A DNS security protection method, device and server device

By embedding tagged data in the DNS query message and performing matching processing, CNAME-type DNS response message is constructed to block attack traffic, and the problem of slow and prone to failure in the existing technology DNS denial of service attack protection is solved, achieving the effect of quickly identifying and blocking attack traffic.

CN115766143BActive Publication Date: 2025-06-10INTERNET DOMAIN NAME SYST BEIJING ENG RES CENT
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211372453.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-03
Publication Date
2025-06-10
Estimated Expiration
2042-11-03

AI Technical Summary

Technical Problem

The prior art responds slowly when defending against DNS denial of service attacks and is prone to protection failure.

Method used

By receiving DNS query messages, legality detection is performed, unique tag data is generated, and matching tag data is matched based on the subdomain information of the domain name. If it matches, the subdomain information is removed for normal processing; otherwise, a CNAME-type DNS response message is constructed and tagged data is embedded to block attack traffic.

Benefits of technology

It realizes rapid identification and blocking of DNS flood attack traffic, and the response time can reach milliseconds, significantly reducing the rate of attack traffic and avoiding protection failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115766143B_ABST
    Figure CN115766143B_ABST
Patent Text Reader

Abstract

The present application discloses a DNS security protection method, device and server device, which solves the problems of slow protection response and easy protection failure in the prior art. The present application adds a specific handshake authentication process to DNS queries from the client, in which tags are embedded in the packets, and normal users are triggered to perform secondary DNS queries through CNAME records; in this way, the secondary DNS requests of normal users can be successfully matched, and after the embedded tags are stripped, subsequent processing can be carried out according to the normal DNS query processing mechanism; while if the client is an attacker, it will directly discard the received response packet, which is equivalent to blocking the attacker's packet, so that most of the DNS flood attack traffic will be cleaned up, and the recognition and blocking of attack protection can achieve a millisecond-level response.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technologies, and in particular, to a DNS security protection method, apparatus, and server device. Background Art

[0002] The DNS server can provide domain name resolution services for the Internet and is crucial for any network application; at the same time, it also includes very important network configuration information, such as user host names and IP addresses, etc. To improve efficiency, DNS uses a stateless UDP + plaintext method for domain name resolution. Although this domain name resolution method is simple and easy to use and improves the user's domain name access experience, it also creates a breeding ground for illegal network attackers. Therefore, DNS, as a key infrastructure of the Internet, is constantly facing severe security threats.

[0003] Currently, there are many types of DNS security threats, and a large part of them come from denial-of-service attacks such as DoS / DDoS (including but not limited to attacks on DNS servers. Here we only describe the attack protection of DNS types). Most of the existing DNS denial-of-service attack protections currently block or limit the speed of attacks through DNS filters, and there is also statistical analysis based on big data for intelligent identification and protection.

[0004] Most of the current mainstream DNS attack protection algorithms are based on manual or large-traffic analysis to identify attacks, and then block the attacks through filters and other processing. A common problem with this attack identification and processing is that the response to new DNS attack traffic is slow. Taking manual attack identification as an example, new DNS flood attack traffic often goes through the following process before being disposed of:

[0005] DNS DDoS attack occurs ---> Professionals arrive (about 1 hour) ---> Capture attack packets and add rough protection policies (about 1 hour) ---> Manually extract attack characteristics and add fine protection policies (about 30 minutes) ---> Keep observing the attack and adjust the protection policy at any time.

[0006] The above are the empirical value times for all the processing of DDOS attack protection. For general attacks, it usually takes an average of 2 hours from detection to blocking. This relatively common and frequently used protection processing flow seems normal, but it will have a huge negative impact on the businesses of some users. For the intelligent recognition and feature extraction algorithms based on data statistical analysis (traffic analysis and statistics), it will be much optimized. From the detection of attack protection failure to the automatic extraction of features, it often takes at least 6 minutes (5 minutes for monitoring protection failure + 1 minute for automatic feature extraction and configuration generation and distribution). These 6 minutes have been greatly improved compared to the 2 hours of manual processing. However, for some important financial customers, these 6 minutes may also mean losses of millions of yuan. Moreover, the intelligent attack recognition and protection based on traffic analysis and statistics also has a fatal drawback, that is, it is an artificially constructed algorithm model, and there is still a huge gap in judgment compared with humans, and it is very easy to have protection failure. Summary of the Invention

[0007] The present application provides a DNS security protection method, device and server device, which solves the problems of slow protection response and easy protection failure in the prior art.

[0008] To achieve the above objectives, the present application gives the following solutions:

[0009] In a first aspect, a DNS security protection method includes:

[0010] Receiving a DNS query message and performing a legality check on the DNS query message; if the message is legal, proceed to the next step; if the message is illegal, discard the message;

[0011] Generating unique marker data according to the source IP of the DNS query message according to a set algorithm; the domain name of the DNS query message is abbreviated as the first domain name, and determining whether the sub-domain information at a set ordinal position in the first domain name matches the marker data;

[0012] If they match, removing the sub-domain information at the set ordinal position from the message and performing subsequent processing according to the normal DNS query processing mechanism;

[0013] If they do not match, constructing a DNS response message and returning it to the client; the type type recorded in the DNS response message is CNAME, and the domain name in the CNAME is abbreviated as the second domain name, and the second domain name is composed of the first domain name and the marker data, where the marker data is placed as the newly added sub-domain information at the set ordinal position in the second domain name.

[0014] Optionally, generating unique marker data according to a set algorithm is obtaining hash data of a set byte length according to a set hash algorithm.

[0015] Further optionally, the set hash algorithm uses domain name-based hash calculation or hash calculation combining an address and a domain name. The set byte length is 4 bytes.

[0016] Optionally, the set bit order is the first field from the left of the domain name.

[0017] In a second aspect, a DNS protection device includes the following program modules:

[0018] A format check module for performing legality detection on the received DNS query message; if the message is legal, it proceeds to the mark matching module for processing; if the message is illegal, the message is discarded;

[0019] A handshake authentication module for generating unique mark data according to the source IP of the DNS query message according to a set algorithm; the domain name of the DNS query message is abbreviated as the first domain name, and it is judged whether the sub-domain information of the set bit order in the first domain name matches the mark data; if they match, the sub-domain information of the set bit order is removed from the message, and subsequent processing is performed according to the normal DNS query processing mechanism; if they do not match, a DNS response message is constructed and returned to the client; if the type type recorded in the DNS response message is CNAME, and the domain name in the CNAME is abbreviated as the second domain name, then the second domain name is composed of the first domain name and the mark data, where the mark data is placed as the newly added sub-domain information in the set bit order in the second domain name.

[0020] Optionally, generating unique mark data according to the set algorithm is to obtain hash data of a set byte length according to the set hash algorithm.

[0021] Further optionally, the set hash algorithm uses domain name-based hash calculation or hash calculation combining an address and a domain name. The set byte length is 4 bytes.

[0022] Optionally, the set bit order is the first field from the left of the domain name.

[0023] In a third aspect, a server device includes a memory and a processor, the memory stores a computer program, and the special feature is that when the processor executes the computer program, the steps of the above DNS security protection method are implemented.

[0024] This application has at least the following beneficial effects:

[0025] This application adds a specific handshake authentication process to DNS queries from clients. In this process, tags are embedded in the packets, and normal users are triggered to perform secondary DNS queries through CNAME records. In this way, the secondary DNS requests of normal users can be successfully matched. After stripping the embedded tags, subsequent processing can be carried out according to the normal DNS query processing mechanism. However, if the client is an attacker, it will directly discard the response packet after receiving it, which is equivalent to blocking the attacker's packet. Thus, most DNS flood attack traffic will be cleaned up, and the identification and blocking of attack protection can achieve a millisecond-level response. Even if the attacker can initiate a secondary DNS query request, the rate of DNS attack traffic will theoretically be halved.

[0026] According to the security protection method of this application, no special configuration or modification is required for the client. Brief Description of the Drawings

[0027] Figure 1 It is a schematic diagram of an application scenario of an embodiment of this application;

[0028] Figure 2 It is a schematic flow diagram of a DNS security protection method (executed by the server) provided by an embodiment of this application;

[0029] Figure 3 It is a schematic flow diagram of the specific process of the attack protection process of an embodiment of this application. Detailed Embodiments

[0030] In order to make the purpose, technical solutions and advantages of this application clearer, the following further details this application in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.

[0031] This application can be applied to the application scenario as Figure 1 shown: The client 1 communicates with the server 2 through the network. Among them, the client 1 can be, but is not limited to, various personal computers, laptops, smart phones, tablets, DNS servers, etc. that have enabled DNS iterative queries; the server 2 can be implemented by an independent server or a server cluster composed of multiple servers; in the server 2, the DNS security protection method provided by this embodiment can be run on a separately configured computer device, or the corresponding function can be integrated into the aforementioned server.

[0032] This application adds multi-level processing to DNS denial-of-service flood attacks, and the identification and blocking of attack protection can achieve a millisecond-level response. For the convenience of the following description, we define some terms used here:

[0033] DoS: Denial of service attack, the attacker initiates a large number of connection requests to the server through a host, but does not actually use the services provided by the server.

[0034] DDoS: Distributed denial of service attack, the attacker initiates a large number of connection requests to the server through multiple hosts at the same time, but does not actually use the services provided by the server.

[0035] DNS random domain name attack: a type of DoS / DDoS, in which the attacker initiates a large number of random domain name DNS query requests. These DNS query requests are for randomly changing domain names, such as fsefdxcfd.test.com. These domain names may not exist at all. In this case, it is often necessary to query the root server and top authoritative server one by one, but all of them are unsuccessful. Hackers use this method to consume the performance of the DNS server.

[0036] In one embodiment, Figure 2 As shown, a DNS security protection method is provided, including:

[0037] Receive a DNS query message and perform a validity check on the DNS query message; if the message is legal, execute the next step; if the message is illegal, discard the message;

[0038] Generate unique tag data according to the source IP of the DNS query message according to a set algorithm; for example, obtain hash data of a set byte length according to a set hash algorithm (specifically, a hash calculation based on the domain name, or a hash calculation based on a combination of an address and a domain name, to obtain hash data of 4 bytes in length); the domain name of the DNS query message is abbreviated as the first domain name, and determine whether subdomain information of a set bit sequence in the first domain name (for example, the first field from the left of the domain name can be selected) matches the tag data;

[0039] If there is a match, the subdomain information with the set bit sequence is removed from the message, and subsequent processing is performed according to the normal DNS query processing mechanism;

[0040] If there is no match, a DNS response message is constructed and returned to the client; the type of the DNS response message record is CNAME, the domain name in the CNAME is abbreviated as the second domain name, and the second domain name is composed of the first domain name and the tag data, wherein the tag data is placed in the set position sequence in the second domain name as newly added subdomain information.

[0041] This embodiment adds a specific handshake authentication process to DNS queries from the client. During this process, tags are embedded in the packets, and normal users are triggered to perform secondary DNS queries through CNAME records. In this way, the secondary DNS requests of normal users can be successfully matched. After stripping the embedded tags, subsequent processing can be carried out according to the normal DNS query processing mechanism. However, if the client is an attacker, the response packet will be directly discarded after being received, which is equivalent to blocking the attacker's packet. As a result, most DNS flood attack traffic will be cleaned up, and the identification and blocking of attack protection can achieve a millisecond-level response.

[0042] The following combines Figure 3 , taking the DNS random domain name attack as an example, to detail the working principle of this embodiment through specific logic:

[0043] PC host (client) < ------> DNS protection module < ------> DNS server (8.8.8.8)

[0044] 1. A DNS query request for a randomly constructed domain name "wefwef.baidu.com" is sent to the DNS server on a host.

[0045] 2. The DNS protection module receives the DNS query packet and performs a legality check on the packet to confirm whether the packet is a standard DNS query packet. If so, a hash calculation using a specific algorithm (the specific algorithm is not limited, such as hash calculation based on the domain name or a combined calculation method of the address and domain name) is performed on the source IP of the packet, resulting in a 4-byte data. Suppose it is 0x821EF366.

[0046] 3. The domain name field of the DNS packet is retrieved to check whether the first 4 bytes of the domain name field of the packet match the 4-byte hash data obtained in the second step. For the newly received packet, regardless of whether it is an attack packet, the first 4 bytes will not match, and it will enter step 4 for processing.

[0047] 4. Construct a DNS response message. The type of the response record is CNAME. The domain name in the CNAME uses the domain name in the previous DNS query message (here it is wefwef.baidu.com), and directly embed the 4-byte hash data obtained in step 2 into the front of the CNAME domain name in the form of a subdomain, that is, embed it in front of "wefwef.baidu.com". After modification, it becomes "821EF366.wefwef.baidu.com". It can be seen that the domain name of the message has an additional string of 4-byte hash data and a dot character '.', and return the DNS response message to the PC host (a fixed DNS response message template can be used to improve efficiency).

[0048] 5. If the PC host is an attacker, it will directly discard the message after receiving the response message, which is equivalent to blocking the attacker's message here. If the PC host is a normal user, it will enter step 6 for processing.

[0049] 6. After the PC host of a normal user receives the CNAME response returned by the DNS protection module, it will not directly discard the message, but read the data of the message and initiate a new DNS query request. The domain name for the query is the new domain name "821EF366.wefwef.baidu.com" with 4-byte hash data embedded at the beginning of the domain name in step 4.

[0050] 7. The DNS protection module will receive the DNS query request sent by the PC host again and perform the matching process in step 3, that is, calculate the hash of the source IP of the message and match the obtained data with the first 4 bytes of the dns query domain name. At this time, the match will succeed.

[0051] 8. After the dns request domain name initiated by the PC host for the second time matches the 4-byte hash value, the dns security module will remove the previously embedded 4-byte hash data and the dot character '.' from the message, and then perform subsequent processing on the DNS query message according to the normal DNS query process, such as directly sending it to the DNS server or directly starting recursive DNS query operations, etc. If the server returns a result, then notify the PC host of the result returned by the server.

[0052] In one embodiment, a DNS protection device (DNS protection module) is further provided, including the following program sub-modules:

[0053] A format check module, used to perform legality detection on the received DNS query message; if the message is legal, transfer it to the mark matching module for processing; if the message is illegal, discard the message;

[0054] A handshake authentication module is used to generate unique marker data according to the source IP of the DNS query message. The domain name of the DNS query message is abbreviated as the first domain name, and it is determined whether the sub-domain information at a set ordinal position in the first domain name matches the marker data. If they match, the sub-domain information at the set ordinal position is removed from the message, and subsequent processing is performed according to the normal DNS query processing mechanism. If they do not match, a DNS response message is constructed and returned to the client. If the type type recorded in the DNS response message is CNAME, and the domain name in the CNAME is abbreviated as the second domain name, then the second domain name is composed of the first domain name and the marker data, where the marker data is placed at the set ordinal position in the second domain name as the newly added sub-domain information.

[0055] For the specific optimization of the DNS protection device, reference can be made to the example description of the DNS protection method in the above text, which will not be elaborated here.

[0056] In one embodiment, a server device is further provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above DNS security protection method are implemented. This server device can be a separately configured computer device (connected to the server), or a DNS protection module added to the server.

[0057] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

Claims

1. A DNS security protection method, characterized in that, it includes: Receiving a DNS query message and performing a legality check on the DNS query message; If the message is legal, proceed to the next step; If the message is illegal, discard the message; Generating unique marker data according to the source IP of the DNS query message by a set algorithm; the domain name of the DNS query message is abbreviated as the first domain name, and determining whether the sub-domain information of the set bit order in the first domain name matches the marker data; If they match, remove the sub-domain information of the set bit order from the message and perform subsequent processing according to the normal DNS query processing mechanism; If they do not match, construct a DNS response message and return it to the client; the type type recorded in the DNS response message is CNAME, and the domain name in CNAME is abbreviated as the second domain name, then the second domain name is composed of the first domain name and the marker data, where the marker data is placed as the newly added sub-domain information in the set bit order in the second domain name.

2. The DNS security protection method according to claim 1, characterized in that, The generating unique marker data according to the set algorithm is to obtain hash data of a set byte length according to the set hash algorithm.

3. The DNS security protection method according to claim 2, characterized in that, The set hash algorithm adopts hash calculation based on the domain name or hash calculation of the combination of the address and the domain name.

4. The DNS security protection method according to claim 2, characterized in that, The set byte length is 4-byte length.

5. The DNS security protection method according to claim 1, characterized in that, The set bit order is the first field from the left of the domain name.

6. A DNS protection device, characterized in that, it includes the following program modules: A format check module for performing a legality check on the received DNS query message; if the message is legal, transfer it to the marker matching module for processing; if the message is illegal, discard the message; A handshake authentication module for generating unique marker data according to the source IP of the DNS query message by a set algorithm; the domain name of the DNS query message is abbreviated as the first domain name, and determining whether the sub-domain information of the set bit order in the first domain name matches the marker data; if they match, remove the sub-domain information of the set bit order from the message and perform subsequent processing according to the normal DNS query processing mechanism; if they do not match, construct a DNS response message and return it to the client; the type type recorded in the DNS response message is CNAME, and the domain name in CNAME is abbreviated as the second domain name, then the second domain name is composed of the first domain name and the marker data, where the marker data is placed as the newly added sub-domain information in the set bit order in the second domain name.

7. The DNS protection device according to claim 6, characterized in that, The generating unique marker data according to the set algorithm is to obtain hash data of a set byte length according to the set hash algorithm.

8. The DNS protection device according to claim 7, characterized in that, the set hash algorithm adopts hash calculation based on the domain name or hash calculation of the combination of the address and the domain name.

9. The DNS protection device according to claim 6, characterized in that, the set ordinal is the first field from the left of the domain name.

10. A server device, comprising a memory and a processor, and the memory stores a computer program, characterized in that, when the processor executes the computer program, the steps of the DNS security protection method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Method for detecting DNS (domain name system) covert channels

    CN102624706A

  • DNS (Domain Name System) transparent proxy method, device and equipment and storage medium

    CN109561172A