Domain name system negative caching method, domain name query system, device and storage medium
By merging the security records in the domain name system into sparse security records and using filter technology, the problem of traditional domain name systems denying large amount of data and security risks in the cache is solved, and efficient query and security enhancement are achieved.
Patent Information
- Application Number
- CN202510296882.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-07-18
AI Technical Summary
In the traditional domain name system negative cache mechanism, each domain name needs to generate an independent NSEC record, resulting in a huge amount of cached data and low query efficiency. The NSEC record exposes the information of all domain names in the zone file, which poses security risks.
Through an authoritative server, the next next security records in the area file are merged into a sparse security record, including the starting domain name, the terminating domain name and K-1 real domain name. The K-1 real domain name and the combination of the domain name and record type is stored in the filter, and the filter is added to the data part of the sparse security record. The recursive server receives the client's domain name resolution request, query whether there is a sparse security record covering the domain name to be matched in the cache, check whether the domain name to be matched and the combination with the domain name to be matched record type exists in the filter, and outputs the negative cache query result based on the inspection results.
It realizes more efficient negative cache matching, reduces the exposure of zone information, improves query efficiency, and effectively prevents random domain name attacks, reducing the processing workload of authoritative services.
Smart Images

Figure CN120342657A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of domain name systems, and in particular, to a method for negative caching of domain name systems, a domain name query system, a device, and a storage medium. Background Art
[0002] When a client accesses a web page, the client performs domain name resolution through a Domain Name System (DNS) server to obtain the domain name corresponding to the web page, and then accesses the web page according to the domain name. DNS servers are divided into two types: authoritative servers and recursive servers. Authoritative servers provide authoritative data, and recursive servers obtain data from authoritative servers and forward it to the querying client. A user's domain name resolution request is first sent to the recursive service. Recursion usually sets up a local cache to improve the resolution performance. If the resolution request hits the cache, the result can be directly returned to the user; if it misses the cache, a recursive query is initiated to the authoritative service. For a resolution request for a non-existent domain name or type, the resolution system will return a negative response, indicating that the queried domain name or type does not exist. The cache search and matching methods for this type of resolution (i.e., negative caching) include exact matching and range matching based on NSEC records. Exact matching means that the query will hit only when the queried domain name and type are the same as those in the cache. Since non-existent domain names have the characteristics of being used once and non-enumerable, the efficiency of negative caching with exact matching is very low. In the scenario of random domain name attacks, the attack traffic can easily penetrate the recursive cache, causing great pressure on the authoritative service. Range matching based on NSEC records is when DNS Security Extensions (DNSSEC) is enabled. When querying a non-existent domain name, the authoritative service returns an NSEC record (the NSEC record indicates that there is no domain name within a certain range of the domain name space), which is used to prove that the queried domain name does not exist. However, the domain names indicating the start and end of the range in the NSEC record actually exist. Through multiple queries for non-existent domain names, malicious queryers can obtain all the domain name information in the zone. That is, the NSEC record will expose all the domain name information in the zone file, posing a security risk. Summary of the Invention
[0003] The present invention provides a method for negative caching of domain name systems, a domain name query system, a device, and a storage medium, so as to solve the defects of the traditional domain name system negative caching mechanism that an independent NSEC record needs to be generated for each domain name, resulting in a large amount of cached data and low query efficiency, and the NSEC record exposes all the domain name information in the zone file, posing a security risk.
[0004] The present invention provides a method for negative caching of domain name systems, including: Merge K consecutive next security records in the zone file into a sparse security record through an authoritative server. The sparse security record includes a starting domain name, an ending domain name, and K - 1 real domain names; Store the K - 1 real domain names and the combination of the domain name and record type in a filter, and add the filter to the data part of the sparse security record; Receive a domain name resolution request from a client through a recursive server, and query whether there is a sparse security record in the cache that covers the domain name to be matched; if it exists, check whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse security record, and output a negative cache query result according to the check result.
[0005] According to the domain name system negative cache method provided by the present invention, the step of checking whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse security record and outputting a negative cache query result according to the check result includes: If neither the domain name to be matched nor the combination of the domain name to be matched and the type exists in the filter, directly generate a negative response and return it to the client; If the domain name to be matched exists in the filter, but the combination of the domain name to be matched and the type does not exist in the filter, generate a negative response indicating that the type does not exist; If the domain name to be matched exists in the filter and the combination of the domain name to be matched and the type also exists in the filter, send a request to the authoritative server to query the record type to obtain the final resolution result.
[0006] According to the domain name system negative cache method provided by the present invention, the filter includes a probabilistic filter. The step of storing the K - 1 real domain names and the combination of the domain name and record type in the filter includes: Calculate the hash values of the K - 1 real domain names and the hash value of the combination of the domain name and record type, and store the hash values of the K - 1 real domain names and the hash value of the combination of the domain name and record type in the probabilistic filter.
[0007] According to the domain name system negative cache method provided by the present invention, it further includes: verifying the negative response returned by the authoritative server through the recursive server; When the domain name to be matched falls within the sparse security record and the filter check returns that the domain name does not exist, it is determined as a negative response.
[0008] According to the domain name system negative cache method provided by the present invention, the domain name is a multi - level domain name. The step of merging K consecutive security record intervals into a sparse security record includes: Perform multi-level expansion on the multi-level domain names, compare the results of the multi-level expansion with the domain names already existing in the zone file for duplicate checking, and discard if there are duplicates; Combine the expanded domain names with the corresponding record types and store them in the filter of the sparse security records; if a domain name does not have any record types, store the domain name in the filter of the sparse security records.
[0009] According to the domain name system negative cache method provided by the present invention, the sparse security records are dynamically adjusted when the zone file is updated, specifically including: If a new domain name is added to the zone file, insert the domain name into the corresponding sparse security record filter. If the number of domain names in the interval exceeds the preset maximum threshold, split the sparse security records; If a domain name is deleted from the zone file, remove the entry from the corresponding filter. If the number of domain names in the interval is lower than the preset minimum threshold, merge adjacent security record intervals and regenerate the sparse security records.
[0010] According to the domain name system negative cache method provided by the present invention, if a domain name is deleted from the zone file, it further includes: If the deleted domain name is the starting domain name of the sparse security record, modify the starting domain name of the sparse security record to the ending domain name of the previous sparse security record and regenerate the sparse security record.
[0011] The present invention also provides a domain name query system, including: An authoritative server, configured to merge K consecutive next security records in the zone file into one sparse security record, where the sparse security record includes a starting domain name, an ending domain name, and K - 1 real domain names; store the K - 1 real domain names and the combination of the domain name and the record type in a filter, and add the filter to the data part of the sparse security record; A recursive server, configured to receive a domain name resolution request from a client, query whether there is a sparse security record covering the domain name to be matched in the cache; if so, check whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse security record, and output a negative cache query result according to the check result.
[0012] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor implements the domain name system negative cache method as described in any one of the above when executing the program.
[0013] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored, and the computer program implements the domain name system negative cache method as described in any one of the above when executed by a processor.
[0014] The DNS negative caching method, domain name query system, device and storage medium provided by the present invention merge K consecutive Next Secure records in the zone file into a sparse secure record by an authoritative server. The sparse secure record includes a starting domain name, an ending domain name, and K-1 real domain names; the K-1 real domain names and the combination of the domain name and the record type are stored in a filter, and the filter is added to the data part of the sparse secure record; a recursive server receives a domain name resolution request from a client, and checks whether there is a sparse secure record covering the domain name to be matched in the cache; if so, checks whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse secure record, and outputs a negative caching query result according to the check result. By means of the improved large interval range expression method, the present invention can achieve more efficient negative caching matching and avoid excessive exposure of zone information at the same time. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1 is a schematic flowchart of the DNS negative caching method provided by an embodiment of the present invention; Figure 2 is a schematic diagram comparing the sNSEC and NSEC record formats provided by an embodiment of the present invention; Figure 3 is a schematic flowchart of the authoritative service processing the resolution request provided by an embodiment of the present invention; Figure 4 is a schematic flowchart of the recursive service synthesizing a negative response provided by an embodiment of the present invention; Figure 5 is a schematic flowchart of the recursive service processing the NXDOMAIN response provided by an embodiment of the present invention; Figure 6 is a schematic diagram comparing the negative caching hit rates in the random subdomain attack scenario provided by an embodiment of the present invention; Figure 7 is a schematic diagram of the functional structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without making creative efforts shall fall within the protection scope of the present invention.
[0018] Figure 1 The flowchart of the domain name system negative caching method provided by the embodiment of the present invention is as Figure 1 shown. The domain name system negative caching method provided by the embodiment of the present invention includes: Step 101: Merge K consecutive next secure records in the zone file into a sparse secure record through an authoritative server. The sparse secure record includes a starting domain name, an ending domain name, and K-1 real domain names; In the embodiment of the present invention, a new resource record type, sparse secure record (sNSEC), is introduced to improve the existing NSEC record data format (RDATA). A "probabilistic filter" field is appended after the "List of Type Bitmap" field in the original NSEC data to store information about the existence of domain names within the interval, as Figure 2 shown.
[0019] When the authoritative service signs the zone file, only one sNSEC record needs to be signed for every K domain names (only the (nK + 1)-th domain name needs to be signed, n = 0, 1, 2,...). For the other K-1 domain names within the interval, the domain name and its combination with the record type are inserted into the filter, and the filter is attached to the NSEC record data part to form an sNSEC record.
[0020] By merging NSEC record intervals, a large-range expression of NSEC records can be generated, reducing the security risk of information exposure.
[0021] Step 102: Store the K-1 real domain names and the combination of the domain name and the record type in the filter, and add the filter to the data part of the sparse secure record; Step 103: Receive a domain name resolution request from a client through a recursive server, and query whether there is a sparse secure record in the cache that covers the domain name to be matched; if it exists, check whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse secure record, and output a negative caching query result according to the check result.
[0022] In an embodiment of the present invention, the recursive server performs a negative scope matching based on the sNSEC record cache for the queried domain name. The matching process includes interval matching and filter checking. If a hit occurs, a negative response is directly synthesized without having to initiate a query to the authoritative server, reducing the workload of the authoritative server's zone file signature processing.
[0023] The traditional negative caching mechanism generates an NSEC record for each domain name in the zone file. The domain name and the next adjacent domain name form the start and end points of an interval range, forming an interval range between adjacent domain names. By searching and matching this interval range, a negative response is generated. This small-range expression negative caching has low efficiency. In the scenario of random domain name attacks, the attack traffic can easily penetrate the recursive cache, causing great pressure on the authoritative service. Moreover, there is a risk of NSEC record exposure.
[0024] The domain name system negative caching method provided by the embodiment of the present invention combines K consecutive next-secure records in the zone file by the authoritative server into a sparse secure record. The sparse secure record includes a start domain name, an end domain name, and K - 1 real domain names; the K - 1 real domain names and the combination of the domain name and the record type are stored in a filter, and the filter is added to the data part of the sparse secure record; the recursive server receives a domain name resolution request from the client and queries whether there is a sparse secure record covering the domain name to be matched in the cache; if it exists, it checks whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse secure record, and outputs a negative cache query result according to the check result. The embodiment of the present invention can achieve more efficient negative cache matching through an improved large-interval range expression, while avoiding excessive exposure of zone information.
[0025] Based on any of the above embodiments, the checking whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse secure record, and outputting a negative cache query result according to the check result includes: Step 201, if neither the domain name to be matched nor the combination of the domain name to be matched and the type exists in the filter, directly generate a negative response and return it to the client; Step 202, if the domain name to be matched exists in the filter, but the combination of the domain name to be matched and the type does not exist in the filter, generate a negative response indicating that the type does not exist; In the traditional scheme using NSEC records, as long as the queried domain name qname falls within the interval range of a certain NSEC in the cache, it is considered a match, or a negative cache hit. In the embodiment of the present invention, the range matching not only requires that qname falls within the interval range of sNSEC, but also requires that qname does not exist in the filter attached to the sNSEC record.
[0026] Step 203: If the domain name to be matched exists in the filter and the combination of the domain name to be matched and the type also exists in the filter, send a query record type request to the authoritative server to obtain the final resolution result.
[0027] In an embodiment of the present invention, if the domain name qname falls within the range of the sNSEC and the query filter shows its existence, at this time, it can continue to query whether the combined domain name of qname+type exists in the filter. If it does not exist, it can be determined that (qname, type) does not exist, and the corresponding negative response can be directly synthesized recursively. Since there is a possibility of false positives in the judgment that qname exists, it is impossible to determine what type of negative it is here, and an authoritative query is required to further determine.
[0028] In an embodiment of the present invention, the filter includes a probabilistic filter, and the probabilistic filter includes a Bloom filter, a Cuckoo filter, etc. Storing the K-1 real domain names and the combination of the domain name and the record type into the filter includes: Calculate the hash values of the K-1 real domain names and the hash value of the combination of the domain name and the record type, and store the hash values of the K-1 real domain names and the hash value of the combination of the domain name and the record type into the probabilistic filter.
[0029] In an embodiment of the present invention, insert the domain name itself and the combination of the domain name and the type into the filter. First, check whether the domain name itself exists in the filter. If it does not exist, it can be determined as the NXDOMAIN type; if it exists, continue to check whether the domain name type combination exists. If it does not exist, it is probably the NODATA type.
[0030] In some embodiments of the present invention, the domain name system negative cache method further includes: verifying the negative response returned by the authoritative server through the recursive server; When the domain name to be matched falls within the sparse security record and the filter check returns that the domain name does not exist, it is determined as a negative response.
[0031] In the traditional solution, the authoritative server queries the zone file database. If the qname exists, it returns a positive response; if the qname does not exist, it finds the NSEC record in the matching interval and attaches the NSEC record corresponding to the wildcard form of the qname, and returns a NXDOMAIN negative response. When the authoritative service returns a negative response, it needs to provide proof of non-existence. Due to the possibility of false positives in the filter, a very small number of non-existent domain names cannot provide proof of non-existence based on sNSEC due to false positives. At this time, the authoritative service can return servfail (resolution failure) or fallback to the original NSEC to provide proof of non-existence. The recursive server verifies the negative response returned by the authoritative server, that is, it needs to satisfy both a) the qname falls within the interval range indicated by the sNSEC; b) the filter check returns that the qname does not exist. This verification mechanism can prevent man-in-the-middle replay attacks.
[0032] In the embodiment of the present invention, as Figure 3 shown, if the qname does not exist, find the sNSEC record in the matching interval, and at the same time, it is necessary to check whether the qname exists in the filter of this interval. If it exists, it means that the filter check result of this qname is a false positive, and this sNSEC record cannot prove the non-existence of the qname. At this time, the authoritative server should return servfail or fallback to the traditional solution to return the corresponding negative response. If the check shows non-existence, then return a NXDOMAIN negative response containing two sNSEC records.
[0033] Based on any of the above embodiments, the domain name is a multi-level domain name, and the merging of K consecutive security record intervals into one sparse security record includes: Perform multi-level expansion on the multi-level domain name, compare the multi-level expansion result with the domain names already existing in the zone file, and discard it if there is a repetition; Combine the expanded domain name with the corresponding record type and store it in the filter of the sparse security record; if the domain name does not have any record type, store the domain name in the filter of the sparse security record.
[0034] In the embodiment of the present invention, in the process of zone file signature processing, the steps of generating sNSEC records include: 1) Set the NSEC record step parameter K, for example, K = 100, indicating that one sNSEC record is generated for every 100 domain names; 2) Set the filter parameter: Calculate the filter size S (bytes) according to the expected false positive (FP) probability, or directly set the filter size to S; 3) After sorting (sorting by the original NSEC), starting from the zone apex, traverse the domain names in the zone file in sequence. The (n*K + 1)th (n = 0, 1, 2, 3, …) domain name generates an sNSEC record. The starting point of the interval indicated by the record is the current domain name, and the ending point of the interval is the next domain name for which an sNSEC record needs to be generated, that is, the ((n + 1)*K + 1)th domain name. The domain names within the interval (including the starting and ending domain names) are expanded and combined according to the following steps: 3a) Multi-level domain name expansion: If the domain name is multi-level, such as a.b.c.example.com (the zone apex is example.com), the domain name needs to be expanded in sequence to c.example.com, b.c.example.com, a.b.c.example.com, and then exclude the domain names that already exist in the zone file (duplicate removal).
[0035] 3b) Domain name and type combination: Combine the expanded domain names with the corresponding types. For example, if there are two record types, A and AAAA, for xxx.example.com, three domain names xxx.example.com, xxxA.example.com, and xxxAAAA.example.com are formed after combination. If there is no record for the domain name, only the domain name is retained. The combination method is not limited to direct splicing, and other methods such as xxx_A.example.com, xxx+A.example.com, etc. are also acceptable.
[0036] 4) Insert all the expanded and combined domain names (except the starting and ending domain names) covered by this interval into the filter and append them to the sNSEC data segment.
[0037] Based on any of the above embodiments, the sparse security record is dynamically adjusted when the zone file is updated, specifically including: If a new domain name is added to the zone file, insert the domain name into the corresponding sparse security record filter. If the number of domain names within the interval exceeds the preset maximum threshold, split the sparse security record; If a domain name is deleted from the zone file, remove the entry from the corresponding filter. If the number of domain names within the interval is lower than the preset minimum threshold, merge adjacent security record intervals and regenerate the sparse security record.
[0038] According to the domain name system negative cache method provided by the present invention, if a domain name is deleted from the zone file, it further includes: If the deleted domain name is the starting domain name of the sparse security record, modify the starting domain name of the sparse security record to the ending domain name of the previous sparse security record and regenerate the sparse security record.
[0039] In the embodiments of the present invention, the method for processing domain name or record modification includes: 1) When a new domain name (qname) or record (type) is added to the zone file, the newly added qname and type are expanded and combined, and then inserted into the filter. If the expanded domain name exists (duplicate domain name), the duplicates are merged first, and then the expanded domain name is inserted into the filter.
[0040] 2) When a domain name or record is deleted from the zone file, the corresponding sNSEC range for that domain name is found, and the deletion operation is performed in the original zone file. Then, the remaining domain names in that range are regenerated into new sNSEC records according to the above process. The cuckoo filter can directly delete the domain name, while the Bloom filter needs to be regenerated. If the deleted domain name is the starting point of the range, the ending domain name of the previous range's sNSEC record also needs to be modified, and the sNSEC record needs to be regenerated.
[0041] 3) Splitting and merging of sNSEC ranges. After multiple addition and deletion operations, the number of domain names in each sNSEC range may deviate significantly from the initial set value K. For an overly large range, it can be split into two or more ranges; for an overly small range, it can be merged with adjacent ranges to regenerate sNSEC. The goal of splitting and merging is to make the number of domain names in each sNSEC range as close as possible to the set value K.
[0042] In the traditional solution for handling a client's domain name resolution request, if the recursive negative response synthesis function such as RFC8198 is enabled, RFC8198 uses a DNSSEC-verified cache. DNSSEC is a security extension protocol used to ensure the integrity of DNS query and response data. The recursive process checks if there is an NSEC record range in the cache that covers the qname. If it exists, it means the negative cache range match is successful, and the recursive process can directly generate an NXDOMAIN negative response and return it to the user.
[0043] In the embodiments of the present invention, as Figure 4As shown, after querying for sNSEC records that match the range in the cache, it is necessary to extract the filter from the sNSEC. First, check and confirm that there are no NS records for each level of domain name between the qname and the zone apex. This step requires expanding the qname first, combining the domain names between the zone apex and the qname with NS, and then querying the filter. For example, assume the qname is 1.2.3.example.com and the zone apex is example.com. Check in turn whether 3NS.example.com and 2NS.example.com exist in the filter. Only when the query results are all non-existent can the next step be carried out; otherwise, abort the synthetic response processing and perform a normal outbound recursive query. Then check whether the qname exists in the filter. If it does not exist, it can be determined that the qname does not exist, and the recursive process can generate a NXDOMAIN negative response and return it to the user. If the qname exists in the filter, combine the qname with the type and check again whether the filter exists. If it does not exist, it means that the qname does not exist or the type does not exist. At this time, return a negative response (NXDOMAIN / NODATA cannot be distinguished, but it can be determined that the qname+type combination does not exist); if it exists, it means that (qname, type) may exist, and the recursive process needs to query the authoritative service to further determine.
[0044] When processing the negative response returned by the authoritative service, in the traditional scheme, the negative response (NXDOMAIN) returned by the authoritative server includes two NSEC records (if the two records are the same, only one is included). The recursive process needs to check whether the qname and its wildcard domain name can be covered by the intervals of the NSEC records respectively.
[0045] As shown in the embodiments of the present invention Figure 5 As shown, in addition to checking that the interval of the sNSEC can cover the qname, it is also necessary to extract the filter of the sNSEC record and check and confirm that the qname does not exist in the filter. If it exists, this sNSEC record cannot prove that the qname does not exist, and the recursive process should discard this response. This checking mechanism can effectively prevent man-in-the-middle replay attacks on actually existing domain names.
[0046] An example of the domain name system negative caching method is illustrated as follows: The domain names in a certain sNSEC interval of the zone example.com are as follows: a.example.com A 1.1.1.1 (starting) b.example.com A 1.1.1.1 c.example.com NS 2.2.2.2 x.d.example.com A 1.1.1.1 x.e.example.com A 1.1.1.1 (Terminated) After expanding and combining the domain names within the interval (including the start and end), the following are obtained (in sequence): a.example.com (start point of the interval) aA.example.com (duplicates bitmap information, this combined domain name may not be inserted into the filter) b.example.com bA.example.com c.example.com cNS.example.comd.example.com x.d.example.com xA.d.example.com e.example.com x.e.example.com (end point of the interval) xA.e.example.com (outside the interval range) Insert the combined domain names within the interval range above into the filter, and the formed sNSEC records are as follows: a.example.com sNSEC e.example.com [Type bitmap] [Filter data] Case where the queried domain name does not exist (initial recursive cache is empty): The user queries (b1.example.com, A), the cache misses, and recursively queries the authority (b1.example.com, A). The authority does not find the domain name and returns a negative response of domain name does not exist (NXDOMAIN), and attaches the sNSEC record of a.example.com as proof. After the recursive receives the negative response, it conducts a non-existence verification. After passing, it caches the sNSEC record and returns a negative response of domain name does not exist to the user, and this parsing is completed.
[0047] Case where the queried domain name does not exist (already cached): The user queries (b2.example.com, A). Since b2 falls within the (a, e) interval, the recursive hits the sNSEC cache. After extracting the filter, it checks that the combined b2A.example.com does not exist in the filter and directly generates a negative response to return to the user, and this parsing is completed.
[0048] Query for the case where the domain name does not exist (random subdomain attack scenario): The user queries (b3.example.com, A), and the recursive processing is exactly the same as that for b2.example.com.
[0049] Query for the case where both the domain name and the type exist: The user queries (b.example.com, A). Since b falls within the interval (a, e), the sNSEC cache is recursively hit. Combining the domain name and the type gives bA.example.com. Checking this domain name in the filter shows its existence. Recursively querying the authoritative server for (b.example.com, A), the authoritative server returns a positive response (the A record of b.example.com). Recursively caching this positive response and returning it to the user, this parsing is completed.
[0050] Query for the case where the domain name exists but the type does not: The user queries (b.example.com, AAAA). Since b falls within the interval (a, e), the sNSEC cache is recursively hit. Combining the domain name and the type gives bAAAA.example.com. Checking this domain name in the filter shows its non-existence. Recursively generating a negative response and returning it to the user, this parsing is completed.
[0051] Query for the case of a multi-level domain name 1: The user queries (a.b.c.example.com, A), hitting the sNSEC cache. After extracting the filter, expand a.b.c.example.com and sequentially query cNS.example.com and bNS.c.example.com in the filter. Since cNS.example.com exists, abort the cache query processing and perform an external recursive query.
[0052] Query for the case of a multi-level domain name 2: The user queries (a.b.c1.example.com, A), hitting the sNSEC cache. After extracting the filter, expand a.b.c1.example.com and sequentially query c1NS.example.com and bNS.c.example.com in the filter, both of which do not exist. Continuing to query a.b.c1.example.com in the filter also shows its non-existence. Directly generating a negative response and returning it to the user, this parsing is completed.
[0053] In the original NSEC scheme, it is easy for attackers to obtain all domain names in the zone file. In this scheme, taking K = 100 as an example (generating one sNSEC record for every 100 domain names), even if attackers can obtain all sNSEC records, only 1% of the domain names are leaked. Other domain names are stored in the filter after being hashed and processed, making it difficult for attackers to crack and restore the domain name information. And it can greatly improve the negative caching efficiency. The sNSEC interval merges K intervals of the original NSEC. A larger single interval range means higher caching efficiency. The experimental results are as Figure 6 shown that the negative caching efficiency (hit rate) of sNSEC can reach twice that of the original NSEC.
[0054] The difference between NSEC3 records and NSEC records is that the domain names indicating the start and end of the range are hashed, and the opt-out option is supported, allowing real domain names that do not support DNSSEC to exist within the range. After turning off the opt-out option, the present invention can also be used for NSEC3, and the steps are similar to those of NSEC.
[0055] The domain name system negative caching method provided by the embodiments of the present invention effectively avoids the leakage of zone file information and reduces the workload of signing the authoritative zone file. In the original NSEC scheme, an NSEC record needs to be generated and signed for each domain name. Taking K = 100 as an example, the number of sNSEC records is only 1% of the original. Generating the filter involves several hash operations. Generally, the workload of zone signing is smaller than that of the original NSEC scheme. Therefore, the size of the signed zone file can be reduced, and the loading speed of the zone file can be improved. It has a defensive effect against flooding attacks of the NXDOMAIN and NODATA types. After combining the existing domain names and types and inserting them into the filter, it can detect whether the combination of qname + type exists. If it is confirmed that it does not exist, the corresponding response can be quickly generated to prevent the attack traffic from flowing to the authoritative service.
[0056] Next, the domain name query system provided by the present invention will be described. The domain name query system described below can be mutually corresponding and referred to with the domain name system negative caching method described above.
[0057] The domain name query system provided by the embodiments of the present invention includes: An authoritative server, configured to merge K consecutive next-secure records in the zone file into one sparse secure record, where the sparse secure record includes a start domain name, an end domain name, and K - 1 real domain names; store the K - 1 real domain names and the combination of the domain name and the record type into a filter, and add the filter to the data part of the sparse secure record; A recursive server is configured to receive a domain name resolution request from a client and query whether there is a sparse security record in the cache that covers the domain name to be matched. If so, it checks whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse security record, and outputs a negative cache query result according to the check result.
[0058] In the domain name query system provided by the embodiments of the present invention, an authoritative server is configured to merge K consecutive next security records in a zone file into one sparse security record. The sparse security record includes a start domain name, an end domain name, and K - 1 real domain names; store the K - 1 real domain names and the combination of the domain name and the record type in a filter, and add the filter to the data part of the sparse security record; a recursive server is configured to receive a domain name resolution request from a client and query whether there is a sparse security record in the cache that covers the domain name to be matched. If so, it checks whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse security record, and outputs a negative cache query result according to the check result. The embodiments of the present invention can improve the efficiency of recursive negative caching in the domain name system, effectively intercept random domain name attack traffic, solve the problem that NSEC is prone to disclose zone file information, and reduce the workload of signature processing for the authoritative server zone file.
[0059] Figure 7 FIG. shows a schematic physical structure diagram of an electronic device. Figure 7 As shown in the figure, the electronic device may include: a processor 710, a communication interface 720, a memory 730, and a communication bus 740. Among them, the processor 710, the communication interface 720, and the memory 730 communicate with each other through the communication bus 740. The memory 730 includes a computer program, an operating system, and acquired data. The processor 710 can call the logical instructions in the memory 730 to execute the domain name system negative caching method, which includes: merging K consecutive next security records in a zone file into one sparse security record through an authoritative server, where the sparse security record includes a start domain name, an end domain name, and K - 1 real domain names; storing the K - 1 real domain names and the combination of the domain name and the record type in a filter, and adding the filter to the data part of the sparse security record; receiving a domain name resolution request from a client through a recursive server and querying whether there is a sparse security record in the cache that covers the domain name to be matched. If so, it checks whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse security record, and outputs a negative cache query result according to the check result.
[0060] In addition, when the logical instructions in the above-mentioned memory 730 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the related art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.
[0061] On the other hand, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the domain name system negative caching method provided by the above-mentioned various methods. The method includes: merging K consecutive next-safe records in a zone file into a sparse safe record by an authoritative server, where the sparse safe record includes a starting domain name, an ending domain name, and K - 1 real domain names; storing the K - 1 real domain names and the combination of the domain name and the record type in a filter, and adding the filter to the data part of the sparse safe record; receiving a domain name resolution request from a client by a recursive server, and querying whether there is a sparse safe record in the cache that covers the domain name to be matched; if it exists, checking whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse safe record, and outputting a negative caching query result according to the check result.
[0062] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.
[0063] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution or the part that contributes to the relevant technology can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0064] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for negative caching in a Domain Name System, characterized in that, Including: Combining K consecutive next security records in the zone file into one sparse security record by an authoritative server, where the sparse security record includes a starting domain name, an ending domain name, and K-1 real domain names; Storing the K-1 real domain names and the combination of domain name and record type into a filter, and adding the filter to the data part of the sparse security record; Receiving a domain name resolution request from a client through a recursive server, and querying whether there is a sparse security record covering the domain name to be matched in the cache; If it exists, check whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse security record, and output a negative cache query result according to the check result.
2. The domain name system negative caching method according to claim 1, characterized in that The checking whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse security record, and outputting a negative cache query result according to the check result includes: If neither the domain name to be matched nor the combination of the domain name to be matched and the type exists in the filter, directly generate a negative response and return it to the client; If the domain name to be matched exists in the filter, but the combination of the domain name to be matched and the type does not exist in the filter, generate a negative response indicating that the type does not exist; If the domain name to be matched exists in the filter and the combination of the domain name to be matched and the type also exists in the filter, initiate a query record type request to the authoritative server to obtain the final resolution result.
3. The method for negative caching of a domain name system according to claim 1 or 2, characterized in that The filter includes a probabilistic filter, and the storing the K-1 real domain names and the combination of domain name and record type into the filter includes: Calculating the hash values of the K-1 real domain names and the hash value of the combination of domain name and record type, and storing the hash values of the K-1 real domain names and the hash value of the combination of domain name and record type into the probabilistic filter.
4. The method for negative caching of a domain name system according to claim 1, wherein Also including: Verifying the negative response returned by the authoritative server through the recursive server; When the domain name to be matched falls within the sparse security record and the filter check returns that the domain name does not exist, it is determined as a negative response.
5. The method for negative caching of a domain name system according to claim 1, characterized in that, The domain name is a multi-level domain name, and the combining K consecutive security record intervals into one sparse security record includes: Performing multi-level expansion on the multi-level domain name, comparing the multi-level expansion result with the domain names already existing in the zone file for duplicate checking, and discarding if there are duplicates; Combining the expanded domain name with the corresponding record type, and storing it into the filter of the sparse security record; if the domain name does not have any record type, store the domain name into the filter of the sparse security record.
6. The method for negating caching of a domain name system according to claim 1, characterized in that, The sparse security record is dynamically adjusted when the zone file is updated, specifically including: If a new domain name is added to the zone file, insert the domain name into the corresponding sparse security record filter. If the number of domain names within the interval exceeds the preset maximum threshold, split the sparse security record; If a domain name is deleted from the zone file, remove the entry from the corresponding filter. If the number of domain names within the interval is lower than the preset minimum threshold, merge adjacent security record intervals and regenerate the sparse security record.
7. The method for negating caching of a domain name system according to claim 1, wherein If a domain name is deleted from the zone file, it also includes: If the deleted domain name is the starting domain name of a sparse security record, modify the starting domain name of the sparse security record to the ending domain name of the previous sparse security record, and regenerate the sparse security record.
8. A domain name query system, characterized in that, Including: An authoritative server for merging K consecutive next security records in a zone file into a sparse security record, where the sparse security record includes a starting domain name, an ending domain name, and K - 1 real domain names; storing the K - 1 real domain names and the combination of the domain name and record type into a filter, and adding the filter to the data part of the sparse security record; A recursive server for receiving a domain name resolution request from a client and querying whether there is a sparse security record in the cache that covers the domain name to be matched; If it exists, check whether the combination of the domain name to be matched and the record type of the domain name to be matched exists in the filter of the sparse security record, and output a negative cache query result according to the check result.
9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the domain name system negative cache method according to any one of claims 1 to 7.
10. A non-transitory readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by a processor, it implements the domain name system negative cache method according to any one of claims 1 to 7.