Root DNS Server Malicious Domain Detection via Statistical Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack an efficient method for DNS operators to detect and remediate malicious domain names within their namespace, requiring extensive resources and complex relationships between network operators.
Innovation Solution
A system that analyzes DNS query patterns at the authoritative name server, top-level domain name server, and root name server levels to monitor and classify DNS traffic, utilizing statistical features and a knowledge database to identify malicious domain names, allowing for rapid detection and remediation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If DNS operators monitor DNS traffic at lower hierarchy levels (AUTH NS, TLD NS), then detection capability is improved, but operational costs and complexity increase
Solution Approach 1:
The patent transitions from monitoring at lower DNS hierarchy levels (AUTH NS, TLD NS) to monitoring at the upper hierarchy level (root NS). This dimensional change in the monitoring position enables operators to observe global DNS query patterns without the operational complexity of deploying sensors at multiple lower-level nodes across different network operators.
2Measurement precision
If DNS operators deploy sensors at multiple lower-level nodes, then detection coverage is improved, but privacy concerns and operational difficulties increase
Solution Approach 1:
The patent makes the root name server perform multiple functions: it continues to provide its primary DNS resolution service while simultaneously serving as a monitoring point for detecting malicious domain names. This eliminates the need for separate sensor deployments at multiple locations, reducing operational complexity and privacy concerns while maintaining global detection coverage.
3Measurement precision
If extensive resources are allocated for monitoring, then detection accuracy is improved, but resource consumption increases
Solution Approach 1:
The patent leverages the root name server's existing infrastructure, computational resources, and traffic flow to perform monitoring functions. The system uses statistical analysis of DNS query patterns that naturally pass through the root server, eliminating the need for dedicated monitoring hardware and reducing overall resource consumption while maintaining high detection accuracy.
Data Source
AI summary
A method and system for detecting a malicious domain name, comprising: collecting domain name statistical information from a non-recursive domain name system name server (RDNS NS); and utilizing the collected domain name statistical information to determine if a domain name is malicious or benign.


