Unlock instant, AI-driven research and patent intelligence for your innovation.

Method and system for improving safety and performance of domain name system (DNS)

A domain name system and performance technology, applied in the field of improving domain name system security and performance, can solve the problems of lack of DNS system security means, lack of prevention technology, and high complexity

Active Publication Date: 2013-06-26
赵家祥
View PDF0 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0008] In the prior art, the common method for DDoS attack is to filter traffic; its limitation is: how to distinguish which traffic is normal and which is illegal (attack purpose) is a very difficult thing
For example, due to the lack of IP addresses (IPv4) on the Internet, many users connect to the Internet through Network Address Translation (NAT), so the traffic generated by these users is from the same IP address from the outside. Source IP address; therefore, it is impossible to distinguish between normal traffic and abnormal traffic simply by judging the source IP address of the traffic; on the other hand, distributed denial of service attacks are closer to traffic generated by normal users from the perspective of source IP Therefore, at present, it can only be dealt with by behavior analysis and other methods, which are highly complex and poor in accuracy. For domain name hijacking, in addition to measures such as strengthening supervision manually by administrators, there is a lack of effective prevention technology
Moreover, these manual interventions are often done after the fact. They are usually discovered and dealt with when a large number of users complain that the service is unavailable. At that time, serious harm has already occurred, losses have been caused and are increasing, and recovery and remediation will also cost more. the price of
[0009] It can be seen from historical data that in recent years, attacks against DNS have been increasing, and the existing technology lacks effective means of DNS system security.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and system for improving safety and performance of domain name system (DNS)
  • Method and system for improving safety and performance of domain name system (DNS)
  • Method and system for improving safety and performance of domain name system (DNS)

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0028] The method and system of the invention aim to improve the security and performance of the DNS system, so that domain name hijacking and DDoS attacks can be effectively resisted. As wrong! Reference source not found. The architecture of the system is shown in the diagram. The DNS system of the present invention includes a load balancer (Load Balancer) and a peer-to-peer working group (node ​​1, node 2, ..., node K) composed of a group of members.

[0029] The entire system presents a DNS IP address to the outside, that is to say, users access the system through a DNS IP address as usual, and the software on the user side does not need to be modified.

[0030] The role of the load balancer is to distribute DNS resolution requests from the Internet to each node, and each node shares the overall traffic. Since each resolution of DNS is a "request / response" (Request / Response), the present invention makes full use of the irrelevance between each domain name resolution, so ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention relates to a method and a system for improving safety and performance of a domain name system (DNS). The system is characterized by comprising an IP address showing one DNS externally, a load equalizer and a peer-to-peer workgroup, wherein the load equalizer is used for distributing DNS resolution requests from the Internet to each node, and each node shares the overall flow; and the peer-to-peer workgroup comprises a group of members: node 1, node 2......node k, and the processes of electing communication coordinators, updating DNS records and arbitrating consistency are mainlycarried out in the workgroup.

Description

technical field [0001] The invention relates to the technical field of network security, in particular to a method and system for improving the security and performance of the domain name system. Background technique [0002] Every day, hundreds of millions of users access the content and applications on the Internet, and at the same time, massive amounts of data are transmitted on the Internet. All of these require the server support provided by the Domain Name System (DNS). [0003] For each user, a meaningful domain name (or host name), such as www.example.com It is easy to remember and easy to use, and it is also necessary for them to access the Internet; on the other hand, for computers on the Internet, an IP address is actually used for communication, such as 208.77.188.166. [0004] On the Internet, it is the domain name system (DNS) that completes the conversion from domain name to IP address; the DNS server will maintain a record of the mapping relationship between...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06H04L29/12H04L12/803
Inventor 赵家祥
Owner 赵家祥