DNS tunnel detection method and DNS tunnel detection device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Publication Date
- 2018-01-05
Smart Images

Figure 1 
Figure 2
Abstract
Description
technical field
[0001] The invention relates to the technical field of the Internet, in particular to a DNS tunnel detection method and a DNS tunnel detection device. Background technique
[0002] Domain Name System (English full name: Domain Name System, English abbreviation: DNS) is one of the most critical basic services of the Internet. It maps domain names and IP addresses to each other, so that people can easily access the Internet without having to memorize complicated IP addresses. The DNS protocol will basically not be intercepted by firewall policies. Even in an enterprise internal network, a DNS server is required for domain name resolution. Moreover, in order to be able to resolve domain names on the Internet, the DNS server within the enterprise needs to communicate with other DNS servers on the Internet. Communication, which creates conditions for the construction of covert channels based on the DNS protocol. Since the DNS tunnel client only needs to request t...