline traffic patterns to identify normal DNS queries and applying detailed analysis only to queries that deviate from established baselines. This selective approach maintains high threat identification accuracy for suspicious activities while preserving overall processing throughput by quickly dismissing normal traffic.
Solution Approach 2:
The system performs preliminary actions by pre-establishing baseline DNS traffic patterns and resource relationship contexts before actual threat detection occurs. These pre-computed baselines and contextual relationships enable faster real-time analysis by providing ready-reference frameworks against which incoming DNS traffic can be quickly compared, reducing processing time while maintaining accuracy.
Data Source
AI summary
Cyber-security techniques are described for monitoring a cloud environment and can be used to identify potential problems, including malicious threats, to the monitored cloud environment using operational telemetry. Techniques are described for monitoring and collecting data related to reverse or recursive DNS (rDNS) traffic associated with a monitored cloud environment. The recursive DNS traffic includes recursive DNS (rDNS) requests originating from the cloud environment and responses to those requests received from DNS resolvers. This collected data is then analyzed to identify potential threats to the monitored cloud environment. The collected data may be analyzed to identify potential sources of threats and to identify one or more portions of the cloud environment that are the targets of the threats. The analysis may trigger alerts to be generated, actions to be performed (e.g., protective measures), reports to be generated, patterns to be recognized, etc.


