Roaming DNS Firewall for Malicious DNS Server Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Roaming client computers face risks when connecting to unsecure networks, as traditional firewalls cannot distinguish malicious DNS servers, and maintaining a VPN connection is cumbersome, leaving user data vulnerable to man-in-the-middle attacks.
Innovation Solution
A roaming DNS firewall system that characterizes network parameters, receives a safe network profile, and modifies DNS identifiers to ensure secure connections by using trusted DNS servers, even when outside a verified network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall functionality is used, then basic network protection is provided, but malicious DNS servers cannot be distinguished from legitimate ones
Solution Approach 1:
The patent introduces an intermediary component that acts as a DNS firewall between the client computer and DNS servers. This intermediary monitors and controls DNS queries, blocking malicious DNS servers while allowing legitimate ones to function. It mediates between the need for basic firewall protection and the requirement to distinguish trustworthy DNS servers, resolving the contradiction by adding a specialized intermediary layer that provides advanced DNS filtering without requiring complete redesign of firewall functionality.
Solution Approach 2:
The patent segments the network security function by separating DNS firewall capabilities from traditional firewall functionality. The DNS firewall operates as a distinct module that specifically handles DNS queries and responses, allowing it to apply specialized trust evaluation logic independent of general network filtering. This segmentation enables the system to provide reliable DNS server verification without increasing overall firewall complexity, as the DNS-specific logic is isolated in its own component.
2Reliability
If VPN connections are maintained to protect against man-in-the-middle attacks, then network security is improved, but connection establishment time increases and user convenience decreases
Solution Approach 1:
The patent implements preliminary action by pre-establishing trust relationships with legitimate DNS servers before the client computer needs to query them. The DNS firewall maintains a cache of trusted DNS server identifiers and pre-evaluates DNS responses for authenticity. This allows the system to provide VPN-level security protection without requiring actual VPN connection establishment, as the trust verification is performed in advance through the DNS firewall's cached credentials and response validation mechanisms.
Solution Approach 2:
The patent extracts the essential security function from VPN connections and isolates it into the DNS firewall component. Instead of requiring full VPN protocol overhead and connection establishment, the DNS firewall extracts only the critical trust verification and encryption functions needed to protect DNS queries. This extraction provides comparable security benefits to VPN while eliminating the time-consuming connection setup process, as the DNS firewall operates independently without requiring VPN tunnel establishment.
3Ease of operation
If DHCP is used to assign DNS servers automatically, then network configuration ease is improved, but the ability to identify malicious DNS servers is lost
Solution Approach 1:
The patent implements feedback mechanisms where the DNS firewall continuously monitors DNS query responses and compares them against cached trusted server identifiers. When a DNS response is received, the firewall provides feedback by validating the source identifier against known trusted servers and blocking responses from untrusted sources. This feedback loop maintains ease of DHCP operation while simultaneously enabling reliable malicious DNS server identification, as the automatic configuration is supplemented by continuous validation feedback from the DNS firewall component.
Solution Approach 2:
The patent introduces dynamics by making the DNS server trust evaluation adaptive rather than static. The DNS firewall dynamically updates its cache of trusted DNS server identifiers based on ongoing network observations and security events. This dynamic approach allows the system to maintain ease of operation with automatic DHCP configuration while adapting to new threats and legitimate DNS servers over time, resolving the contradiction by making the identification process flexible and responsive rather than fixed.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A roaming domain name system (DNS) firewall is provided for execution by an endpoint agent provided on a mobile computing device. The increase of the mobile workforce presents security challenges as mobile computer devices are regularly connecting to unknown, untrusted or unverified networks. These networks can present security risks to organizations by routing URL resolutions requests to malicious DNS servers that may be utilized for redirecting traffic to unsafe hosts. A roaming DNS firewall on the mobile computing device monitors access to networks to determine if the network is deemed safe or unsafe based upon associated network parameters. In response to the determination of an unsafe network the DNS identifiers are modified or trusted to a trusted DNS to ensure DNS requests are not processed by a malicious DNS host.