Recursive DNS Signal Analysis for Cloud Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud service provider (CSP) environments are highly vulnerable to malicious cyber-attacks due to their distributed nature and complexity, posing a significant threat to customer data and requiring innovative protection methods.

Innovation Solution

A cloud defense system monitors and analyzes recursive DNS (rDNS) traffic to identify potential threats by tracking regions, virtual cloud networks (VCNs), and host machines, generating baselines to differentiate malicious activity from normal behavior, and initiating protective actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional monitoring methods are used in distributed cloud environments, then system complexity is reduced, but threat detection precision deteriorates due to the distributed and complex nature of cloud environments

Engineering Contradiction:
Improvethreat detection precisionVSAvoidcloud environment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a cloud defense system as an intermediary layer between DNS resolvers and the cloud environment. This mediator collects, normalizes, and analyzes rDNS request data from multiple sources, transforming complex distributed threat signals into structured intelligence that improves detection precision without requiring changes to the underlying complex cloud infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimensional layer of analysis by collecting rDNS request data from multiple DNS resolvers simultaneously. Instead of monitoring a single DNS pathway, the system aggregates data across multiple dimensions (different resolvers, different regions), enabling threat detection through multi-dimensional pattern recognition that transcends the complexity of individual cloud environments.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive monitoring of rDNS traffic is implemented, then threat detection capability is improved, but data processing volume increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddata processing volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the critical elements from raw rDNS traffic data - specifically the request data containing source IP addresses, domain names, and response information. By extracting and focusing on these key threat-indicating elements rather than processing entire data streams, the system maintains high threat detection capability while reducing overall data processing volume.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges data from multiple DNS resolvers into a unified analysis stream. By combining rDNS request data from different resolvers and consolidating threat intelligence, the system achieves comprehensive threat detection coverage while processing data in an integrated manner that reduces redundant processing and optimizes resource utilization.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12621314B2DNS recursive PTR signals analysis
Publication Date: 2026.05.05 ORACLE INT CORP
  • US12621314B2 patent drawing
  • US12621314B2 patent drawing
  • US12621314B2 patent drawing

AI summary

Cyber-security techniques are described for monitoring a cloud environment and identifying potential problems, including malicious threats, to the monitored cloud environment using operational telemetry. Techniques are described for monitoring and collecting data related to reverse or recursive DNS (rDNS) traffic associated with a monitored cloud environment. The recursive DNS traffic includes recursive DNS (rDNS) requests originating from the cloud environment and responses to those requests received from DNS resolvers. This collected data is then analyzed to identify potential threats to the monitored cloud environment. The collected data may be analyzed to identify potential sources of threats and to identify one or more portions of the cloud environment that are the targets of the threats. The analysis may trigger alerts to be generated, actions to be performed (e.g., protective measures), reports to be generated, patterns to be recognized, etc.