Response Policy Zone Context Embedding for DNS Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current response policy zones (RPZs) in DNS systems do not provide context for on-line threats associated with malicious domain names, making it tedious and error-prone to determine appropriate mitigation strategies, as they rely on manual correlation with threat databases and lack contextual information.

Innovation Solution

A method that determines threat characteristics using threat intelligence to generate aliases and DNS resource records, which are transmitted to DNS name servers, enabling context-aware DNS responses that correlate malicious domain names with their associated threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If manual correlation with threat database is used, then contextual information can be obtained, but the process becomes tedious and time consuming

Engineering Contradiction:
Improvecontextual informationVSAvoidtime consuming
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-generating alias DNS resource records that embed threat context information before actual DNS queries occur. The RPZ system pre-processes threat intelligence data and creates mapping records (e.g., CNAME records) that link malicious domain names to alias names containing encoded threat characteristics. When a DNS query matches a malicious domain, the pre-prepared alias record immediately provides contextual information without requiring real-time manual correlation or additional database lookups, thus eliminating time loss while preserving complete contextual data.

Inventive Principle:
Principle #10Preliminary action

2Extent of automation

If manual configuration of correlation application is used, then automatic identification is achieved, but the system remains error prone and lacks effectiveness

Engineering Contradiction:
Improveautomatic identificationVSAvoiderror prone
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent applies self-service by enabling the DNS system to automatically correlate malicious domain names with threat context through self-updating RPZ configurations. The system automatically receives threat intelligence feeds, parses threat characteristics, generates appropriate alias records, and updates the RPZ configuration without human intervention. This automated self-service mechanism eliminates manual configuration errors while maintaining high reliability through consistent application of correlation rules and automatic validation of threat intelligence data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback by creating a closed-loop system where DNS query results and threat intelligence data continuously inform RPZ configuration updates. The system monitors DNS queries for matches against known malicious domains, receives updated threat intelligence feeds, and automatically adjusts the alias records and RPZ configurations based on this feedback. This continuous feedback loop ensures the system remains accurate and reliable by constantly updating its correlation rules based on the latest threat data and observed query patterns.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If threat database categorization is used, then threat classification is provided, but additional contextual information such as severities is not indicated

Engineering Contradiction:
Improvethreat categorizationVSAvoidcontextual information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent applies the nested doll principle by embedding multiple layers of threat context information within the alias name structure. The alias records contain encoded threat characteristics including threat category, severity level, and other contextual attributes nested within the DNS resource record format. For example, an alias might encode: domain-name.malware-category.severity-level.threat-family, creating a nested information structure where each layer provides additional contextual detail about the threat, thereby preserving comprehensive information while maintaining DNS protocol compatibility.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10440059B1Embedding contexts for on-line threats into response policy zones
Publication Date: 2019.10.08 VERISIGN INC
  • US10440059B1 patent drawing
  • US10440059B1 patent drawing
  • US10440059B1 patent drawing

AI summary

In one embodiment, a response policy zone (RPZ) application generates an RPZ that includes contexts for the on-line threats that are associated with domain names. For a domain name that is associated with an on-line threat, the RPZ application determines a threat specification that describes a characteristic of the on-line threat. The RPZ application then generates an alias based on the domain name and the threat specification. Subsequently, the RPZ application generates a domain name system (DNS) resource record that maps the domain name to the alias, includes the resource record in the RPZ, and transmits the RPZ to a DNS name server that implements the RPZ. Upon receiving a DNS query associated with the domain name, the DNS name server generates a DNS response based on the alias. Because the domain name and the threat specification is reflected in the alias, the DNS response automatically provides a relevant context.