Root DNS Server Malicious Domain Detection via Statistical Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack an efficient method for DNS operators to detect and remediate malicious domain names within their namespace, requiring extensive resources and complex relationships between network operators.

Innovation Solution

A system that analyzes DNS query patterns at the authoritative name server, top-level domain name server, and root name server levels to monitor and classify DNS traffic, utilizing statistical features and a knowledge database to identify malicious domain names, allowing for rapid detection and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If DNS operators monitor DNS traffic at lower hierarchy levels (AUTH NS, TLD NS), then detection capability is improved, but operational costs and complexity increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidoperational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transitions from monitoring at lower DNS hierarchy levels (AUTH NS, TLD NS) to monitoring at the upper hierarchy level (root NS). This dimensional change in the monitoring position enables operators to observe global DNS query patterns without the operational complexity of deploying sensors at multiple lower-level nodes across different network operators.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If DNS operators deploy sensors at multiple lower-level nodes, then detection coverage is improved, but privacy concerns and operational difficulties increase

Engineering Contradiction:
Improvedetection coverageVSAvoidoperational ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent makes the root name server perform multiple functions: it continues to provide its primary DNS resolution service while simultaneously serving as a monitoring point for detecting malicious domain names. This eliminates the need for separate sensor deployments at multiple locations, reducing operational complexity and privacy concerns while maintaining global detection coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If extensive resources are allocated for monitoring, then detection accuracy is improved, but resource consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent leverages the root name server's existing infrastructure, computational resources, and traffic flow to perform monitoring functions. The system uses statistical analysis of DNS query patterns that naturally pass through the root server, eliminating the need for dedicated monitoring hardware and reducing overall resource consumption while maintaining high detection accuracy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9686291B2Method and system for detecting malicious domain names at an upper DNS hierarchy
Publication Date: 2017.06.20 FORTRA LLC
  • US9686291B2 patent drawing
  • US9686291B2 patent drawing
  • US9686291B2 patent drawing

AI summary

A method and system for detecting a malicious domain name, comprising: collecting domain name statistical information from a non-recursive domain name system name server (RDNS NS); and utilizing the collected domain name statistical information to determine if a domain name is malicious or benign.