Domain name security protection method and device, computer equipment and storage medium
By intercepting and matching the domain name query request of the recursive server and generating response information, the network attack problem of the root server is solved, and security protection and load reduction are achieved.
Patent Information
- Application Number
- CN202510832081.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-06-18
AI Technical Summary
Root servers face resolution errors and network attacks caused by malicious attacks. Traditional defense methods rely on physical resources and have low security protection efficiency.
By intercepting the domain name query request of the recursive server, resolving the target top-level domain name, matching it with the local preset top-level domain name, generating a response message and sending it to the recursive server, avoiding sending requests directly to the root server.
It achieves network security protection for the root server, reduces processing volume, alleviates load pressure, and improves the stability and reliability of the domain name system.
Smart Images

Figure CN120602455A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and specifically to a domain name security protection method, apparatus, computer equipment, and storage medium. Background Art
[0002] With the rapid development of Internet technology, the Domain Name System (DNS), as a core component of the Internet, undertakes the important task of resolving domain names into IP addresses. Root servers are the core infrastructure of the DNS, responsible for authoritatively resolving top-level domains (such as .com, .cn, and .org) worldwide.
[0003] However, the root servers of the DNS (including 13 logical roots and thousands of physical root instances) are also facing increasingly severe security threats. On the one hand, malicious attackers could launch hijacking attacks to tamper with or delete top-level domain information in the root server zone file records, resulting in the inability to correctly resolve subdomains under the corresponding top-level domain, with serious consequences. On the other hand, malicious attackers could launch network attacks against the root servers by launching a large number of top-level domain query requests, thereby affecting the stability and reliability of the DNS service.
[0004] In related technologies, traditional root server network attack defense methods rely on stacking the physical resources of root servers and combining them with load balancing to resist large-scale network attacks. However, this is difficult to operate and manage, and the security protection efficiency is low. Summary of the Invention
[0005] The embodiments of the present application provide a domain name security protection method, apparatus, computer equipment, and storage medium, which can protect the root server to achieve protection of the top-level domain name.
[0006] To achieve the above objectives, an embodiment of the present application provides a domain name security protection method, which includes:
[0007] Intercepting a domain name query request message sent by a recursive server to a root server, and parsing the domain name query request message to determine a target top-level domain name that the recursive server needs to query;
[0008] Matching the target top-level domain name with multiple preset top-level domain names to obtain a matching result;
[0009] When the matching result indicates a successful match, determining a target top-level domain configuration parameter corresponding to the target top-level domain according to a mapping relationship between the preset top-level domain and the preset top-level domain configuration parameter;
[0010] Generate domain name response information corresponding to the target top-level domain name according to the target top-level domain name configuration parameters and the domain name query request information, and send the domain name response information to the recursive server.
[0011] To achieve the above objectives, an embodiment of the present application provides a domain name security protection device, comprising:
[0012] An interception module is used to intercept domain name query request information sent by the recursive server to the root server, and parse the domain name query request information to determine the target top-level domain name that the recursive server needs to query;
[0013] A matching module, configured to match the target top-level domain name with a plurality of preset top-level domain names to obtain a matching result;
[0014] a determination module configured to determine, when the matching result indicates a successful match, a target top-level domain name configuration parameter corresponding to the target top-level domain name based on a mapping relationship between the preset top-level domain name and the preset top-level domain name configuration parameter;
[0015] A generating module is configured to generate domain name response information corresponding to the target top-level domain name according to the target top-level domain name configuration parameters and the domain name query request information, and send the domain name response information to the recursive server.
[0016] In some embodiments, the determining module is configured to:
[0017] Determine the data transmission protocol type corresponding to the domain name query request information;
[0018] The target top-level domain configuration parameter corresponding to the target top-level domain is determined according to the mapping relationship between the preset top-level domain name and the preset top-level domain configuration parameter, and the data transmission protocol type.
[0019] In some embodiments, a generating module is configured to:
[0020] Determining a target data structure according to the target top-level domain configuration parameters;
[0021] Obtaining a transaction identification number, a media access control address, a source Internet Protocol address, a destination Internet Protocol address, a source port number, and a destination port number from the domain name query request information;
[0022] The transaction identification number, the media access control address, the source Internet Protocol address, the destination Internet Protocol address, the source port number and the destination port number are respectively set in the fields corresponding to the target data structure to obtain domain name response information corresponding to the target top-level domain name.
[0023] In some embodiments, a generating module is configured to:
[0024] Setting the transaction identification number, the media access control address, the source Internet Protocol address, the destination Internet Protocol address, the source port number, and the destination port number in corresponding fields of the target data structure, respectively, to obtain initial domain name response information;
[0025] The initial domain name response information is verified to generate a verification value, and domain name response information corresponding to the target top-level domain name is generated according to the verification value and the initial domain name response information.
[0026] In some embodiments, the domain name security protection device further includes a configuration module for:
[0027] Before matching the target top-level domain with the plurality of preset top-level domains to obtain a matching result, obtaining the plurality of preset top-level domains and preset top-level domain configuration parameters of each preset top-level domain;
[0028] A mapping relationship between each preset top-level domain name and the preset top-level domain name configuration parameter is generated and saved.
[0029] In some embodiments, the configuration module is configured to:
[0030] Before matching the target top-level domain with the plurality of preset top-level domains to obtain a matching result, determining a target preset top-level domain with updated preset top-level domain configuration parameters among the plurality of preset top-level domains;
[0031] A new version of the preset top-level domain name configuration parameters corresponding to the target preset top-level domain name is obtained, and the preset top-level domain name configuration parameters corresponding to the target preset top-level domain name are updated using the new version of the preset top-level domain name configuration parameters.
[0032] In some embodiments, the configuration module is configured to:
[0033] Determining a target Internet Protocol address corresponding to the recursive server according to the domain name query request information;
[0034] Determining, based on the target Internet Protocol address, a total number of times the recursive server sends request information to the root server within a preset time period, and a sending frequency per unit time;
[0035] When the total number of times and the sending frequency do not meet the preset safety conditions, generating abnormal response information according to the domain name query request information, and sending the abnormal response information to the recursive server;
[0036] When the total number of times and the sending frequency meet the preset security conditions, the step of matching the target top-level domain name with a plurality of preset top-level domain names to obtain a matching result is performed.
[0037] In some embodiments, the domain name security protection device further includes a forwarding module configured to:
[0038] After matching the target top-level domain name with a plurality of preset top-level domain names to obtain a matching result, when the matching result indicates a matching failure, forwarding the domain name query request information to the root server;
[0039] Receive domain name response information returned by the root server according to the domain name query request information, and forward the domain name response information to the recursive server.
[0040] In some embodiments, the forwarding module is configured to:
[0041] Get the number of query request information processed within a preset time period;
[0042] When the number is greater than a preset number, forwarding the domain name query request information to the root server;
[0043] Receive domain name response information returned by the root server according to the domain name query request information, and forward the domain name response information to the recursive server.
[0044] In order to achieve the above-mentioned purpose, an embodiment of the present application provides a computer-readable storage medium on the one hand, which stores multiple instructions, and the instructions are suitable for a processor to load to execute the domain name security protection method provided by the embodiment of the present application.
[0045] In order to achieve the above-mentioned objectives, an embodiment of the present application provides a computer device on the one hand, including a memory, a processor, and a computer program stored in the memory and capable of running on the processor. When the processor executes the computer program, the domain name security protection method provided in the embodiment of the present application is implemented.
[0046] In an embodiment of the present application, a domain name query request message sent by a recursive server to a root server is intercepted and the domain name query request message is parsed to determine a target top-level domain name that the recursive server needs to query; the target top-level domain name is matched with multiple preset top-level domain names to obtain a matching result; when the matching result indicates a successful match, target top-level domain name configuration parameters corresponding to the target top-level domain name are determined based on a mapping relationship between the preset top-level domain name and the preset top-level domain name configuration parameters; domain name response information corresponding to the target top-level domain name is generated based on the target top-level domain name configuration parameters and the domain name query request message, and the domain name response information is sent to the recursive server.
[0047] In this way, the domain name query request information sent by the recursive server to the root server is intercepted, and then parsed to determine the target top-level domain name that the recursive server needs to query, and then the target top-level domain name is matched with multiple preset top-level domain names that have been saved locally. Then, if the match is successful, the target top-level domain name configuration parameters corresponding to the target top-level domain name are determined according to the mapping relationship between the preset top-level domain name and the preset top-level domain name configuration parameters; the domain name response information corresponding to the target top-level domain name is generated according to the target top-level domain name configuration parameters and the domain name query request information, and the domain name response information is sent to the recursive server. This avoids the recursive server directly sending the domain name query request information to the root server, which can prevent the root server from being attacked by the network, thereby achieving network security protection for the root server, and achieving network security protection for the top-level domain name. At the same time, it also reduces the root server's processing capacity for domain name query request information, alleviating the load pressure on the root server.
[0048] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present application. The purposes and other advantages of the present application can be achieved and obtained through the structures particularly pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0050] Figure 1 This is a schematic diagram of the system framework corresponding to the domain name security protection method provided in the embodiment of the present application;
[0051] Figure 2 This is a scenario diagram of the domain name security protection method provided by an embodiment of the present application;
[0052] Figure 3 This is a flowchart of a domain name security protection method provided by an embodiment of the present application;
[0053] Figure 4 is a schematic diagram of the data structure provided in an embodiment of the present application;
[0054] Figure 5 This is another flowchart of the domain name security protection method provided by an embodiment of the present application;
[0055] Figure 6This is a schematic diagram of the structure of the domain name security protection device provided in an embodiment of the present application;
[0056] Figure 7 It is a structural diagram of the computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0057] In order to enable those skilled in the art to better understand the solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of this application.
[0058] It should be noted that in each specific embodiment of this application, when it comes to the need to perform relevant processing based on domain name query request information, the user's permission or consent will be obtained first, and the collection, use and processing of such data will comply with relevant laws, regulations and standards. In addition, when the embodiment of this application needs to obtain the user's sensitive personal information, the user's separate permission or consent will be obtained through a pop-up window or by jumping to a confirmation page. After clearly obtaining the user's separate permission or consent, the necessary user-related data for the normal operation of the embodiment of this application will be obtained.
[0059] It should be noted that some processes described in the specification, claims, and figures above include multiple steps that appear in a specific order. However, it should be understood that these steps may be executed in a different order than the order in which they appear herein or in parallel. The step numbers are used solely to distinguish between the different steps and do not themselves represent any order of execution. Furthermore, terms such as "first," "second," or "target" are used herein to distinguish similar objects and are not necessarily used to describe a specific order or precedence.
[0060] The embodiments of the present application provide a domain name security protection method, device, computer equipment and storage medium. Specifically, the embodiments of the present application will be described from the dimension of the domain name security protection device, and the domain name security protection device can be specifically integrated in a computer device, which can be a server or a terminal and other devices. Among them, the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. Among them, the terminal can be a programmable device, a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, a smart home appliance, a car terminal, an intelligent voice interaction device, an aircraft, etc., but is not limited to this.
[0061] Before further explaining the embodiments of the present application in detail, the nouns and terms involved in the embodiments of the present application are explained. The nouns and terms involved in the embodiments of the present application are subject to the following interpretations:
[0062] Recursive Server: A key component of the Domain Name System (DNS) architecture, a recursive server is primarily responsible for processing user domain name resolution requests and completing the resolution process through recursive queries. It acts as a bridge between users and other DNS servers (such as root servers, top-level domain servers, and authoritative servers). It initiates queries on behalf of users to other servers until it obtains the final IP address or resolves a failed domain, and then returns the result to the user.
[0063] Root Server: The root server is the cornerstone of the Domain Name System (DNS) architecture. It is responsible for storing and managing the address information of top-level domain (TLD) servers and is an indispensable first-level node in the DNS resolution process. When a recursive server cannot directly obtain the domain name resolution result through the local cache or authoritative server, it must first initiate a query to the root server, which will guide the next query direction (such as informing the corresponding top-level domain server address). There are currently 13 groups of root servers in the world (logically divided into 13 letter identifiers from A to M), managed by different organizations and distributed in multiple data centers around the world using Anycast technology to ensure high availability and anti-attack.
[0064] A Field-Programmable Gate Array (FPGA) is an integrated circuit chip that can be programmed and configured using a hardware description language (HDL). It is a form of semi-custom hardware. Users can program it to implement specific digital logic functions according to their needs. It consists of a large number of programmable logic cells, programmable wiring resources, and input and output units. Through programming, these resources can be flexibly configured and connected to implement a variety of digital circuit functions such as counters, adders, and communication protocol processing modules. It has a wide range of applications in electronic design, for example, in communications equipment for high-speed data processing and protocol conversion.
[0065] User Datagram Protocol (UDP): A connectionless, unreliable transport layer protocol, UDP is a core member of the TCP / IP protocol stack. Unlike the connection-oriented TCP, UDP does not require a connection to be established before communication. Instead, it encapsulates data into datagrams and sends them directly. This makes it suitable for scenarios with high real-time requirements and a low tolerance for packet loss.
[0066] The Transmission Control Protocol (TCP) is a core protocol in the Internet Protocol Suite (TCP / IP). It belongs to the transport layer and is responsible for providing reliable, connection-oriented byte stream transmission services on the network. It is widely used in scenarios requiring highly reliable data transmission, such as web browsing (HTTP / HTTPS), file transfer (FTP), and email (SMTP / POP3).
[0067] The above is an explanation of the relevant professional terms involved in this application. Other relevant terms will be designed and described in detail later.
[0068] First, let’s explain the technical problems existing in related technologies:
[0069] With the rapid development of Internet technology, the Domain Name System (DNS), as a core component of the Internet, undertakes the important task of resolving domain names into IP addresses. Root servers are the core infrastructure of the DNS, responsible for authoritatively resolving top-level domains (such as .com, .cn, and .org) worldwide.
[0070] However, the root servers of the DNS (including 13 logical roots and thousands of physical root instances) are also facing increasingly severe security threats. On the one hand, malicious attackers could launch hijacking attacks to tamper with or delete top-level domain information in the root server zone file records, resulting in the inability to correctly resolve subdomains under the corresponding top-level domain, with serious consequences. On the other hand, malicious attackers could launch network attacks against the root servers by launching a large number of top-level domain query requests, thereby affecting the stability and reliability of the DNS service.
[0071] In related technologies, traditional root server network attack defense methods rely on stacking the physical resources of root servers and combining them with load balancing to resist large-scale network attacks. However, this is difficult to operate and manage, and the security protection efficiency is low.
[0072] In order to solve the above problems, the embodiments of the present application propose a domain name security protection method, device, computer equipment and storage medium. By intercepting the domain name query request information sent by the recursive server to the root server, and then parsing it to determine the target top-level domain name that the recursive server needs to query, and then matching the target top-level domain name with multiple preset top-level domain names that have been saved locally, and then, if the match is successful, determining the target top-level domain name configuration parameters corresponding to the target top-level domain name according to the mapping relationship between the preset top-level domain name and the preset top-level domain name configuration parameters; generating domain name response information corresponding to the target top-level domain name according to the target top-level domain name configuration parameters and the domain name query request information, and sending the domain name response information to the recursive server. In this way, the recursive server is prevented from directly sending the domain name query request information to the root server, which can prevent the root server from being attacked by the network, thereby achieving network security protection for the root server, and achieving network security protection for the top-level domain name, while also reducing the root server's processing capacity for domain name query request information and alleviating the load pressure on the root server.
[0073] See also Figure 1 , Figure 1 Schematic diagram of the system framework corresponding to the domain name security protection method provided in the embodiment of the present application. The domain name security protection method provided in the embodiment of the present application can be applied in this system framework.
[0074] Please refer to the following for details: Figure 1 , Figure 1 This is a system architecture diagram of the domain name security protection method provided in the embodiment of the present application, which includes a terminal 140, the Internet 130, a gateway 120, a server 110, etc.
[0075] The terminal 140 or the server 110 may be a device for executing the domain name security protection method.
[0076] Terminal 140 includes, but is not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, and the like. Embodiments of the present application can be applied in various scenarios, including, but not limited to, network security and network defense. Furthermore, it can be a single device or a combination of multiple devices. For example, multiple desktop computers connected via a local area network, sharing a common display, and working collaboratively, collectively constitute a terminal 140. Terminal 140 can communicate with Internet 130 via wired or wireless means to exchange data.
[0077] Server 110 refers to a computer system that provides certain services to terminal 140. Compared to ordinary terminal 140, server 110 has higher requirements in terms of stability, security, and performance. Server 110 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.
[0078] Gateway 120, also known as a gateway or protocol converter, implements network interconnection at the transport layer and is a computer system or device that performs a conversion function. It acts as a translator between two systems using different communication protocols, data formats, languages, or even completely different architectures. Gateways can also provide filtering and security functions. Messages sent from terminal 140 to server 110 are sent through gateway 120 to the corresponding server 110. Messages sent from server 110 to terminal 140 are also sent through gateway 120 to the corresponding terminal 140.
[0079] The domain name security protection method in the embodiment of the present application can be applied in a variety of scenarios, such as network security, etc. The scenarios to which the domain name security protection method in the present application is applied are not limited here.
[0080] See also Figure 2 , Figure 2 This is a scenario diagram of the domain name security protection method provided in an embodiment of the present application.
[0081] Among them, the domain name security protection scenario always includes the configuration end, programmable devices, recursive servers and root servers.
[0082] The configuration end can be understood as the upper device of the programmable device. The configuration end can configure preset top-level domain name configuration parameters corresponding to different top-level domain names, and then send the preset top-level domain name configuration parameters to the programmable device.
[0083] Specifically, users set the preset top-level domain configuration parameters for the top-level domains that require security protection through the configuration end's web page. The preset top-level domain configuration parameters include the correct authoritative information corresponding to the top-level domain (such as NS records and A records). The configuration end's backend software then sends the preset top-level domain configuration parameters to the programmable device. At the same time, the configuration end can also detect the security protection status of the top-level domain by reading registers in the programmable device.
[0084] The programmable device may be a device based on a field programmable gate array (FPGA), and the programmable device may perform the following steps:
[0085] Intercept the domain name query request information sent by the recursive server to the root server, and parse the domain name query request information to determine the target top-level domain name that the recursive server needs to query;
[0086] Match the target top-level domain name with multiple preset top-level domain names to obtain a matching result;
[0087] When the matching result indicates a successful match, determining the target top-level domain configuration parameter corresponding to the target top-level domain according to the mapping relationship between the preset top-level domain and the preset top-level domain configuration parameter;
[0088] Generates domain name response information corresponding to the target top-level domain name according to the target top-level domain name configuration parameters and the domain name query request information, and sends the domain name response information to the recursive server.
[0089] In traditional technical solutions, the recursive server generally directly sends the domain name query request information to the root server to obtain the authoritative information related to the top-level domain name. In this application, by setting the preset top-level domain name configuration parameters of each top-level domain name that needs to be protected in the programmable device, after determining the target top-level domain name in the domain name query request information, if the target top-level domain name is the top-level domain name that needs to be protected, the programmable device can be used to respond to the domain name query request information, that is, generate domain name response information (such as the authoritative information of the target top-level domain name) and send it to the recursive server. This reduces the risk of the root server being directly exposed to the network and receiving network attacks, realizes the security protection of the root server, and achieves the security protection effect of the top-level domain name.
[0090] In order to understand more in detail the domain name security protection method provided by this application. Figure 3 , Figure 3 This is a flow chart of a domain name security protection method provided by an embodiment of the present application. The domain name security protection method may include the following steps:
[0091] Step 210: intercept the domain name query request information sent by the recursive server to the root server, and parse the domain name query request information to determine the target top-level domain name that the recursive server needs to query;
[0092] Step 220: Match the target top-level domain name with multiple preset top-level domain names to obtain a matching result;
[0093] Step 230: When the matching result indicates a successful match, determine the target top-level domain configuration parameters corresponding to the target top-level domain based on the mapping relationship between the preset top-level domain and the preset top-level domain configuration parameters;
[0094] Step 240: Generate domain name response information corresponding to the target top-level domain name according to the target top-level domain name configuration parameters and the domain name query request information, and send the domain name response information to the recursive server.
[0095] The following will describe in detail steps 210 to 240. In this application, the domain name security protection method will be implemented from the perspective of a programmable device.
[0096] In step 210, the domain name query request information sent by the recursive server to the root server is intercepted, and the domain name query request information is parsed to determine the target top-level domain name that the recursive server needs to query.
[0097] Among them, the recursive server will generate domain name query request information when processing the corresponding network task. For example, when accessing a web page, it will generate domain name query request information to obtain relevant information of the top-level domain name, thereby completing subsequent web page access.
[0098] The programmable device can intercept the domain name query request information sent by the recursive server to the root server, and then parse the domain name query request information to determine the target top-level domain name that the recursive server needs to query. For example, the programmable device receives the domain name query request information sent by the recursive server to the root server through the network interface. The domain name query request information can be understood as a message. The programmable device will parse the domain name query request information header field and extract information such as the source Media Access Control Address (MAC), source Internet Protocol Address (IP), destination Internet Protocol Address, source port number, destination port number, transaction identification number (Transaction ID), and the target top-level domain name to be queried.
[0099] In some embodiments, before matching the target top-level domain with a plurality of preset top-level domains to obtain a matching result, the method further includes:
[0100] (1.1) Obtaining multiple preset top-level domain names and preset top-level domain name configuration parameters of each preset top-level domain name;
[0101] (1.2) Generate and save the mapping relationship between each preset top-level domain name and the preset top-level domain name configuration parameter.
[0102] Among them, the configuration terminal can set the preset top-level domain name configuration parameters for each preset top-level domain name. For example, the user can enter the domain name configuration parameter management interface through the configuration terminal, and then add the preset top-level domain name configuration parameters for each preset top-level domain name through this page. The preset top-level domain name configuration parameters include the domain name serial number, the query domain name (such as the aaa top-level domain name) and the query type (such as NS record, A record, AAAA record). In addition, the protocol used for the return packet data can also be configured (such as UDP or TCP).
[0103] Users can also use this page to clear the historical preset top-level domain name configuration parameters for the preset top-level domain name and then save the new preset top-level domain name configuration parameters. When clearing the historical preset top-level domain name configuration parameters, the programmable device can also clear the historical preset top-level domain name configuration parameters for the preset top-level domain name simultaneously.
[0104] After the user saves the preset top-level domain name configuration parameters on this page, the page will send a save configuration instruction to the configuration end. The configuration end will package the preset top-level domain name configuration parameters and send them to the programmable device, so that the new preset top-level domain name configuration parameters are written into the programmable device and take effect.
[0105] Users can also use this page to write zone files to the configuration backend software for retrieval. Zone files contain the correct authoritative information related to top-level domain names (NS records and A records), which are important for top-level domain name matching and automatic packet response.
[0106] Users can also initiate a search request through this page, which will send a search instruction to the configuration backend software. The configuration end will search the top-level domain name zone file, retrieve the response parameters corresponding to the top-level domain name based on the top-level domain name in the search request initiated by the user, and then store the search results in the database table and refresh the page data.
[0107] The programmable device can receive multiple preset top-level domain names and preset top-level domain name configuration parameters of each preset top-level domain name sent by the configuration end, and then locally generate and save the mapping relationship between each preset top-level domain name and the preset top-level domain name configuration parameters.
[0108] As can be seen from the above, the preset top-level domain name configuration parameters of the preset top-level domain name can be generated according to actual needs. This ensures that the preset top-level domain name configuration parameters are available to achieve effective protection of the preset top-level domain name.
[0109] In some embodiments, before matching the target top-level domain with a plurality of preset top-level domains to obtain a matching result, the method further includes:
[0110] (2.1) determining a target preset top-level domain name having updated preset top-level domain name configuration parameters among a plurality of preset top-level domain names;
[0111] (2.2) Obtaining a new version of the preset top-level domain configuration parameters corresponding to the target preset top-level domain, and updating the preset top-level domain configuration parameters corresponding to the target preset top-level domain using the new version of the preset top-level domain configuration parameters.
[0112] Among them, the programmable device can query the configuration end for the first version number of the preset top-level domain name configuration parameters of each preset top-level domain name, and then determine the second version number of the preset top-level domain name configuration parameters of each preset top-level domain name stored locally, and then compare the first version number and the second version number of the preset top-level domain name configuration parameters of each preset top-level domain name, so as to determine the target preset top-level domain name whose preset top-level domain name configuration parameters have been updated.
[0113] Then, the new version of the preset top-level domain configuration parameters corresponding to the target preset top-level domain are obtained from the configuration terminal, and the preset top-level domain configuration parameters corresponding to the target preset top-level domain are updated using the new version of the preset top-level domain configuration parameters. For example, the old version of the preset top-level domain configuration parameters corresponding to the target preset top-level domain are deleted, and then the new version of the preset top-level domain configuration parameters corresponding to the target preset top-level domain are saved.
[0114] The advantage of doing so is that it can ensure that the preset top-level domain name configuration parameters stored locally on the programmable device are always up to date, thereby achieving more effective protection for the preset top-level domain name.
[0115] In some embodiments, before matching the target top-level domain with a plurality of preset top-level domains to obtain a matching result, the method further includes:
[0116] (3.1) Determine the target Internet Protocol address corresponding to the recursive server based on the domain name query request information;
[0117] (3.2) determining the total number of times the recursive server sends request information to the root server within a preset time period and the frequency of such requests per unit time based on the target Internet Protocol address;
[0118] (3.3) When the total number of times and the sending frequency do not meet the preset security conditions, an abnormal response message is generated according to the domain name query request information, and the abnormal response message is sent to the recursive server.
[0119] (3.4) When the total number of times and the sending frequency meet the preset security conditions, the step of matching the target top-level domain name with multiple preset top-level domain names is executed to obtain a matching result.
[0120] The target IP address of the recursive server is determined based on the domain name query request information. The target IP address can be understood as an identifier corresponding to the recursive server. Then, based on the target IP address, the total number of request messages sent by the recursive server to the root server within a preset time period and the frequency of such requests per unit time are determined. For example, the preset time period is 1 minute and the unit time is 1 second.
[0121] The system then determines whether the total number of requests and the frequency of transmissions meet pre-set security conditions. For example, if the pre-set security conditions are that the total number of requests is less than a pre-set total number threshold and the frequency of transmissions is less than a pre-set frequency threshold, then if the recursive server's total number of requests and frequency of transmissions do not meet these pre-set security conditions, the domain name query request information sent by the recursive server may be a malicious request. Therefore, the recursive server may be an unsafe and potentially offensive device.
[0122] When the total number of requests and the frequency of requests do not meet the preset security conditions, an exception response message is generated based on the domain name query request information and sent to the recursive server. For example, the exception response message may contain the text "Too many requests, please try again later."
[0123] When the total number of times and the sending frequency meet the preset security conditions, for example, the total number of times is less than the preset total number threshold, and the sending frequency is less than the preset sending frequency threshold, the step of matching the target top-level domain name with multiple preset top-level domain names to obtain a matching result is executed.
[0124] The advantage of doing this is that it can intercept some malicious requests and prevent the root server from being attacked by malicious network attacks, thereby protecting the root server and top-level domain names.
[0125] In some embodiments, before matching the target top-level domain with a plurality of preset top-level domains to obtain a matching result, the method further includes:
[0126] (4.1) Obtain the number of query request information processed within a preset time period;
[0127] (4.2) When the number is greater than the preset number, the domain name query request information is forwarded to the root server;
[0128] (4.3) Receive the domain name response information returned by the root server based on the domain name query request information, and forward the domain name response information to the recursive server.
[0129] The number of query request messages processed within a preset time period can be obtained. For example, if the preset time period is 1 minute, the number of query request messages processed within the preset time period is 10 million. When the number exceeds the preset number, the domain name query request message is forwarded to the root server. For example, if the preset number is 9 million, it is considered that the programmable device is unable to process the excessive number of query request messages. To ensure that the query request messages from the recursive server can be properly processed, the domain name query request message is forwarded to the root server, domain name response information returned by the root server based on the domain name query request message is received, and the domain name response information is forwarded to the recursive server.
[0130] The advantage of this is that when the programmable device is relatively busy, the query request information of the top-level domain name can be processed normally.
[0131] In step 220, the target top-level domain name is matched with a plurality of preset top-level domain names to obtain a matching result.
[0132] The programmable device locally stores multiple preset top-level domain names and preset top-level domain name configuration parameters corresponding to each preset top-level domain name. These top-level domain names can form a top-level domain name table entry, and then the target domain name is matched with the top-level domain name table entry to obtain a matching result.
[0133] If the same top-level domain name as the target top-level domain name is found in the top-level domain table, the matching result is a success. If the same top-level domain name as the target top-level domain name is not found in the top-level domain table, the matching result is a failure.
[0134] In some embodiments, after matching the target top-level domain with a plurality of preset top-level domains to obtain a matching result, the method further includes:
[0135] (1.1) When the matching result indicates a match failure, forward the domain name query request information to the root server;
[0136] (1.2) Receive the domain name response information returned by the root server based on the domain name query request information, and forward the domain name response information to the recursive server.
[0137] If the matching result indicates a match failure, this indicates that the target top-level domain is not a pre-defined top-level domain that requires protection. The domain name query request can then be forwarded to the root server. Upon receiving the domain name query request, the root server processes the query request to generate a domain name response, which is then sent to the programmable device. The programmable device then sends the domain name response to the recursive server. The domain name response includes authoritative information for the target top-level domain.
[0138] Step 230: When the matching result indicates a successful match, determine the target top-level domain configuration parameters corresponding to the target top-level domain based on the mapping relationship between the preset top-level domain and the preset top-level domain configuration parameters;
[0139] When the matching result indicates a successful match, it indicates that the target top-level domain is a preset top-level domain that requires security protection. At this time, the target top-level domain configuration parameters corresponding to the target top-level domain can be determined based on the mapping relationship between the preset top-level domain and the preset top-level domain configuration parameters. The target top-level domain configuration parameters can be understood as relevant processing parameters for processing the domain name query request information corresponding to the target top-level domain, which can realize the response to the domain name query request information.
[0140] In some embodiments, determining the target top-level domain configuration parameter corresponding to the target top-level domain based on the mapping relationship between the preset top-level domain and the preset top-level domain configuration parameter includes:
[0141] (1.1) Determine the data transmission protocol type corresponding to the domain name query request information;
[0142] (1.2) Determine the target top-level domain configuration parameters corresponding to the target top-level domain according to the mapping relationship between the preset top-level domain and the preset top-level domain configuration parameters and the data transmission protocol type.
[0143] Among them, the data transmission protocol type corresponding to the domain name query request information is generally TCP type or UDP type. The data structures corresponding to these two types of data transmission protocols are different, so it is necessary to set a preset top-level domain name configuration parameter respectively. That is to say, for a preset top-level domain name, it is necessary to consider the preset top-level domain name configuration parameters corresponding to the TCP type, and it is also necessary to set the preset top-level domain name configuration parameters corresponding to the UDP type.
[0144] First, the preset top-level domain configuration parameters corresponding to the target top-level domain can be determined based on the mapping relationship between the preset top-level domain and the preset top-level domain configuration parameters. Then, the target top-level domain configuration parameters corresponding to the target top-level domain can be selected from the preset domain configuration parameters based on the data transmission protocol type. For example, if the data transmission protocol type is TCP, the preset top-level domain configuration parameters corresponding to the TCP type can be selected as the target top-level domain configuration parameters.
[0145] The advantage of this is that domain name query request information of different data transmission protocol types can be processed to ensure the accuracy of domain name response information subsequently generated according to the target top-level domain name configuration parameters.
[0146] In step 240, domain name response information corresponding to the target top-level domain name is generated according to the target top-level domain name configuration parameters and the domain name query request information, and the domain name response information is sent to the recursive server.
[0147] Among them, the relevant data in the domain name query request information can be extracted, and then the domain name response information corresponding to the target top-level domain name is generated through the target top-level domain name configuration parameters. The domain name response information contains the relevant information of the top-level domain name that the recursive server needs to query, such as NS records, A records, AAAA records, etc.
[0148] In some embodiments, generating domain name response information corresponding to the target top-level domain name based on the target top-level domain name configuration parameters and the domain name query request information includes:
[0149] (1.1) Determine the target data structure based on the target top-level domain configuration parameters;
[0150] (1.2) Obtaining the transaction identification number, media access control address, source Internet Protocol address, destination Internet Protocol address, source port number, and destination port number from the domain name query request information;
[0151] (1.3) The transaction identification number, media access control address, source Internet Protocol address, destination Internet Protocol address, source port number, and destination port number are respectively set in the corresponding fields of the target data structure to obtain the domain name response information corresponding to the target top-level domain name.
[0152] The data transmission protocol corresponding to the domain name query request information is often the TCP protocol or the UDP protocol. Therefore, the domain name query request information often corresponds to two data structures. The data structure of the domain name response information returned by the programmable device to the recursive server should be consistent with the data structure corresponding to the domain name request information. For example, if the domain name query request information corresponds to the TCP protocol, the domain name response information will also be the TCP protocol. If the domain name query request information corresponds to the UDP protocol, the domain name response information will also be the UDP protocol.
[0153] The target data structure can be determined based on the target top-level domain configuration parameters. Figure 4 , Figure 4 This is a schematic diagram of the data structure provided by the embodiment of the present application. If the data structure corresponding to the target data structure is the data structure corresponding to the UDP protocol, please refer to Figure 4In the figure above, the UDP packet is the data structure corresponding to the UDP protocol, which includes the destination MAC, source IP, destination IP, IP checksum, source port, destination port, UDP checksum, transaction ID, etc. The MAC header includes the destination MAC, the IP header includes the source IP, destination IP, and IP checksum, the UDP header includes the source port, destination port, and UDP checksum, and the DNS information includes the transaction ID.
[0154] If the target data structure corresponds to the data structure of the TCP protocol, please refer to Figure 4 In the figure above, the TCP message is the data structure corresponding to the TCP protocol, which includes the destination MAC, source IP, destination IP, IP checksum, source port, destination port, sequence number, acknowledgment number, TCP checksum, transaction ID, etc. The MAC header includes the destination MAC, the IP header includes the source IP, destination IP, and IP checksum, the TCP header includes the source port, destination port, sequence number, acknowledgment number, and TCP checksum, and the DNS information includes the transaction ID.
[0155] After determining the target data structure, the transaction identification number, media access control address, source Internet Protocol address, destination Internet Protocol address, source port number, and destination port number are obtained from the domain name query request message. The transaction identification number, media access control address, source Internet Protocol address, destination Internet Protocol address, source port number, and destination port number are then set in the corresponding fields of the target data structure to obtain the domain name response message corresponding to the target top-level domain name.
[0156] For example, if the target data structure is a data structure corresponding to the UDP protocol, the source MAC address in the domain name query request message is set in the destination MAC address field of the target data structure, the source MAC address field of the target data structure is specified by the corresponding target domain name configuration parameter, the destination IP address in the domain name query request message is set in the source IP address field of the target data structure, the source IP address in the domain name query request message is set in the destination IP address field of the target data structure, the destination port in the domain name query request message is set in the source port field of the target data structure, and the source port in the domain name query request message is set in the destination port field of the target data structure. The UDP checksum and IP checksum are then calculated to generate the corresponding domain name response message.
[0157] For example, if the target data structure is a data structure corresponding to the TCP protocol, the source MAC address in the domain name query request message is set in the destination MAC address field of the target data structure, where the source MAC address field of the target data structure is specified by the corresponding target domain name configuration parameter. The destination IP address in the domain name query request message is set in the source IP address field of the target data structure, the source IP address in the domain name query request message is set in the destination IP address field of the target data structure, the destination port in the domain name query request message is set in the source port field of the target data structure, and the source port in the domain name query request message is set in the destination port field of the target data structure. The sequence number in the domain name query request message is set in the acknowledgment number field of the target data structure, and the acknowledgment number in the domain name query request message is set in the sequence number field of the target data structure. The specific replacement process is as follows: the sequence number and acknowledgment number of the domain name query request message are extracted and replaced with the sequence number field of the acknowledgment number field of the target data structure; and the sequence number plus the DNS length of the original message (used to calculate the acknowledgment number of the reply packet) are replaced with the sequence number field of the reply packet. Then the TCP checksum and IP checksum are calculated to generate the corresponding domain name response information.
[0158] From the above, it can be seen that in this application, domain name response information can be flexibly generated based on domain name request information.
[0159] In some embodiments, the transaction identification number, media access control address, source Internet Protocol address, destination Internet Protocol address, source port number, and destination port number are respectively set in corresponding fields of the target data structure to obtain domain name response information corresponding to the target top-level domain name, including:
[0160] (1.3.1) Setting the transaction identification number, media access control address, source Internet Protocol address, destination Internet Protocol address, source port number, and destination port number in the corresponding fields of the target data structure to obtain the initial domain name response information;
[0161] (1.3.2) Perform information verification on the initial domain name response information to generate a verification value, and generate domain name response information corresponding to the target top-level domain name based on the verification value and the initial domain name response information.
[0162] Among them, the transaction identification number, media access control address, source Internet Protocol address, destination Internet Protocol address, source port number and destination port number can be set in the corresponding fields of the target data structure respectively to obtain the initial domain name response information. The specific generation method is as described above.
[0163] The initial domain name response information is then verified to generate a checksum, such as an MD5 checksum, and the domain name response information corresponding to the target top-level domain name is generated based on the checksum and the initial domain name response information. The advantage of this is that the recursive server can perform integrity verification on the domain name response information based on the checksum, ensuring that the received domain name response information is complete.
[0164] In an embodiment of the present application, a domain name query request message sent by a recursive server to a root server is intercepted and the domain name query request message is parsed to determine a target top-level domain name that the recursive server needs to query; the target top-level domain name is matched with multiple preset top-level domain names to obtain a matching result; when the matching result indicates a successful match, target top-level domain name configuration parameters corresponding to the target top-level domain name are determined based on a mapping relationship between the preset top-level domain name and the preset top-level domain name configuration parameters; domain name response information corresponding to the target top-level domain name is generated based on the target top-level domain name configuration parameters and the domain name query request message, and the domain name response information is sent to the recursive server.
[0165] In this way, the domain name query request information sent by the recursive server to the root server is intercepted, and then parsed to determine the target top-level domain name that the recursive server needs to query, and then the target top-level domain name is matched with multiple preset top-level domain names that have been saved locally. Then, if the match is successful, the target top-level domain name configuration parameters corresponding to the target top-level domain name are determined according to the mapping relationship between the preset top-level domain name and the preset top-level domain name configuration parameters; the domain name response information corresponding to the target top-level domain name is generated according to the target top-level domain name configuration parameters and the domain name query request information, and the domain name response information is sent to the recursive server. This avoids the recursive server directly sending the domain name query request information to the root server, which can prevent the root server from being attacked by the network, thereby achieving network security protection for the root server, and achieving network security protection for the top-level domain name. At the same time, it also reduces the root server's processing capacity for domain name query request information, alleviating the load pressure on the root server.
[0166] See also Figure 5 , Figure 5 This is another flowchart of the domain name security protection method provided by an embodiment of the present application, which may include the following steps:
[0167] Step 301: intercepting a domain name query request message sent by a recursive server to a root server, and parsing the domain name query request message to determine a target top-level domain name that the recursive server needs to query;
[0168] Step 302: Determine the target Internet Protocol address corresponding to the recursive server based on the domain name query request information;
[0169] Step 303: Determine the total number of times the recursive server sends request information to the root server within a preset time period and the frequency of sending information per unit time according to the target Internet Protocol address;
[0170] Step 304: When the total number of times and the sending frequency meet the preset security conditions, the target top-level domain name is matched with multiple preset top-level domain names to obtain a matching result;
[0171] Step 305: When the matching result indicates a match failure, forward the domain name query request information to the root server;
[0172] Step 306: Receive the domain name response information returned by the root server according to the domain name query request information, and forward the domain name response information to the recursive server;
[0173] Step 307: When the matching result indicates a successful match, determine the data transmission protocol type corresponding to the domain name query request information;
[0174] Step 308: Determine the target top-level domain configuration parameters corresponding to the target top-level domain according to the mapping relationship between the preset top-level domain and the preset top-level domain configuration parameters and the data transmission protocol type;
[0175] Step 309: Determine the target data structure based on the target top-level domain configuration parameters;
[0176] Step 310: Obtain the transaction identification number, media access control address, source Internet Protocol address, destination Internet Protocol address, source port number, and destination port number from the domain name query request information;
[0177] Step 311: Set the transaction identification number, media access control address, source Internet Protocol address, destination Internet Protocol address, source port number, and destination port number in the corresponding fields of the target data structure to obtain domain name response information corresponding to the target top-level domain name.
[0178] In the above embodiments, the description of each embodiment has its own focus. For the part that is not described in detail in a certain embodiment, please refer to the detailed description of the above domain name security protection method, which will not be repeated here.
[0179] See also Figure 6 , Figure 6 FIG2 is a schematic diagram of the structure of a domain name security protection device provided in an embodiment of the present application. The domain name security protection device can execute the above-mentioned domain name security protection method.
[0180] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program that has a predetermined function and works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as processing circuits or memories) or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the function of the module or unit.
[0181] Domain name security protection device 400, comprising:
[0182] Interception module 410, for intercepting domain name query request information sent by the recursive server to the root server, and parsing the domain name query request information to determine the target top-level domain name that the recursive server needs to query;
[0183] A matching module 420 is configured to match the target top-level domain name with a plurality of preset top-level domain names to obtain a matching result;
[0184] Determining module 430, configured to determine target top-level domain configuration parameters corresponding to the target top-level domain based on a mapping relationship between the preset top-level domain and the preset top-level domain configuration parameters when the matching result indicates a successful match;
[0185] The generating module 440 is configured to generate domain name response information corresponding to the target top-level domain name according to the target top-level domain name configuration parameters and the domain name query request information, and send the domain name response information to the recursive server.
[0186] In some implementations, the determination module 430 is configured to:
[0187] Determine the data transmission protocol type corresponding to the domain name query request information;
[0188] The target top-level domain configuration parameters corresponding to the target top-level domain are determined according to the mapping relationship between the preset top-level domain name and the preset top-level domain configuration parameters and the data transmission protocol type.
[0189] In some embodiments, the generating module 440 is configured to:
[0190] Determine the target data structure according to the target top-level domain configuration parameters;
[0191] Obtaining a transaction identification number, a media access control address, a source Internet Protocol address, a destination Internet Protocol address, a source port number, and a destination port number from the domain name query request information;
[0192] The transaction identification number, media access control address, source Internet Protocol address, destination Internet Protocol address, source port number and destination port number are respectively set in the corresponding fields of the target data structure to obtain domain name response information corresponding to the target top-level domain name.
[0193] In some embodiments, the generating module 440 is configured to:
[0194] Setting the transaction identification number, media access control address, source Internet Protocol address, destination Internet Protocol address, source port number, and destination port number in corresponding fields of the target data structure to obtain initial domain name response information;
[0195] The initial domain name response information is verified to generate a verification value, and domain name response information corresponding to the target top-level domain name is generated based on the verification value and the initial domain name response information.
[0196] In some embodiments, the domain name security protection device 400 further includes a configuration module for:
[0197] Before matching the target top-level domain name with the plurality of preset top-level domain names and obtaining a matching result, obtaining the plurality of preset top-level domain names and preset top-level domain name configuration parameters of each preset top-level domain name;
[0198] A mapping relationship between each preset top-level domain name and the preset top-level domain name configuration parameter is generated and saved.
[0199] In some embodiments, the configuration module is configured to:
[0200] Before matching the target top-level domain name with the plurality of preset top-level domain names and obtaining a matching result, determining a target preset top-level domain name having updated preset top-level domain name configuration parameters among the plurality of preset top-level domain names;
[0201] The new version of the preset top-level domain name configuration parameters corresponding to the target preset top-level domain name are obtained, and the preset top-level domain name configuration parameters corresponding to the target preset top-level domain name are updated using the new version of the preset top-level domain name configuration parameters.
[0202] In some embodiments, the configuration module is configured to:
[0203] Determining a target Internet Protocol address corresponding to the recursive server based on the domain name query request information;
[0204] Determine the total number of times the recursive server sends request information to the root server within a preset time period and the frequency of such requests per unit time based on the target Internet Protocol address;
[0205] When the total number of times and the sending frequency do not meet the preset security conditions, an abnormal response message is generated according to the domain name query request information, and the abnormal response message is sent to the recursive server;
[0206] When the total number of times and the sending frequency meet the preset security conditions, the step of matching the target top-level domain name with multiple preset top-level domain names to obtain a matching result is executed.
[0207] In some implementations, the domain name security protection device 400 further includes a forwarding module configured to:
[0208] After matching the target top-level domain name with multiple preset top-level domain names and obtaining a matching result, if the matching result indicates a match failure, forwarding the domain name query request information to the root server;
[0209] Receives the domain name response information returned by the root server based on the domain name query request information, and forwards the domain name response information to the recursive server.
[0210] In some embodiments, the forwarding module is configured to:
[0211] Get the number of query request information processed within a preset time period;
[0212] When the number is greater than the preset number, the domain name query request information is forwarded to the root server;
[0213] Receives the domain name response information returned by the root server based on the domain name query request information, and forwards the domain name response information to the recursive server.
[0214] In the above embodiments, the description of each embodiment has its own focus. For the part that is not described in detail in a certain embodiment, please refer to the detailed description of the above domain name security protection method, which will not be repeated here.
[0215] In an embodiment of the present application, the interception module 410 intercepts the domain name query request information sent by the recursive server to the root server, and parses the domain name query request information to determine the target top-level domain name that the recursive server needs to query; the matching module 420 matches the target top-level domain name with multiple preset top-level domain names to obtain a matching result; when the matching result indicates a successful match, the determination module 430 determines the target top-level domain name configuration parameters corresponding to the target top-level domain name based on the mapping relationship between the preset top-level domain name and the preset top-level domain name configuration parameters; the generation module 440 generates domain name response information corresponding to the target top-level domain name based on the target top-level domain name configuration parameters and the domain name query request information, and sends the domain name response information to the recursive server.
[0216] In this way, the domain name query request information sent by the recursive server to the root server is intercepted, and then parsed to determine the target top-level domain name that the recursive server needs to query, and then the target top-level domain name is matched with multiple preset top-level domain names that have been saved locally. Then, if the match is successful, the target top-level domain name configuration parameters corresponding to the target top-level domain name are determined according to the mapping relationship between the preset top-level domain name and the preset top-level domain name configuration parameters; the domain name response information corresponding to the target top-level domain name is generated according to the target top-level domain name configuration parameters and the domain name query request information, and the domain name response information is sent to the recursive server. This avoids the recursive server directly sending the domain name query request information to the root server, which can prevent the root server from being attacked by the network, thereby achieving network security protection for the root server, and achieving network security protection for the top-level domain name. At the same time, it also reduces the root server's processing capacity for domain name query request information, alleviating the load pressure on the root server.
[0217] The present application also provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the above-mentioned domain name security protection method when executing the computer program. The computer device may include a server, a programmable device, or other devices.
[0218] See also Figure 7 , Figure 7 The hardware structure of a computer device according to another embodiment is shown. The computer device includes:
[0219] The processor 501 may be implemented as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.
[0220] The memory 502 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 502 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 502 and is called by the processor 501 to execute the domain name security protection method of the embodiments of this application;
[0221] Input / output interface 503, used to implement information input and output;
[0222] Communication interface 504, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);
[0223] Bus 505 , which transmits information between various components of the device (e.g., processor 501 , memory 502 , input / output interface 503 , and communication interface 504 );
[0224] The processor 501 , the memory 502 , the input / output interface 503 and the communication interface 504 are connected to each other in communication within the device via a bus 505 .
[0225] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned domain name security protection method.
[0226] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0227] The domain name security protection method, apparatus, computer device, and storage medium provided in the embodiments of the present application intercept domain name query request information sent by a recursive server to a root server, and parse the domain name query request information to determine a target top-level domain name that the recursive server needs to query; match the target top-level domain name with multiple preset top-level domain names to obtain a matching result; when the matching result indicates a successful match, determine target top-level domain name configuration parameters corresponding to the target top-level domain name based on a mapping relationship between the preset top-level domain name and the preset top-level domain name configuration parameters; generate domain name response information corresponding to the target top-level domain name based on the target top-level domain name configuration parameters and the domain name query request information, and send the domain name response information to the recursive server.
[0228] In this way, the domain name query request information sent by the recursive server to the root server is intercepted, and then parsed to determine the target top-level domain name that the recursive server needs to query, and then the target top-level domain name is matched with multiple preset top-level domain names that have been saved locally. Then, if the match is successful, the target top-level domain name configuration parameters corresponding to the target top-level domain name are determined according to the mapping relationship between the preset top-level domain name and the preset top-level domain name configuration parameters; the domain name response information corresponding to the target top-level domain name is generated according to the target top-level domain name configuration parameters and the domain name query request information, and the domain name response information is sent to the recursive server. This avoids the recursive server directly sending the domain name query request information to the root server, which can prevent the root server from being attacked by the network, thereby achieving network security protection for the root server, and achieving network security protection for the top-level domain name. At the same time, it also reduces the root server's processing capacity for domain name query request information, alleviating the load pressure on the root server.
[0229] The embodiments described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0230] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.
[0231] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.
[0232] Those skilled in the art will appreciate that all or some of the steps in the methods, systems, and functional modules / units in the devices disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.
[0233] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0234] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0235] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the above-mentioned units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0236] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0237] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0238] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes various media that can store programs, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0239] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention should be within the scope of the present invention.
Claims
1. A domain name security protection method, characterized in that: The method comprises: Intercepting a domain name query request message sent by a recursive server to a root server, and parsing the domain name query request message to determine a target top-level domain name that the recursive server needs to query; Matching the target top-level domain name with multiple preset top-level domain names to obtain a matching result; When the matching result indicates a successful match, determining a target top-level domain configuration parameter corresponding to the target top-level domain according to a mapping relationship between the preset top-level domain and the preset top-level domain configuration parameter; Generate domain name response information corresponding to the target top-level domain name according to the target top-level domain name configuration parameters and the domain name query request information, and send the domain name response information to the recursive server.
2. The domain name security protection method according to claim 1, characterized in that: The determining the target top-level domain configuration parameter corresponding to the target top-level domain according to the mapping relationship between the preset top-level domain and the preset top-level domain configuration parameter includes: Determine the data transmission protocol type corresponding to the domain name query request information; The target top-level domain configuration parameter corresponding to the target top-level domain is determined according to the mapping relationship between the preset top-level domain name and the preset top-level domain configuration parameter, and the data transmission protocol type.
3. The domain name security protection method according to claim 1, characterized in that: Generating domain name response information corresponding to the target top-level domain name according to the target top-level domain name configuration parameters and the domain name query request information includes: Determining a target data structure according to the target top-level domain configuration parameters; Obtaining a transaction identification number, a media access control address, a source Internet Protocol address, a destination Internet Protocol address, a source port number, and a destination port number from the domain name query request information; The transaction identification number, the media access control address, the source Internet Protocol address, the destination Internet Protocol address, the source port number and the destination port number are respectively set in the fields corresponding to the target data structure to obtain domain name response information corresponding to the target top-level domain name.
4. The domain name security protection method according to claim 3, characterized in that: The step of setting the transaction identification number, the media access control address, the source Internet Protocol address, the destination Internet Protocol address, the source port number, and the destination port number in corresponding fields of the target data structure, and obtaining domain name response information corresponding to the target top-level domain name, includes: Setting the transaction identification number, the media access control address, the source Internet Protocol address, the destination Internet Protocol address, the source port number, and the destination port number in corresponding fields of the target data structure, respectively, to obtain initial domain name response information; The initial domain name response information is verified to generate a verification value, and domain name response information corresponding to the target top-level domain name is generated according to the verification value and the initial domain name response information.
5. The domain name security protection method according to claim 1, characterized in that: Before matching the target top-level domain name with a plurality of preset top-level domain names to obtain a matching result, the method further includes: Obtain multiple preset top-level domain names and preset top-level domain name configuration parameters of each preset top-level domain name; A mapping relationship between each preset top-level domain name and the preset top-level domain name configuration parameter is generated and saved.
6. The domain name security protection method according to claim 1, characterized in that: After matching the target top-level domain name with a plurality of preset top-level domain names to obtain a matching result, the method further includes: When the matching result indicates a matching failure, forwarding the domain name query request information to the root server; Receive domain name response information returned by the root server according to the domain name query request information, and forward the domain name response information to the recursive server.
7. The domain name security protection method according to claim 1, characterized in that: Before matching the target top-level domain name with a plurality of preset top-level domain names to obtain a matching result, the method further includes: Determining a target Internet Protocol address corresponding to the recursive server according to the domain name query request information; Determining, based on the target Internet Protocol address, a total number of times the recursive server sends request information to the root server within a preset time period, and a sending frequency per unit time; When the total number of times and the sending frequency do not meet the preset safety conditions, generating abnormal response information according to the domain name query request information, and sending the abnormal response information to the recursive server; When the total number of times and the sending frequency meet the preset security conditions, the step of matching the target top-level domain name with a plurality of preset top-level domain names to obtain a matching result is performed.
8. The domain name security protection method according to any one of claims 1 to 7, characterized in that: Before matching the target top-level domain name with a plurality of preset top-level domain names to obtain a matching result, the method further includes: Determining a target preset top-level domain name having updated preset top-level domain name configuration parameters among the plurality of preset top-level domain names; A new version of the preset top-level domain name configuration parameters corresponding to the target preset top-level domain name is obtained, and the preset top-level domain name configuration parameters corresponding to the target preset top-level domain name are updated using the new version of the preset top-level domain name configuration parameters.
9. The domain name security protection method according to any one of claims 1 to 7, characterized in that: Before matching the target top-level domain name with a plurality of preset top-level domain names to obtain a matching result, the method further includes: Get the number of query request information processed within a preset time period; When the number is greater than a preset number, forwarding the domain name query request information to the root server; Receive domain name response information returned by the root server according to the domain name query request information, and forward the domain name response information to the recursive server.
10. A domain name security protection device, characterized in that: The device comprises: An interception module is used to intercept domain name query request information sent by the recursive server to the root server, and parse the domain name query request information to determine the target top-level domain name that the recursive server needs to query; A matching module, configured to match the target top-level domain name with a plurality of preset top-level domain names to obtain a matching result; a determination module configured to determine, when the matching result indicates a successful match, a target top-level domain name configuration parameter corresponding to the target top-level domain name based on a mapping relationship between the preset top-level domain name and the preset top-level domain name configuration parameter; A generating module is configured to generate domain name response information corresponding to the target top-level domain name according to the target top-level domain name configuration parameters and the domain name query request information, and send the domain name response information to the recursive server.
11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a plurality of instructions, which are suitable for loading by a processor to execute the domain name security protection method according to any one of claims 1 to 9.
12. A computer device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that: When the processor executes the computer program, the domain name security protection method according to any one of claims 1 to 9 is implemented.
Citation Information
Patent Citations
Domain name query method and system, routing node, control node and protection node
CN110636006A
Joint detection system and joint detection method for important DNS recursive server
CN115622755A
Domain name resolution behavior olfactory detection method and device
CN117376038A
Request message processing method and system and related equipment
CN117692173A
Domain name management method and device based on alliance chain, equipment and storage medium
CN118316633A