URL Reputation Scoring for DNS Security in Tiered Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Domain Name System (DNS) protocol is vulnerable to malicious activities, such as covert channels and botnets, which compromise network integrity and security, making it difficult to distinguish trustworthy from untrustworthy redirection targets in a tiered web delivery network.
Innovation Solution
A method using a processor to validate attributes of a Uniform Resource Locator (URL) and establish a reputation score, classifying it as benign, malignant, suspicious, or malicious, by employing DNS response resource record botnet signature detection analysis, IP address attribution, and domain-IP cross verification against intelligence databases, to ensure only trustworthy destinations receive name resolution requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If DNS protocol is used for name resolution in a tiered web delivery network, then network communication efficiency is improved, but vulnerability to malicious activities such as covert channels and botnets increases
Solution Approach 1:
The patent introduces an intermediary verification system that sits between the DNS protocol and the web delivery network. This intermediary validates URL attributes and establishes reputation scores before allowing name resolution requests to proceed, thereby maintaining DNS communication efficiency while blocking malicious activities through an additional security layer
Solution Approach 2:
The system performs preliminary verification of URL attributes and establishes reputation scores before DNS name resolution requests are processed. By pre-validating attributes and pre-assessing trustworthiness, the system prevents malicious requests from reaching the DNS protocol, thus maintaining efficiency while enhancing security
2Reliability
If URL validation and reputation scoring are implemented, then network security is improved, but system complexity increases
Solution Approach 1:
The patent segments the security verification process into distinct modular components: attribute validation module, reputation score establishment module, and URL classification module. Each module handles a specific aspect of verification, making the overall complex system manageable through functional segmentation and independent development of each component
Solution Approach 2:
The verification system is designed as a universal multi-functional platform that can validate multiple types of URL attributes, assess reputation across different classification criteria, and integrate with various DNS implementations. This universal approach consolidates multiple security functions into a single system, reducing overall complexity compared to having separate specialized systems
Data Source
AI summary
Embodiments for verifying trustworthiness of redirection targets in a tiered delivery computing network by at least a portion of a processor. A degree of trustworthiness for a uniform resource locator (URL) is determined by validating at least one attribute of the URL to establish a reputation score of the URL. The URL is classified, using the reputation score, into one of a plurality of classifications to indicate the degree of trustworthiness.


